What I Actually Tell People When They Ask About Passkeys
More people are asking me about passkeys than about almost anything else at the moment. They'll be logging into their bank or their email, see a prompt asking if they want to "create a passkey instead", and message me wondering if it's safe, if it's a trick, or if they're about to lock themselves out of their own account. So here's the honest, plain-English version of what I tell them.
What a Passkey Actually Is
A passkey replaces your password with something tied to your actual device, usually unlocked with your face, your fingerprint, or your phone's PIN. There's no string of characters to type, remember, or accidentally hand over to a fake login page. Behind the scenes it's a pair of cryptographic keys, one that stays locked on your phone or computer and never leaves it, and one that sits with the website you're logging into. Neither one is any use without the other, which is the whole point.
You don't need to understand the cryptography to use one safely. All you need to know is that when a site asks you to create a passkey, it's asking to swap a password (a shared secret that can be guessed, leaked, or phished) for something that can't be typed into a fake page by mistake, because there's nothing to type.
Why They're Safer Than a Password, Even a Good One
I've written before about the method I actually use to build a password worth trusting, and even a properly random, unique password still has one weakness: you or your browser has to enter it somewhere, and a convincing fake login page can catch that. A passkey can't be phished the same way, because it only works on the genuine site it was created for. If a scam page copies your bank's login screen pixel for pixel, your passkey simply won't respond to it, because the underlying address doesn't match. That single fact removes one of the most common ways people get caught out, without you having to spot anything suspicious yourself.
What Happens If You Lose Your Phone
This is the question I get asked most, and it's a fair one. Passkeys are usually backed up to your Apple, Google, or Microsoft account and sync across your other devices, so losing one phone doesn't lock you out for good, the same way losing your phone doesn't delete your saved passwords from a password manager. Most sites also let you register more than one passkey, or fall back to a traditional login method if you genuinely lose access everywhere. I'd still treat losing a phone as a reason to check your account recovery options are up to date, the same as I would with any account, passkey or not.
Where I've Already Switched, and Where I Haven't
I've moved over on my email and a couple of accounts where a breach would genuinely hurt, and it's been painless every time, a face scan or a fingerprint and I'm in. I haven't switched everywhere yet, mostly because not every site supports it, and I'm in no rush to chase it down site by site. That's the realistic way to approach this: switch where it's offered on the accounts that matter most, and let the rest catch up over time rather than treating it as an all-or-nothing project.
A Word for Families Sharing One Device
I get asked about this a lot by people helping an older parent or a partner who shares a tablet or a family computer. Because a passkey is tied to a face, fingerprint, or device PIN rather than something typed in, it can actually make shared devices safer, nobody can peer over a shoulder and memorise a password if there's no password to see. The one thing worth checking is that each person is set up with their own face or fingerprint profile on a shared device before you start creating passkeys, otherwise you can end up with everyone's accounts unlocking for everyone. Two minutes in the device's settings sorts that out properly.
Passkeys and Password Managers Aren't Rivals
This is the bit that trips people up. A passkey isn't something you need to remember or store yourself, it lives on your device or in your password manager, and a good password manager will actually create, store, and sync your passkeys alongside the passwords you still need for the sites that haven't caught up yet. I use NordPass for exactly this, it handles both without me having to think about which system a particular login is using. If you're still relying on your browser to remember everything or, worse, reusing the same password everywhere, that's genuinely the more urgent fix to make first.
Should You Switch Today?
If a site you use offers a passkey, I'd say yes, set it up, it takes less time than resetting a forgotten password ever did. I wouldn't go out of your way to demand it from every service you use, and I definitely wouldn't panic if half your accounts still ask for a password next year, this is a genuine industry shift but it's happening gradually, not overnight. Pair it with two-factor authentication on anything that doesn't support passkeys yet, I still treat that as non-negotiable on every account that matters, and you're covering the gap sensibly while the rest of the web catches up.
If you want a clearer picture of where passkeys fit into your wider setup, the UK's National Cyber Security Centre has straightforward guidance on moving away from passwords, or you can get in touch and I'll talk you through your specific accounts.
