Passkeys, and why they end phishing
The first login method that cannot be handed to the wrong person, because it cannot be spoken.
Updated 2026-09-26
Passkeys are the first genuinely new login method in decades, and the first that cannot be phished. That claim gets made loosely about a lot of things. Here it is literally true, and it is worth understanding why.
How they work, without the cryptography
When you create a passkey, your device generates two matched keys. The site keeps one, which is useless on its own. Your device keeps the other and never hands it over — not to the site, not to you.
To sign in, the site sends a challenge. Your device unlocks with your face, fingerprint or PIN, answers the challenge, and the site checks the answer against its half.
There is no secret to type, and no secret to give away.
Why phishing stops working
A passkey is bound to the site's actual domain. Your device will only answer a challenge from the domain the passkey was made for.
So a perfect copy of your bank's login page, on barc1ays-secure.com, cannot ask for something it is able to receive. There is nothing for you to type in the wrong place, no code to read out, nothing to intercept. The attack does not fail because you were careful. It fails because it is not possible.
That is a different category from "harder to phish", which is the best a password or an authenticator code can manage.
The honest downsides
Losing the device. Real, and mostly solved: passkeys sync through iCloud Keychain, Google Password Manager or your password manager, so a new phone gets them back. But if you store one only on a single device with no sync, losing it means account recovery.
Recovery is the weak point. An account with a passkey and a "reset by SMS" fallback is only as strong as the SMS. Attackers go for the fallback, so tidy those up too.
Not everywhere yet. Most large services support them. Plenty of smaller ones do not.
Ecosystem awkwardness. An Apple-made passkey works on Windows via a QR code and your phone. It works, it is a few more seconds, and it is better than it was.
Getting started
Turn them on where they matter most and where they are best supported: your Google or Apple account, Microsoft, PayPal, Amazon, and any bank that offers them.
You do not have to delete the password. Most services keep it as a fallback, and having both is already a large improvement.
Look for "Passkeys", "Sign in without a password" or "Security keys" in account settings.
Where they sit against everything else
Best to worst, briefly: passkeys, then a hardware key, then an authenticator app, then SMS codes, then nothing. The full reasoning is in two-factor authentication, ranked.
The short version: if a service offers a passkey, take it. It is the only option on that list that removes the attack rather than making it harder.
Check a password Free, and it needs no account.