Passkeys: Should You Use Them, and Do They Make You Safer?
Every few months a headline announces that the password is finally dead and passkeys have killed it. You can ignore that argument. Whether the password has a future is a fun thing to debate and a useless thing to base your own security on. The question actually worth your time is smaller and more practical. Should you turn passkeys on, and will doing it make you safer?
Short answer: yes, on the accounts that matter most, and yes, but in a specific way that’s worth understanding so you don’t over-trust it. Passkeys shut down two of the most common ways ordinary people lose accounts. They don’t shut down all of them, and on most sites they sit alongside your old password rather than replacing it. So the benefit is real but bounded. Let me show you where it’s real, where it stops, and what to actually do about it.
What a Passkey Is, in Plain Terms
Strip away the jargon and a passkey is simple. Instead of a password you memorize and type, your phone or computer holds a secret key, and it unlocks that key when you prove it’s you with your face, your fingerprint, or the PIN you use to open the device. The site you’re logging into never sees the key that matters. It only sees a matching public half that’s useless on its own.
The technical name is public-key cryptography, and the short version is worth having because it explains the whole benefit. When you set up a passkey, your device creates two linked keys. The private one stays locked on your device and never leaves it. The public one goes to the website. To log you in, the site sends your device a puzzle only the private key can solve, your device solves it after you unlock it, and the site checks the answer against the public key it already has.
Nothing secret ever crosses the internet. That’s the difference that matters. A password is a shared secret, which means both you and the website hold the same string of characters. If a crook tricks you into typing it on a fake page, or breaks into the company’s servers and grabs the file, your account is theirs. A passkey has no shared secret to steal. There’s nothing on the company’s end that unlocks your account, and nothing for you to accidentally hand over.
What Turning One On Actually Does for Your Security
This is the part that matters for you, so let me be specific about the win rather than waving at “it’s more secure.”
Passkeys kill phishing on the accounts where you use them. Phishing is when someone builds a fake login page, gets you to enter your credentials, and walks off with them. It’s the single most common way regular people lose accounts. When you create a passkey for, say, chase.com, your device ties that key to that exact web address. Land on a lookalike like chase-secure-login.com and your device checks the address, sees it doesn’t match, and refuses to sign in. You don’t have to spot the fake. The math spots it for you. That’s a real protection that doesn’t depend on you being sharp at the wrong moment.
Passkeys also survive data breaches. Because the company only stores your useless public key, a breach of their servers gives an attacker nothing to log in with. And since there’s no password, there’s nothing to reuse. A huge share of account takeovers happen because someone reused a password that later leaked from a different site. A passkey has no leaked-and-reused failure mode. It also quietly does the job a text-message code or authenticator app used to do, since it proves you have the device and were able to unlock it.
So for the two attacks most likely to actually hit you, phishing and stolen or reused passwords, turning on a passkey genuinely closes the door. That’s not marketing. It’s how the thing is built.
Where the Security Win Stops
Here’s the honest limit, and it’s the reason I’d never tell you a passkey makes an account “safe” rather than “safer.”
On most sites, adding a passkey doesn’t remove your password. It sits next to it. The account now has a strong new front door, but the old doors are all still standing: you can still log in with the password, and you can still reset that password by email or text. Your real security is set by the weakest way into the account, not the strongest. So a smart attacker doesn’t fight the passkey at all.
The strong front door, the weak back door.
A phisher won’t attack your passkey. They’ll send you to a fake page that says “passkey isn’t working, sign in with your password instead,” and plenty of people will do exactly that. Or they’ll skip you entirely and trigger the “forgot password” flow, which often sends a reset code by text. That code can be stolen through a SIM swap, which is when a criminal cons your phone carrier into moving your number to a phone they control. A passkey on an account that still allows password login and SMS recovery is a deadbolt on a door that’s propped open around the side.
Two more limits worth knowing. Support is uneven. The big names are on board, but only a fraction of the wider web offers passkeys today, so you’ll be typing passwords for a good while no matter what the headlines say. And recovery is the genuine soft spot. If your only passkey lived on a phone you lost before it synced anywhere, you can be locked out, which is the flip side of “no shared secret.” The security model that makes passkeys hard to steal also makes them harder to get back.
None of this means don’t use them. It means use them with clear eyes. The win is that you remove yourself from the phishing and password-reuse firing line on your most important accounts. That’s a lot. It just isn’t everything.
So Should You Use Them?
Yes, and here’s the simple way to decide where. Turn a passkey on wherever the account is worth protecting and the site supports it, starting at the top of your list rather than the bottom.
Your email comes first, because your email is the reset point for almost everything else you own. Whoever controls your inbox can walk into your other accounts through their “forgot password” doors. After email, your primary Apple, Google, or Microsoft account, then your bank. Those are the accounts a criminal actually wants, and they’re exactly the ones where passkeys are ready today. Chase, Bank of America, Wells Fargo, Capital One, PayPal, and the major platforms all support them now, and the federal government has been pushing the same direction. CISA recommends phishing-resistant sign-in like passkeys as the strongest form of two-factor authentication.
You don’t need to convert every account, and you shouldn’t wait until you can. The value is front-loaded. A handful of passkeys on your highest-value logins buys you most of the protection available.
What to Actually Do
The right posture is calm and hybrid. You’re not picking the new way over the old way. You’re using each where it’s strongest, and closing the weak doors where you can.
Turn on passkeys for your top accounts, email first, then platforms and bank. Where a site lets you remove the password or switch off SMS recovery after you’ve added a passkey, do it. That’s what turns a passkey from a nice addition into an actual security upgrade, because it starts closing the back doors instead of just adding a front one.
Keep a password manager for everything else. Most of your accounts will need passwords for years yet, and the only sane way to have a strong, unique one for each is to let software remember them. That single habit does more for your security than almost anything else on this list, and it costs you a few minutes to set up.
Keep two-factor authentication on anything important, and lean toward an authenticator app over text messages. App-based codes can’t be lifted through a SIM swap. The FTC’s guidance on phishing makes the same point: a second factor is what stops an attacker who already has your password.
And back up your keys. Make sure your passkeys sync through your Apple or Google account so a lost phone doesn’t lock you out, and save any recovery codes a service hands you. While you’re tightening things up, it’s worth pairing this with a credit freeze at all three bureaus, which blocks a different kind of door than a passkey does.
The Honest Bottom Line
Forget whether passkeys are replacing passwords. That’s a question for people who write about technology, not people trying to protect their accounts. The question that matters is whether turning them on makes you safer, and the answer is a clear yes with a clear boundary. On your most important accounts, a passkey removes you from the two attacks most likely to actually get you, phishing and stolen passwords. It doesn’t make the account bulletproof, especially while the old password and text-message recovery are still hanging around behind it. So turn passkeys on where they count, close the weaker doors when the site lets you, and keep strong unique passwords and app-based two-factor everywhere else.
You don’t need the password to die to be meaningfully safer this week. You just need to use the tools already sitting in your account settings. If you’re weighing whether to pay for extra help on top of these free steps, my take on whether identity theft protection is worth it is the honest next read.
Tom Reardon spent over 20 years in product and operations at major identity protection providers. He writes at MyScamGuide.com to give consumers the honest picture the industry’s marketing never did.
Recommended resources:
- CISA: Turn On Multifactor Authentication: the federal guide to phishing-resistant sign-in, including passkeys
- FTC: How to Recognize and Avoid Phishing Scams: what phishing looks like and how to shut it down
- IdentityTheft.gov: the FTC’s official recovery resource if an account is compromised