Skip to content
Mindcraft Impuls

Passkeys:
Signing in without passwords - and without a chance for phishing

Approx. 6 minutes read

Experience this topic as an interactive Cyber Snack:
just click and learn it all in 5 minutes.

Cyber Snack: start passkeys interactively

Open the login page, unlock the password manager, paste the password, unlock your phone, confirm the code: the classic login is tedious - and still the weak spot through which attackers most often get into other people's accounts. Passkeys turn this around. A quick glance at the camera or a finger on the sensor is enough. Signing in becomes not only faster, it also defeats phishing, because there is simply nothing left to type into a fake page.

Passkeys are no longer a niche topic. According to FIDO Alliance estimates, around five billion passkeys were in use worldwide in May 2026. Google has offered them as the default sign-in option for personal accounts since October 2023, and since May 2025 Microsoft has created new consumer accounts without a password by default. Even so, many users do not really know what happens when they sign in with a passkey - or where the remaining risks lie.

The June Cyber Snack makes exactly that clear: how passkeys work, why phishing pages technically cannot do anything with them, and what happens when a phone is lost or stolen.

What a passkey actually is

A passkey is a digital key that replaces the password. Instead of memorizing a string of characters and typing it in at every login, you confirm the sign-in the same way you unlock your phone or laptop: with face recognition, a fingerprint or your device PIN.

The term does not refer to a single vendor's product but to an open standard. Passkeys are based on FIDO2 and WebAuthn, developed by the FIDO Alliance and the World Wide Web Consortium (W3C) and supported by Apple, Google and Microsoft. That is why they work in all common browsers and operating systems - with major services such as Google, Amazon, Microsoft or PayPal, and increasingly with business applications too.

Setting one up usually takes just a few clicks: in the security settings of the account, you select 'Create a passkey' and confirm with your fingerprint, face or PIN. No technical knowledge is required - your device guides you through the process step by step. From then on, you sign in with your passkey.

Password versus passkey: the login compared

A direct comparison shows how big the difference is in everyday life. Suppose you do everything right with your password: you use a password manager and have two-factor authentication enabled. You open the login page, unlock the password manager, find the right password, paste it, then unlock your phone and confirm the second factor.

With a passkey, you open the login page, select 'Sign in with a passkey' and briefly place your finger on the sensor or look at the camera. That is all.

The figures confirm this impression. According to the FIDO Alliance Passkey Index from October 2025, based on data from companies such as Amazon, Google, Microsoft, PayPal and TikTok, a passkey sign-in takes 8.5 seconds on average, compared with 31.2 seconds for other methods. At the same time, 93 percent of passkey sign-ins succeed, versus only 63 percent for other methods. In May 2025, Microsoft even reported a success rate of around 98 percent for passkey sign-ins on its consumer accounts, compared with 32 percent for passwords.

Similar to 2FA - but technically something else entirely

The fingerprint or face scan is reminiscent of two-factor authentication (2FA), which many people already know. The experience is similar, but the technology is not. With 2FA, the password remains the first factor; the code or push confirmation is merely added on top. A passkey, by contrast, replaces both the password and the second factor.

A passkey combines two factors in itself: something you have (the device holding the private key) and something you are or know (biometrics or PIN). And unlike an SMS code or a code from an authenticator app, it cannot be intercepted on a fake page and passed on.

What happens behind the scenes when you sign in

Illustration of a key pair: public key on the server, private key on the smartphone unlocked by fingerprint
The public key is stored with the service, the private key stays with you - and it is only unlocked locally by fingerprint, face or PIN.

During setup, your device generates a cryptographic key pair: two long, random values that belong together mathematically but have different jobs. The private key stays with you - on your device, on a security key or encrypted in your password manager. The public key is stored with the online service, for example Google or Amazon.

When you sign in later, the service sends your device a kind of mathematical puzzle, the so-called challenge. Your device now asks locally for your fingerprint, face or PIN - this is the moment when it checks that it really is you in front of the device. Only after this approval does it sign the challenge with the private key. The server verifies the signature with the public key. If it matches, you are signed in - without a password ever being transmitted.

Two details are crucial here. First, your biometric data never leaves the device. The service only learns that the local check was successful. Second, only the public key is stored on the server. If the service is hacked, attackers get nothing they could use to sign in - unlike with stored passwords.

Why phishing fails against passkeys

Illustration of a fake login page where the passkey refuses to sign in, while it works on the genuine page
On a fake domain there is no matching passkey - the sign-in never even happens.

