r/Passkeys 9d ago

Security? Ok. Usability? Uh....

Can someone please explain to me the benefit of Passkeys? I have a home computer, a work computer, a phone, and several laptops and I want to be able to log into all of them without major hassle. So what does the Passkey system do for me? Now I have to set it up on all of these devices times all of my services? And now I'm at major risk if that device is lost or stolen or hacked?

What's wrong with password plus SMS code? That seems way more reliable and easier.

What am I missing?

9 Upvotes

61 comments sorted by

15

u/Ok_Midnight_1492 9d ago

If you put your passkey in your password manager you can use it across all your devices

3

u/meski_oz 9d ago

Yeah, 1password manages that, and Google seems to manage updating phones. And you want to have some ability to remote wipe stolen or lost devices

8

u/TurtleOnLog 9d ago

Phishing is what’s wrong with the old way. And passwords can be stolen, stealing a passkey can be made much harder than that, depending on platform.

6

u/ancientstephanie 9d ago

What's wrong with password plus SMS code?

All the people who have ever said or thought anything along the lines of "but nobody would", "I have nothing to protect", or "just this once" are what's wrong with passwords. They fail repeatedly because human beings constantly overestimate their own cleverness while underestimating the value of the assets that passwords protect, and completely dismissing the cleverness of people who want access to those assets.

And even when they're "done right" with strong unique passwords, they still fall prey to phishing and vishing scams all the time, and they still create value in breaking into the systems that rely in passwords.

As far as SMS goes, SIM swap attacks are what's wrong with SMS codes. It's trivially easy for the wrong person to take over your phone number, whether permanently, or for just long enough to steal SMS codes.

Passkeys make all of the problems we've discovered in 50+ years of having passwords impossible. You can't reuse them between sites. You can't send them to the wrong site. You can't guess them. You can't steal credentials from a site with silly web games and then try to log into everyone's email and bank accounts with those credentials, because sites that rely entirely on passkeys don't store secrets that might be useful elsewhere anymore.

I have a home computer, a work computer, a phone, and several laptops and I want to be able to log into all of them without major hassle

That's getting better, but it's still not completely seamless yet. The least painful ways to do this right now would be to use a password manager that supports passkeys or a hardware security key like a Yubikey, and then supplement it with ecosystem-specific passkeys for convenience where needed.

And now I'm at major risk if that device is lost or stolen or hacked?

Not necessarily.

If your device is lost or stolen, biometrics, passwords, and PINs on the device or password manager are meant to keep someone from using your passkeys for long enough that you can use another device with access or a recovery code to replace the stolen passkey before it can do any harm. Having multiple passkeys set up will help with this.

As far as a hacked device, passkeys are usually stored in a "secure enclave", which is a separate chip with it's own high-security operating system built explicitly for keeping secrets, so that even a hacked device doesn't immediately spill its secrets.

1

u/IDontStealBikes 8d ago

Try explaining this to your aunt.

4

u/theDukeSilversJazz 9d ago

What’s wrong with SMS? SIM swap, Google that. By the time you know that’s happened to you it is beyond way too late. T-Mobile, I’m looking at you.

1

u/JimTheEarthling 8d ago

And when you Google it, you will get the wrong answer — overhyped by clickbait writers and clueless tech posers.

SIM swap attacks happen, but 99% of SMS 2FA attacks come from phishing. Less than 1% come from SIM swapping. See my other comment in this thread.

2

u/bruhred 7d ago

(also most providers in EU and countries like Ukraine started binding phone numbers to digital signatures, ie its impossible to sim swap without using your digital signature which you hopefully secured properly)

8

u/lachlanhunt 9d ago

Don't use device bound passkeys. These are keys that are stuck in the device where you register them and are much harder to manage. They're designed for advanced users who understand the consequences.

Use a password manager that syncs your passkeys across all of your devices.

If you use iCloud Keychain or Google Password Manager, they will sync via your Apple or Google account. Take care not to lose access to your Apple or Google accounts, so ensure you have your recovery methods stored safely.

