Passkeys are the latest, and some say greatest, account security mechanism, but many users remain confused about the technology.
Well-known tech writer Leo Notenboom recently published an article titled How Passkeys Work (A No-Tech Version), which is perhaps the best and easiest-to-understand explanation I’ve seen. However, the majority of comments from Leo’s readers prove that many users are still struggling to grasp the passkey concept.
- You also might like: Unlocking Success: Navigating Your Way With A Passkey
Here then are some of the main points of confusion about passkeys clarified in the simplest of terms:
- Passkeys Are Per Device: Passkeys are saved on the device on which they are created, and the passkey will only work on the device on which it is created
- Passkeys & Password Managers: Using a cloud-based password manager, such as Bitwarden, will allow for passkeys to be shared across devices. However, the same password manager must be used across all devices
- Passkeys & Passwords: Creating a passkey does not mean that a password previously created for that account will no longer work; both are valid. The only way a password will become superseded by a passkey is if the service/website itself stops accepting passwords, and passkeys then become the only option
Passkey Pros:
Enhanced Security:
- Encryption: Because it’s encrypted, a passkey cannot be viewed or guessed by anyone
- Breach Protection: Passkeys protect the user in cases of external data breaches because the private key – which allows access to the account — never leaves the device
Passkey Cons:
- Lost or Stolen PC: If a PC is lost or stolen and the person now in possession manages to gain access to the system, then that person will also have free access to all your accounts. You need to ensure that access to the system is protected by a strong security measure, such as a very strong password, PIN, or biometrics
- Fresh/Clean Installs: If you perform a fresh/clean operating system install, all passkeys will be lost unless they are stored in a password manager
BOTTOM LINE:
The underlying problem is that the passkey technology is complex and evolving, which does make it very difficult to explain, let alone to understand. Heck, even I am not altogether comfortable with the concept.
That said, it seems passkeys are the way of the future, so I guess we’ll all eventually need to get on board. In the meantime, I’ll stick with a strong password together with 2FA.
How about you? Are you into passkeys or just as confused as many users appear to be?
—