Perhaps the most important advantage is protection against phishing. A passkey is cryptographically bound to the genuine web address of the service it was created for. At every sign-in, the browser and operating system check which domain you are on and only offer the passkey where it belongs.

If a phishing email lures you to a deceptively genuine-looking page such as 'amaz0n' - with a zero instead of an O - simply nothing happens: no passkey exists for this address, and no valid signature for the real domain can be created there. Even if you fall for the fake, your device does not.

This matters above all for attacks designed to harvest credentials: from fake parcel notifications to cloned Microsoft 365 login pages behind seemingly harmless Teams invitations, as described in our insight Web meetings: when the attacker sits at the virtual table. Modern phishing kits even intercept one-time codes there in real time. Against a passkey, that does not help them.

A password can be given away. A passkey can only be used - and only where it belongs.

Synced or device-bound?

Illustration of a smartphone, tablet and laptop syncing a passkey via an encrypted cloud
Synced passkeys are available on all of your own devices - end-to-end encrypted.

Strictly speaking, there are two kinds of passkeys. Device-bound passkeys live permanently on a single device, for example a hardware security key. The private key cannot be read out or copied there. Most everyday passkeys, however, are synced passkeys: they are distributed to all your devices via iCloud Keychain, Google Password Manager or another password manager.

Even then, the private key remains protected: Apple and Google sync passkeys with end-to-end encryption, so the providers themselves cannot read them. What matters is this: the private key is never transmitted to the online service you sign in to - not even during the challenge. That is why hackers cannot grab it during sign-in.

For companies, the distinction matters. Synced passkeys are convenient and make recovery easier. Device-bound passkeys offer the highest level of security because the key cannot be copied - useful, for example, for administrator and other high-risk accounts. In a FIDO survey from February 2025, almost half of the companies rolling out passkeys were using a mix of both.

Lost, stolen, forgotten: the three most common questions

What happens if you lose your phone?

If a passkey exists only on that one device, you can no longer sign in with it. But the finder cannot copy or transfer it either. If the passkey is synced, you simply sign in with another device, such as your tablet or laptop. Otherwise, you go through the service's recovery options, often the password, and then create a new passkey on your new device. That is why it is best to set up a second device in advance or use syncing.

And what if someone steals your phone?

A thief may be holding the device with your passkeys, but cannot use them without your approval: nothing works without your face, fingerprint or PIN. It becomes dangerous if the thief knows the device PIN. That is exactly the scheme the Wall Street Journal described in early 2023: thieves in bars watched victims type in their passcode and then stole the iPhone - along with access to accounts and data.

Apple responded with Stolen Device Protection: when the feature is enabled and the iPhone is away from familiar locations, saved passwords and passkeys can only be used with Face ID or Touch ID - with no passcode fallback. The lesson applies to every device: use biometrics, choose a long device PIN and shield it when entering it in public.

Why does the old password remain a risk?

This is currently the biggest weakness. Many services keep the password in the background as an alternative sign-in option or emergency fallback. Anyone with a weak or reused password such as 'Summer2026' throws away the protection of the passkey: an attacker simply takes the old route. As long as the password cannot be switched off, all the rules for secure passwords still apply, as summarized in our insight Why passwords are never 100% secure.

Downgrade attacks: when the back door stays open

Proofpoint researchers showed in August 2025 that fallback methods are not a theoretical problem. They demonstrated how a phishing page can pose to Microsoft Entra ID as a browser that supposedly does not support passkeys. The victim is then offered a weaker sign-in method, such as an authenticator app or SMS code - and that is exactly what can be intercepted. According to Proofpoint, no attacks in the wild were known. The consequence is clear nonetheless: where passkeys have been rolled out, insecure alternatives should be switched off, at least for sensitive accounts.

Five rules for making the switch

1. Enable passkeys wherever possible

Check the security settings of important accounts such as email, your Microsoft or Google account, online shopping and payment services, and set up a passkey. It usually takes just a few minutes.

2. Protect the device itself

Use fingerprint or face recognition and a long device PIN instead of a short code. Shield your PIN when entering it in public and enable your device's theft protection features.

3. Prepare for emergencies

Set up passkeys on a second device or use end-to-end encrypted syncing. That way, you keep access even if a phone is lost.

4. Do not forget the old password

As long as the password remains active as an alternative, it must be long and unique. Where a service allows it, disable password sign-in altogether.

5. Be suspicious of fallback logins

If a page suddenly asks for a password or SMS code although you normally sign in with a passkey, be careful. If your device does not offer a passkey on a page, that may be a sign of a fake.