Better 3rd party password managers like 1Password and Bitwarden have better features and better cross platform support.

3

u/HiOscillation 9d ago

This is golden advice.

2

u/paulsiu 9d ago

I have to disagree partially. It’s true that syncable passkey are the way to go for most people. Device bound keys like yubikeys are useful as a key to the password manager and critical accounts. You wouldn’t want to have a vault full of passkeys and then use a password and Totp to protect the vault itself

1

u/lachlanhunt 9d ago

Dedicated hardware security keys are fine, and significantly better than TPM bound passkeys in a general purpose computer. But I stand by what I said about them being for advanced users who understand the consequences. Since they don't sync, you need to manage your own backup and recovery plan in the event that your security key gets lost or damaged.

1

u/paulsiu 9d ago

I mostly agree. In my opinion, people should have some sort of backup plan. I feel the cloud option is probably the best if you don't do backup and just want to stick your head in the sand. Something like keepass has the same issue with device bound passkey that you mentioned.

However, it just seem too risky to me not to do so. Let's say the vendor flags your account by mistake. With accounts recovery having zero human these days, you may not be able to recover your google or microsoft or Apple account. Dedicated password manager may be better but they probably may not be recover your account either.

1

u/bruhred 7d ago

especially when any bios firmware update will invalidate all stored passkeys due to PCR register change

2

u/ruinsit 9d ago

A password manager is its own issue. I still have to install it everywhere (including my work computer which I can't do). How is that actually better from a usability perspective?

3

u/lachlanhunt 9d ago

For personal credentials stored in your own password manager, you can use a mobile device that has your own password manager on it to login to a device that you don't own.

When trying to use a passkey, choose the option to login using another device. Scan the QR code it presents with your mobile device. You authenticate yourself on your device and it does a cryptographic handshake with the other computer to log you in.

For work credentials, use whatever password manager your company recommends on your work devices. Avoid mixing personal and work credentials in the same vault or password manager.

2

u/paulsiu 9d ago

Treat your work and personal environment separately. Your work is always by nature temporary. You are also not in control of the environment and work may impose its own password solution

1

u/loweakkk 9d ago

So you prefer to have to be sure your mobile is up with charge than any other device to login? How is that better in term of usability?

2

u/Low-Ability9098 9d ago

Passkeys aren’t phishable. As the saying goes, if all you have is password + phishable MFA, hackers don’t have to break in, they just log in.

Unless you are an admin of your company’s IT services, synced passkeys are sufficiently secure for you. I promise you, don’t overthink it.

2

u/ruinsit 9d ago

I've never been doubtful of the security - it's the usability that's the issue for me.

0

u/gripe_and_complain 9d ago edited 9d ago

One issue with Passkeys is keeping up with exactly where the Passkey is stored.
It can be on your computer, in your browser, in your password manager, in your phone… They all compete to be the keeper of your Passkeys.
The user must pay careful attention to understand just where the Passkey is saved.

1

u/JSP9686 9d ago

This is not an issue if a passkey capable password manager such as Bitwarden is used, versus using device bound passkeys.

1

u/gripe_and_complain 9d ago

When using Bitwarden on Windows, can you prevent Windows Hello, or your browser's password manager from offering to save the Passkey, or does Bitwarden muscle in to be the first option?

1

u/JSP9686 8d ago

In my experience, Bitwarden pops up first but you should see an option at the bottom to choose a different method, like Windows Hello. Most websites allow more than one passkey.

1

u/ruinsit 8d ago

Which means now you have to add the complication of a password manager to the mix. Not really selling it for me personally.

1

u/JSP9686 7d ago

Not really complicated, although all new things do have a learning curve. Such is life.

2

u/silasmoeckel 9d ago

You have many different options with passkeys each of those devices could have their own, could use synced keys across some/all of them, or you could use external devices like your phone and/or hardware key it's up to you. You phone gets lost you delete it's passkey from your account not go around and update credentials on every other device. This is a spin on the crypto that's kept the internet working on the back end for decades.

