Passkeys use public-key cryptography so a service stores a public credential rather than a reusable secret. The sign-in ceremony is bound to the legitimate site, which makes common phishing flows less effective.

This article is part of the cybersecurity technology guide library.

What improves

There is no password to type into a lookalike page and no shared secret for the service to leak. Device authentication can also make strong sign-in easier for ordinary users.

What remains

Attackers can still target active sessions, compromised devices, weak help-desk procedures, and recovery channels. A secure primary sign-in paired with weak recovery is still a weak account.

Deployment checklist

Support more than one trusted device, explain where credentials are synchronised, make recovery visible, notify users about new passkeys, and provide a way to review and revoke credentials.

AM

About the author

Arjun Mehta

Security & Software Editor

Cybersecurity, developer tooling, open-source software, and cloud systems.

No vendor-sponsored conclusions or affiliate relationships.
Version 1

Initial reviewed edition.