Email, Facebook, online banking, shopping or any app — we need an identity to enter almost every place on the internet. For a long time the most familiar key to that identity has been the password. We have had to build complicated passwords mixing capital letters, small letters, numbers and special characters. We have also heard the advice not to use the same password in more than one place, for security. But a new word has now appeared alongside that familiar arrangement in the world of technology: the passkey. This technology for logging in without a password is slowly becoming popular. The question therefore arises: will passkeys take the place of passwords entirely in future?
The problem with passwords arises mainly from people’s habits in using them. Many use the same or a similar password across different accounts so that it is easy to remember. Others use a date of birth, a mobile number, a name or some simple word. That can make a password comparatively easy to guess. And if a password leaks from a website’s database, several accounts can be put at risk where the same password has been used on other services. Taking a password from a user by leading them to a fake website through phishing is another familiar problem.
Passkeys try to solve this problem in a different way. Here the user does not have to type a password that has to be remembered. Instead, a cryptographic key is used between the device and the website. Broadly speaking, when a passkey is created, a “public key” and a “private key” are generated. The public key may be stored with the online service concerned, while the private key stays on the user’s device or in a related secure system. The important point is that the private key is not normally sent to the website’s server in the way a password is.
So how do you log in? Suppose you have opened an account on a website using a passkey. When you go to enter it again, the website can set your device a cryptographic challenge. The secure system on your device answers that challenge using the private key. The answer is then verified with the public key held by the website. From the user’s side the whole process can feel much simpler: the login is completed using the phone’s fingerprint reader, face recognition, a PIN or the device’s screen lock.
This is where the big difference lies. Fingerprint or face data is not sent to the website as a password. Rather, the device’s local security system authenticates the user and permits the use of the cryptographic key concerned. So there is no need to send your biometric data to a website every time you log in to it.
Another important advantage of passkeys is their ability to resist phishing. With an ordinary password, a user can go by mistake to a fake site that looks like the real one and type the password in. In the passkey system the cryptographic identity is tied to a particular website or service. That makes it far harder to be made to log in with a passkey on a fake website. This is why a passkey is not simply a technology for reducing the nuisance of remembering passwords. It is also bringing a large change to the method of verifying online identity.
Passwords have not become obsolete, however. Countless websites and accounts around the world still depend on them. Many users have older devices or use services that do not support passkeys. In some cases account recovery, backup or another authentication method may also be needed alongside a passkey. For the present it is therefore more usual for passkeys and passwords to run side by side.
Passkeys are also connected with password manager systems. Modern devices and various password managers can help in storing and using passkeys. So questions of how a passkey will be available when a user moves from one device to another, how it will be backed up and how an account can be recovered have also become important. In other words, a passkey is not just a matter of remembering a word, as a password is; it is a system tied to the user’s device, account and secure identity arrangements.
One thing is important to keep in mind here: a passkey does not mean the end of every security problem. If someone else takes control of a user’s phone or computer, if the device’s screen lock is weak, or if the user is deceived, various kinds of risk can arise. Using a strong device PIN, keeping software regularly updated, managing accounts securely and avoiding suspicious links therefore remain important.
Technology companies are also moving towards a password-free future. Standards such as FIDO2 and WebAuthn, created by the FIDO Alliance, are playing an important part in advancing strong cryptographic authentication as an alternative to passwords. Large technology companies such as Apple, Google and Microsoft have added passkey support on various platforms. As a result the opportunity for users to create and store passkeys and use them across devices is slowly growing.
Imagine opening an account on a new website in future. The site does not tell you to “create a strong password”; it says “create a passkey”. You give your phone’s fingerprint or approve it with the screen lock, and the account is created. The next time you log in, your identity is confirmed the same way. There is no password to remember or to type over and over. That experience is the central aim of the passkey.
So which is the login system of the future, the passkey or the password? In reality the answer is not simply one at the expense of the other. Passwords are still widely used, but passkeys are advancing as a technology that can reduce the need for password-based logins. Their importance is growing in particular because of phishing resistance, user convenience and cryptographic security. In future, perhaps, we will no longer think “what was my password?” but will tell our phone or computer “I am who I am”, and the technology will prove it.