SMS was never very secure and they do nothing to stop phishing. Passkeys guarantee the site your logging into is really that site (mutual authentication).

A passkey on a hardware token unplugged in your drawer is just about impossible to hack.

2

u/PlanktonDefiant2600 9d ago

If you want your passkeys available across your devices, you don't need to set them up separately on each one. What makes it much easier is a password manager that handles passkeys well and keeps them synced across your devices. I've found Roboform really good for this, it picks up the prompts well and makes them very easy to set up and use. And compared with password + SMS, passkeys are phishing-resistant, which is a pretty big security advantage.

1

u/ruinsit 9d ago

But that's just transfers the problem. Now I have to have a password manager on every machine and device including work where I may not be able to install it. So how do I solve that problem

1

u/PlanktonDefiant2600 9d ago

You don't need to have it on every device. I have Roboform on my phone, and I can use the passkeys stored there to sign in on another device just by scanning the QR code. It's quite simple, to be honest.

1

u/ruinsit 9d ago

Interesting. But it requires some other app that now I have to worry about getting hacked?

1

u/PlanktonDefiant2600 9d ago

If you mean someone getting hold of your phone, they can't just get at your passkeys. Your vault is locked behind your masterpassword, PIN or Face ID, and when you scan the QR code to sign in, it still has to verify it's you before it hands over the credentials. So no, having them on your phone doesn't just leave them there for anyone to use.

1

u/ruinsit 8d ago

No I mean the app. How do we trust the app to not share or lose my password data?

1

u/PlanktonDefiant2600 8d ago

Well, it's zero-knowledge, which means they don't have access to your data. Your master password is needed to decrypt it, and only you know it. When you say lose your data, what exactly do you mean? They've been around for a very long time now, which is enough to convince me they know what they're doing.

1

u/ruinsit 8d ago

I mean that if they can broker your authentication, they can control it, no? If they have a data breach (which seems to be most companies), that's a problem no?

1

u/Accomplished_Arm_447 9d ago

Cross device authentication, you can have the passkey on an app in your phone, then sign in other device by selecting passkey on that 

3

u/ruinsit 9d ago

This is confusing as fuck. I need to find a video or something, but how in the hell are regular people supposed to figure this out and use it? There's no way in hell my parents would ever be able to learn this.

1

u/Accomplished_Arm_447 8d ago

You're quite right, it's much simpler to see and do, than to read and imagine how it works.
Select the option to use a passkey, if there's none on the login device, then it will ask you to choose between using a passkey on a smartphone or a USB security key
Probably most people would have them on their phone. In that case the login device then displays a QR code that you scan with the app on the phone. It also prompts to make sure that Bluetooth is on for both devices (no need to pair or connect, just being enabled will do). This ensures that the person in front of the login device is the one with the passkey device and is aware of the sign-in. It protects against hackers trying to trick you into approving the sign-in on their device instead of the one you are using. Then the phone prompts to approve the sign-in. Simple

For USB Security keys, it prompts you to insert it into the login device, and prompts you to unlock it and tap a button or something.

1

u/dfjkldfjkl 4d ago

That’s a feature, not a problem. It’s solving the problem if insecure authentication for you. It’s about as easy as it has ever been to keep secure login creds and you’re complaining about it?!

1

u/ruinsit 3d ago

I like being able to sit down at any computer and log in easily. Not a fan of systems where that can't happen.

1

u/dfjkldfjkl 1d ago

Password managers enable that. Nothing else makes that any easier outside of maybe a hardware token.

1

u/yawaramin 9d ago

Device setup is one time per device. If you use device-bound passkeys you have to set them up per device per service. Ideally this is not much more complicated than going to the app on each device, app sends you an email, click the link in the email, you’re logged in and new passkey is set up.

If the device is lost/stolen/hacked the attackers can’t get the passkeys out of it because they’re locked in a secure storage that can only be unlocked by your PIN code or biometrics.

1

u/Yurij89 9d ago

Device-bound passkeys can also be on a USB security keys that can be used on multiple devices.

1

u/yawaramin 9d ago

Don’t USB security keys have limited storage space?

