NOETRION

Browse by topic

← All articles
TECHNOLOGY · 7 MIN READ

Passkeys explained: why sign-in is changing

Learn what a passkey stores, why a fake website cannot use it like a stolen password, and what recovery still matters.

Passkeys are an alternative to entering a password. A passkey uses a cryptographic key pair: the website stores a public key, while the private key stays with an authenticator such as your device or password manager. You unlock its use with a device gesture such as a PIN or biometric check.

Your device
Private key
⇄Website
Public key
The private key is used to sign a challenge; the website verifies it with the public key. The secret key is not sent to the website.

What changes for phishing?

A password can be typed into a convincing fake page. WebAuthn credentials are bound to a website’s domain, so an impostor domain cannot obtain a valid signature for the real site. This is why passkeys are described as phishing resistant. It does not make every account problem disappear: recovery methods and access to your devices still matter.

Synced and device-bound passkeys

Some passkeys sync through a credential provider across your devices; others remain on one device or security key. Before depending on one method, check how your provider handles new devices and account recovery.

What to do when a site offers one

Create a passkey on a device or credential manager you control, keep its recovery options current, and review the site's other sign-in methods. A passkey is a useful security improvement, but the whole account is only as strong as its remaining recovery paths.

Sources and further reading