What are passkeys? A cybersecurity researcher explains how you can use your phone to make passwords a thing of the past (2024)

Passwords could soon become passé.

Effective passwords are cumbersome, all the more so when reinforced by two-factor authentication. But the need for authentication and secure access to websites is as great as ever. Enter passkeys.

Passkeys are digital credentials stored on your phone or computer. They are analogous to physical keys. You access your passkey by signing in to your device using a personal identification number (PIN), swipe pattern or biometrics like fingerprint or face recognition. You set your online accounts to trust your phone or computer. To break into your accounts, a hacker would need to physically possess your device and have the means to sign in to it.

As a cybersecurity researcher, I believe that passkeys not only provide faster, easier and more secure sign-ins, they minimize human error in password security and authorization steps. You don’t need to remember passwords for every account and don’t need to use two-factor authentication.

How passkeys work

Passkeys are generated via public-key cryptography. They use a public-private key pair to ensure a mathematically protected private relationship between users’ devices and the online accounts being accessed. It would be nearly impossible for a hacker to guess the passkey – hence the need to physically possess the device the passkey is accessed from.

Passkeys consist of a long private key – a long string of encrypted characters – created for a specific device. Websites cannot access the value of the passkey. Rather, the passkey verifies that a website possesses the corresponding public key. You can use the passkey from one device to access a website using another device. For example, you can use your laptop to access a website using the passkey on your phone by authorizing the login from your phone. And if you lose your phone, the passkey can be stored securely in the cloud with the phone’s other data, which can be restored to a new phone.

Why passkeys matter

Passwords can be guessed, phished or otherwise stolen. Security experts advise users to make their passwords longer with more characters, mixing alphanumeric and special symbols. A good password should not be in the dictionary or in phrases, have no consecutive letters or numbers, but be memorable. Users should not share them with anyone. Last but not least, users should change passwords every six months at minimum for all devices and accounts. Using a password manager to remember and update strong passwords helps but can still be a nuisance.

Even if you follow all of the best practices to keep your passwords safe, there is no guarantee of airtight security. Hackers are continuously developing and using software exploits, hardware tools and ever-advancing algorithms to break these defenses. Cybersecurity experts and malicious hackers are locked in an arms race.

Passkeys remove the onus from the user to create, remember and guard all their passwords. Apple, Google and Microsoft are supporting passkeys and encourage users to use them instead of passwords. As a result, passkeys are likely to soon overtake passwords and password managers in the cybersecurity battlefield.

However, it will take time for websites to add support for passkeys, so passwords aren’t going to go extinct overnight. IT managers still recommend that people use a password manager like 1Password or Bitwarden. And even Apple, which is encouraging the adoption of passkeys, has its own password manager.

What are passkeys? A cybersecurity researcher explains how you can use your phone to make passwords a thing of the past (2024)
Top Articles
If you can’t open a website in Safari on Mac
Which USMLE Step Exam is the Hardest?
Worcester Weather Underground
Uhauldealer.com Login Page
Splunk Stats Count By Hour
Bashas Elearning
What Are the Best Cal State Schools? | BestColleges
FFXIV Immortal Flames Hunting Log Guide
Jefferey Dahmer Autopsy Photos
Sprague Brook Park Camping Reservations
Craigslist Nj North Cars By Owner
Chase Claypool Pfr
What's New on Hulu in October 2023
Xm Tennis Channel
[PDF] INFORMATION BROCHURE - Free Download PDF
Alexandria Van Starrenburg
Daily Voice Tarrytown
Urban Dictionary: hungolomghononoloughongous
The Exorcist: Believer (2023) Showtimes
Zack Fairhurst Snapchat
TBM 910 | Turboprop Aircraft - DAHER TBM 960, TBM 910
Craigslist Maui Garage Sale
Kringloopwinkel Second Sale Roosendaal - Leemstraat 4e
Craigslist Personals Jonesboro
11 Ways to Sell a Car on Craigslist - wikiHow
Craigslist Pennsylvania Poconos
Accuweather Minneapolis Radar
Helpers Needed At Once Bug Fables
1979 Ford F350 For Sale Craigslist
New Stores Coming To Canton Ohio 2022
Pulitzer And Tony Winning Play About A Mathematical Genius Crossword
1636 Pokemon Fire Red U Squirrels Download
Orange Park Dog Racing Results
lol Did he score on me ?
10 Best Quotes From Venom (2018)
Laveen Modern Dentistry And Orthodontics Laveen Village Az
Bad Business Private Server Commands
Makemkv Key April 2023
Spn-523318
The TBM 930 Is Another Daher Masterpiece
R/Moissanite
Gravel Racing
Wunderground Orlando
Clausen's Car Wash
Pa Legion Baseball
How Much Is 10000 Nickels
Denise Monello Obituary
Gon Deer Forum
Avance Primary Care Morrisville
What is a lifetime maximum benefit? | healthinsurance.org
300+ Unique Hair Salon Names 2024
Fallout 76 Fox Locations
Latest Posts
Article information

Author: Jamar Nader

Last Updated:

Views: 6019

Rating: 4.4 / 5 (55 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Jamar Nader

Birthday: 1995-02-28

Address: Apt. 536 6162 Reichel Greens, Port Zackaryside, CT 22682-9804

Phone: +9958384818317

Job: IT Representative

Hobby: Scrapbooking, Hiking, Hunting, Kite flying, Blacksmithing, Video gaming, Foraging

Introduction: My name is Jamar Nader, I am a fine, shiny, colorful, bright, nice, perfect, curious person who loves writing and wants to share my knowledge and understanding with you.