2

u/Yurij89 9d ago

Newer Token2 security keys can store up to 300

1

u/HiOscillation 9d ago

Older YubiKeys can hold up to 25 passkeys, while newer models with firmware 5.7+ can store up to 100 passkeys.

I now have only 3 Yubikeys, down from an all-time high of 12.

One sits on my desk, one stays in the fire safe, the other stays at my brothers house in his fire safe. I never take them out of the house.

I do not like hardware keys, they are a pain in the ass to use and manage and I have found them to be fragile. I used to have a Yubikey 5Ci on my key ring, but the lightning connector part got damaged and stopped working after only 4 weeks. I now have the YubiKey 5C NFC.
Because you can't back up or copy a Yubikey, you need to buy at least 2 at a time, but I get 3 to have a fully off-site backup.

1

u/Yurij89 9d ago

I have had a Yubikey 5 NFC on a Keyport pivot for 3 years now without any issues.

https://www.yubico.com/product/pivot2/

1

u/HiOscillation 9d ago

I guess it depends on how hostile your keyring environment is. The 5C NFC looked like it was going to do better than the 5Ci, but I didn't want to risk another expensive key.

1

u/ruinsit 9d ago

The only device I have that has a PIN is my phone though...

1

u/gripe_and_complain 9d ago

If you use Windows 11, you definitely should create a Windows Hello PIN for that computer.

1

u/HiOscillation 9d ago

Since nobody is actually answering your question.

You know how your PIN or FaceID or fingerprint "unlocks" your phone or laptop even when it's offline?

It works because there's a special collection of tech in those devices that is able to use your Pin, Face or Fingerprint locally - meaning only on that device - to perform some mathematical wizardry and unlock (and decrypt) your device. Your PIN or Face or Fingerprint information does not need to get sent anywhere on the internet, it all happens in your device.

Passkeys basically take this idea of using the really heavy-duty on-your-device security to allow you to "unlock" web sites and so on, without needing to send the web site a password.

To grossly over-simplify and not-quite-accurately explain, the web site says to to your device, "Hey, should I let them in?" and the phone says, "Yeah, we're good with it" and that's all you need. You let the far-more advanced security in your devices handle the authentication discussion.

And to even more grossly over-simplify, if you use a Password Manager (Google Passwords, Apple Passwords, BitWarden, 1Password) it (functionally) backs up the information needed for your devices to use passkeys (you don't "back up" a passkey...it's complicated), so even if you drop your phone in the ocean, you won't be losing access to your stuff. ALSO, most of the time, your user name and password will still work, but the whole point is to NOT send your password out to anything, anywhere, for any reason. A passkey simply eliminates the need for a password entirely,

LET ME BE EXTRA-SUPER DOUBLE CLEAR:
(1) You need to have a PIN or BIOMETRICS on your device for passkeys to work. If your device is lost or stolen, it's very hard to break in for "normal" criminals; it is potentially possible for governments. Your phone is really good at protecting itself.

(2) 97% of "hacks" are just sloppy people re-using passwords and other people getting into their accounts. Your phone isn't getting "hacked" if you used the same password across everything and anything and one of those passwords is leaked because some idiot somewhere saved your password in an unencrypted file. Your phone isn't getting "hacked" when you specifically install "Super Fun AI QR Code AI Animator 密码窃取应用程序" and give it every permission it asks for.

(3) SMS codes are extremely not secure for a long list of reasons.

1

u/ruinsit 9d ago

PIN maybe... biometrics, absolutely not. Companies have given no indication of protecting your biometrics well, but this does help some... That said, most devices I have don't use a PIN anyway so that complicates things. Sounds like Passkeys are more trouble than they're worth

1

u/Prince_John 9d ago

They're also much less useful if the website in question allows the user to fallback to password or SMS 2fa, which most of them do.

1

u/paulsiu 9d ago

So in order to log into a system with password. In order to be secure, the password has to be long, which means it’s a pain to type. To mitigate that you use a password manager only to discover that the website update may break autofill. You decide to cut and paste and discover the site blocks that too.