Passkeys in companies: where adoption stands

Among consumers, passkeys have gone mainstream. In the FIDO Alliance survey for World Passkey Day in May 2026, covering 11,000 people in ten countries, 90 percent said they were aware of passkeys and 75 percent had enabled them on at least one account. As early as October 2024, Amazon reported that more than 175 million customers had set up passkeys. In Germany, the picture was considerably different: in a survey by the Federal Office for Information Security (BSI) in spring 2024, only about a third of respondents even knew the term.

In companies, the picture is mixed. According to the same FIDO study of 1,400 decision-makers, 68 percent of organizations have deployed passkeys for employee sign-ins or are in the process of doing so. 82 percent name fully passwordless authentication as their goal, but only 28 percent have achieved it. Organizations using passkeys report, among other things, faster logins (45 percent), fewer password reset tickets (35 percent) and fewer phishing-related incidents (32 percent).

Platforms and authorities are driving the topic forward too. Microsoft announced that passkey profiles and synced passkeys would become generally available in Entra ID from March 2026; administrators can then specify whether only device-bound passkeys, only synced passkeys or both are allowed. Germany's BSI explicitly recommends passkeys and in autumn 2025 published a draft technical guideline (TR-03188) on operating passkey servers securely.

Limits and objections

Passkeys are not a cure-all. Not every application supports them; older line-of-business applications, VPN access or production systems in particular often still depend on passwords. Shared devices and functional accounts fit poorly with the principle of 'one person, one device, one key'. And switching between ecosystems is not yet seamless everywhere, even though the FIDO Alliance is working on new standards for securely exporting and importing passkeys.

Above all, the risk shifts. When the login itself is hardly attackable anymore, recovery and the help desk move into focus: if a phone call to the service desk is enough to register a new device or reset sign-in, that creates a new back door. And once signed in, users are not automatically protected against malware that hijacks an active session. Passkeys secure the sign-in - not everything that happens afterwards.

What awareness teams should take from this

For CISOs and awareness managers, the message is unusually positive: with passkeys, there is finally a security measure that is also more convenient. The hurdle is rarely the technology, but a lack of knowledge and mistrust. Many employees fear handing their fingerprint to their employer or a tech giant, or do not know what happens if they lose their phone.

This is exactly where awareness comes in: explaining that biometric data never leaves the device; showing how setup works in practice; clarifying which recovery routes exist. And teaching a new rule of thumb: anyone who normally signs in with a passkey and is suddenly asked for a password or SMS code should become suspicious.

The topic deserves priority. According to the Verizon Data Breach Investigations Report 2025, compromised credentials were the initial access vector in 22 percent of the breaches reviewed. Our insight Ransomware: why the ransom screen is only the end shows how quickly a single taken-over account can turn into a company-wide incident.

Conclusion

Passkeys are among the rare security measures that make life easier rather than harder. They replace the password with a key pair that cannot be guessed, cannot be handed over and cannot be typed into a fake page. The remaining risks lie mainly in our habits and devices: weak device PINs, old passwords as a back door and insecure recovery routes.

So at your next login, it is worth asking: is a passkey already available here? If so - set it up. A glance at the camera is faster than any password.

Sources

FIDO Alliance, October 14, 2025: "FIDO Alliance Launches Passkey Index Revealing Significant Passkey Uptake and Business Benefits".

FIDO Alliance, May 2026: "FIDO Alliance Reports Accelerating Global Passkey Adoption on World Passkey Day 2026"; FIDO Alliance, February 26, 2025: "New FIDO Alliance research shows 87 percent of US and UK workforces are deploying passkeys for employee sign-ins".

Microsoft Security Blog, May 1, 2025: "Pushing passkeys forward: Microsoft's latest updates for simpler, safer sign-ins"; Google, October 10, 2023: "Passwordless by default: Make the switch to passkeys"; Google, September 19, 2024: "Sync passkeys securely across your devices"; BleepingComputer, October 15, 2024: "Amazon says 175 million customers now use passkeys to log in".

Apple Platform Security: "iCloud Keychain security overview"; Apple Support: "About Stolen Device Protection for iPhone"; Wall Street Journal (Joanna Stern), February 2023, report on iPhone thefts after passcodes were spied on.

Proofpoint, August 13, 2025: "Don't Phish-let Me Down: FIDO Authentication Downgrade".

BSI, October 2024: passkey recommendation and consumer survey; BSI, autumn 2025: draft technical guideline TR-03188 (passkey servers); Microsoft Message Center MC1221452: passkey profiles and synced passkeys in Entra ID; Verizon, 2025 Data Breach Investigations Report.

Topic cluster