Passkeys Are Replacing Your Passwords Right Now
Passkeys cannot be phished or stolen in a breach, and 75% of people have one. Here is how they work and why your recovery flow is now the weakest link.

Table of contents
Your bank asked if you wanted to use Face ID instead of your password. You tapped yes without reading much, and now signing in takes half a second and no typing.
You just created a passkey. About 75% of consumers have now enabled at least one, mostly without deciding to, and the FIDO Alliance counts roughly five billion in active use.
The security improvement is real and larger than most upgrades you will be offered this decade. The part worth your attention is where the weakness moved to, because it did not disappear.
Key Takeaways
- Roughly 75% of consumers have at least one passkey, with about five billion active worldwide
- A passkey cannot be phished or stolen in a server breach, because the secret half never leaves your device
- Attackers have responded by targeting account recovery and post-login sessions instead
- Your real security is now set by your weakest recovery path, which is usually still email or SMS
How passkeys actually work
Strip away the branding and a passkey is a pair of mathematically linked keys created when you register.
The private key stays on your device, locked behind Face ID, Touch ID or your PIN. The public key goes to the website, which stores it openly because on its own it is useless.
When you sign in, the site sends a challenge. Your device signs it with the private key. The site verifies that signature against the public key it already holds. The FIDO Alliance, which maintains the standard, calls this possession plus biometric verification.
Two consequences follow, and they are the whole argument.
First, a server breach gets an attacker nothing. There is no password file to steal, only public keys that were never secret. Compare that to any password breach you have received an email about.
Second, and more useful day to day: a passkey cannot be phished. Your device checks the domain before it signs anything. Land on a convincing fake of your bank and the authentication simply does not complete, because the domain does not match. You cannot be tricked into typing a passkey into the wrong box, since there is no typing.
That matters because phishing has become considerably harder to spot by eye, as we covered in the tells that still give AI scams away. Passkeys remove the judgement call entirely.
Where your passkeys live
A fair objection: if the key is on one device, what happens when that device is at the bottom of a lake.
Passkeys sync. iCloud Keychain handles it across Apple devices, Google Password Manager across Android and Chrome, and third-party managers like 1Password and Bitwarden work across both. Apple's documentation covers how the sync is end-to-end encrypted.
This is also the design decision people argue about. Syncing makes passkeys usable but ties your keys to a platform account. Lose access to that account and you have a genuine problem, which brings us to the part nobody markets.
The weak point moved, it did not vanish
This is the section to read twice.
The cryptography is not the target any more, because attacking it is pointless. Attackers shifted to the recovery flow and the session after you log in.
Think about what happens when you lose your phone. Most services fall back to something: a code emailed to you, an SMS, a support call, a security question. Your account is only as strong as that fallback, no matter how good the passkey is.
Trace it through a real chain:
- Your bank login uses a passkey, protected by Face ID. Excellent.
- Lost device recovery for that bank sends a code to your email.
- Your email is protected by a password and an SMS code.
- Your phone number can be moved by anyone who convinces a carrier they are you.
The effective security of that bank account is not the passkey. It is the phone shop. You have built a vault door onto a chain whose weakest link is a conversation with a customer service representative.
This is why recovery design was a stated barrier for 16% of organisations that have not gone fully passwordless. It is the hard part, and consumers inherit the problem. Regulators are pushing the same direction, with several financial supervisors moving to phase out SMS one-time codes specifically because they are the soft underbelly.
Device-level protection has improved a great deal, as our piece on on-device processing in smartphones covers. Recovery flows have not kept pace.
Audit your own chain in fifteen minutes
Practical exercise, and it is genuinely worth doing once.
Pick your five most valuable accounts. Usually primary email, bank, the app store account holding your cards, your password manager, and whichever social account could be used to impersonate you.
For each, answer one question: what happens if I lose my phone right now? Go into account settings and actually read the recovery options. Most people have never looked.
Then fix in this order:
- Email first, always. It is the recovery path for everything else, so it deserves the strongest protection you can apply. A passkey plus a hardware key if you have one.
- Remove SMS wherever an alternative exists. An authenticator app or a second passkey both beat a text message, because neither can be moved by a carrier.
- Save your recovery codes somewhere offline. Printed, in a drawer. This is the one situation where paper genuinely outperforms a screen.
- Register a passkey on two devices where the service allows it, so losing one is an inconvenience rather than an emergency.
If a phone is compromised rather than lost, the picture differs again, and our look at how to stay safe from device-level attacks covers that scenario.
Should you switch everything over?
Yes, with one sequencing rule.
Add passkeys as they are offered, starting with email, then financial accounts, then everything else. Most services run them alongside your existing password rather than replacing it, which is the sensible way in.
Do not delete your password until you have tested recovery. Sign out fully, sign back in with the passkey, and confirm you know what the fallback is. Discovering a broken recovery path while locked out is a bad afternoon.
Adoption is running at about 68% of organisations deploying, piloting or rolling out passkeys for staff, so the choice is being made for a lot of people regardless. Better to move deliberately.
Frequently Asked Questions
What is a passkey and how does it work?
A passkey replaces your password with a pair of cryptographic keys. The private key stays on your device behind Face ID, Touch ID or a PIN, while the website stores only the public key. Signing in means your device proves it holds the private key without ever sending it.
Are passkeys safer than passwords?
Substantially. They cannot be phished, because your device verifies the domain automatically, and they cannot be stolen in a server breach, because the secret half is never stored there. The remaining risk sits in account recovery rather than the passkey itself.
What happens to my passkeys if I lose my phone?
If they sync through iCloud Keychain, Google Password Manager or a password manager, they are available on your other devices. If not, you fall back to the service's recovery process, which is why auditing that process matters more than the passkey itself.
Can passkeys be hacked?
The passkey itself is extremely difficult to attack, so attackers have moved to the recovery flow and to hijacking sessions after login. A passkey protecting an account whose recovery runs through SMS is only as strong as that text message.
Should I delete my password after setting up a passkey?
Not immediately. Keep it until you have signed out and signed back in with the passkey, and confirmed you understand the recovery path. Most services support both at once, which makes a gradual switch the safer approach.
The part to act on
Passkeys are a genuine improvement and you should take them wherever they are offered. Phishing stops being a judgement call, and breach notifications stop mattering for those accounts.
But the attack did not go away. It relocated to the flow you use when something goes wrong, which almost nobody has looked at.
Spend fifteen minutes this week on your five most important accounts and read what happens when you lose your phone. That exercise, not the passkey, is what determines whether your accounts are actually safe.
Written by
Nora Whitfield
Technology & AI
Covers the technology beat for Quick Trend Insights, with a focus on what new AI tools and consumer hardware actually change for the people using them.
Related Articles
View all
Your Smart TV Is Watching What You Watch
Smart TV tracking captures your screen every 15 to 60 seconds, even over HDMI. Here is what ACR really records, who pays for it, and how to switch it off.

AI Scams: The Tells That Still Give Them Away
The FBI named AI a crime category for the first time after $893 million in losses. The old advice about spotting scams no longer works. Here is what does.

Robotaxis Take Paying Riders: Are They Safe?
Tesla started paid Cybercab rides in Austin, then drew a federal safety probe weeks later. Here is what a car with no steering wheel means for riders.