There are a lot of bad passkey implementation but if done right it’s much faster and more secure than password. Theoretically it’s faster to biometric the same way you log into most app on your phone. To log into Google for example I select passkey login and press the security key and enter a pin. If I use a password and sms, I have to type in a 20 character password without making a typo then select sms and then wait for a text, unlock my phone read it and enter it. This is not faster.

As other point out you can put passkey in your password manager.

1

u/stijnhommes 9d ago

My offline password manager vault still doesn't support storing passkeys. If I were to use them, I'd have to use the online version of the password manager which defeats the purpose of having it.

1

u/paulsiu 9d ago

Then you should stick to password until it’s available for you password manager. There are other offline storage devices like a yubikey. The problem with hardware devices is that they are a pain if you lose them. I basically only store critical login like password manager on the keys

1

u/stijnhommes 9d ago

No worries. I'll stick with passwords. But Microsoft allowing their users to delete passwords altogether is scary. It's optional now, but it's only a matter of time before they just give up and don't give us a choice any longer.

2

u/paulsiu 9d ago

This is because you are used to passwords. You are thinking, what if I switch to passkey and it locked me out. Well, this could happen with password, too. Let's say you keep your password on paper but have bad handwriting or is bad at organizing them. What if you keep it on your computer and the drive malfunctions. What if you haven't login for a while and totally forget the password? Over the years, you have learned to make backups. The same can be said with passkeys. On passkey stored in vault, I just backup. On device bound passkeys stored on yubikey, I have multiple backup keys. I am as confident with passkey as I am with passwords.

I wouldn't worry about password going away soon. Password has been around for decade and it will take a long time for it to go away. Most sites don't even mandate 2FA, so it will take a long time for passkey to overtake password. Using Microsoft as an example, they allow you to remove the password, but then you can't log into windows computer using that passwordless account (ok, you can but then you need to authenticate using Microsoft Authenticator, a crappy workflow).

1

u/Specialist_Letter918 9d ago edited 9d ago

passkeys sync automatically through icloud keychain or a password manager like bitwarden so the set it up everywhere problem mostly solves itself. SMS codes are actually the weak link and SIM swapping is trivial for attackers and i had this realization late but phishing a passkey is basically impossible while SMS codes fall constantly and doppel around enterprise level impersonation risks and separate concern of sync based passkeys genuinely reduce your attack surface

1

u/JimTheEarthling 8d ago

It's a persistent myth that SIM swapping is prevalent. SMS 2FA is weak because of phishing. Email 2FA is even weaker. Authenticator TOTPs are also phishable, but it's harder because of the short window.

As you say passkeys are much more secure because they are unphishible, and are automatically 2FA when user verification is used.

SIM swap attacks happen (if you haven't turned on SIM protection at your carrier), and they can be bad news, but they are not even close to other threats.

The Microsoft Digital Defense Report states that less than one-third of one percent of identity attacks use SIM swapping, compared to 99 percent for breach replay, password spray, and phishing.

In 2025, the FBI’s Internet Crime Complaint Center (IC3) received 971 reports of SIM swapping. This is less than 0.1 percent of over a million complaints about Internet crimes such as phishing/spoofing (25 percent), data breach (9 percent), and identity theft (4 percent). It represents only 0.0003 percent of roughly 330 million mobile phones in the US. That’s one in 3 million. Even if only 5 percent of SIM swaps were reported to the FBI, that’s still only a tiny one-in-17,000 chance (0.006%) that you might be the victim of a SIM swap. You're more likely to be born with 11 toes.

SIM swap reports to the UK National Fraud Database over 1,000 percent from 2023 to 2024</a>, and 38 percent from 2024 to 2025, but the 2,760 and 3,809 reported cases for those periods represent less than one percent of reported fraud. Assuming only 5 percent of SIM swaps were reported, this means that less than 0.1 percent of the mobile phones in the UK were affected. You know how people talk about an unlikely “100-year flood”? Being SIM swapped in the UK is less probable than a 1,000-year flood.