By J. Mesa
The first Thursday of May used to be World Password Day. This year the FIDO Alliance promoted World Passkey Day in its place, and Microsoft announced that new Microsoft accounts go passwordless by default. Google, Apple, Amazon, and most large banks now offer passkeys. If you run a small business, you will see the prompt soon, and your staff will ask what to do with it.
What is a passkey?
A passkey is a sign-in credential that replaces your password with a cryptographic key stored on your phone, computer, or security key. You approve a sign-in with your fingerprint, your face, or your device PIN. You type nothing, and you have nothing to remember.
Passkeys follow an open standard called FIDO2, built by the FIDO Alliance and the World Wide Web Consortium. Apple, Google, and Microsoft all support it, so a passkey works across phones, laptops, and browsers from different makers.
How does a passkey work?
When you create a passkey for a website, your device generates two linked keys.
- The private key stays on your device, protected by its security chip. It never leaves and nobody sees it, including you.
- The public key goes to the website. It can check a signature, and it can’t create one.
When you sign in, the website sends your device a challenge. You unlock the device with your fingerprint, face, or PIN. The device signs the challenge with the private key and sends the signature back. The website checks it against the public key and lets you in.
Your fingerprint or face never leaves the device. The biometric only unlocks the key locally. The website receives a signature and nothing else.
Are passkeys safer than passwords?
Yes, for four reasons.
- Nothing to phish. Your device ties each passkey to the real website address. A fake login page at a look-alike address gets no response, because the passkey for the real site does not match. You can’t hand over a secret you never knew.
- Nothing useful to steal from the website. A breach of the site’s database exposes public keys. Criminals can’t sign in with a public key.
- No reuse. Every passkey is unique to one account on one site.
- No guessing. There is no word to guess and no pattern to crack.
Most break-ins at small businesses start with a stolen or phished password. Passkeys remove that entire category for the accounts that support them.
Do passkeys replace multi-factor authentication?
A passkey combines two factors in one step: something you have, the device holding the key, and something you are or know, the biometric or PIN that unlocks it. For that reason, most services skip the extra code prompt when you sign in with a passkey.
Passkeys also beat the common forms of multi-factor authentication. A criminal can trick you into reading a text message code over the phone or approving a push notification. A passkey gives the criminal nothing to ask for.
What happens if I lose my phone?
This question stops most people, and the answer depends on where the passkey lives.
Synced passkeys live in a password manager: Apple Passwords with iCloud Keychain, Google Password Manager, or a third-party manager such as 1Password or Bitwarden. The manager encrypts them and syncs them to your other devices. Lose the phone, sign in to the manager on a new phone, and your passkeys return.
Device-bound passkeys live on one piece of hardware, such as a YubiKey security key. They can’t be copied. Lose the key and that passkey is gone, so you register two keys and store the spare in a safe.
Either way, set up recovery before you need it:
- Create passkeys on at least two devices, or keep a spare security key.
- Protect the account that syncs your passkeys with a strong password and multi-factor authentication.
- Save the recovery codes each service offers and store them on paper in a locked place.
A thief who steals your phone still needs your face, your fingerprint, or your PIN to use a passkey. Choose a six-digit PIN or longer, and do not share it.
Where can I use passkeys today?
The list grows each month. Current supporters include Google, Microsoft, Apple, Amazon, PayPal, eBay, GitHub, Shopify, Intuit, Adobe, WhatsApp, LinkedIn, and a growing number of banks and payroll providers. Look for “Passkeys” or “Sign-in options” in the security settings of each account. The directory at passkeys.directory tracks which sites support them.
How do I set up a passkey?
The steps look about the same everywhere.
- Sign in to the account the usual way.
- Open the security or sign-in settings.
- Choose “Create a passkey” or “Add a passkey.”
- Approve with your fingerprint, face, or device PIN.
- Repeat on a second device, or confirm that your password manager synced it.
To sign in on a computer that does not hold your passkey, pick the option to use a phone. The computer shows a QR code, you scan it with your phone, and you approve on the phone. The two devices confirm over Bluetooth that they sit near each other, which blocks a remote attacker from using the same trick.
Should a small business switch to passkeys?
Yes, in stages. Start with the accounts whose loss would hurt most.
- Email and identity. Turn on passkeys in Microsoft 365 or Google Workspace for owners, administrators, and anyone who handles money. Microsoft Entra ID and Google Workspace both let administrators manage passkeys for staff.
- Banking, payroll, and accounting. Add a passkey wherever the provider offers one.
- Administrators. Give anyone with admin rights two hardware security keys. Device-bound keys offer the strongest protection for the accounts that control everything else.
- Everyone else. Use a business password manager that stores and syncs passkeys, so the company keeps control when an employee leaves.
Update your access policy to name passkeys as the preferred sign-in method, and show the staff how they work during training. The first passkey prompt confuses people. A five-minute demonstration fixes that.
What are the downsides of passkeys?
- Uneven support. Many sites still offer passwords only, so you will run passwords and passkeys side by side for years. Keep the password manager.
- Ecosystem lock-in. Moving passkeys between Apple, Google, and third-party managers is still clumsy. The FIDO Alliance is working on a standard for secure transfer.
- The password often remains. Many sites add a passkey and keep the old password as a fallback. An attacker can still phish that password. Where the service allows it, remove the password or replace it with a long random one stored in your manager.
- Shared accounts. A passkey belongs to a person’s device. For a login that three employees share, store the passkey in a shared vault in your password manager.
- Recovery is the weak point. An account protected by a passkey and recoverable by a text message is only as strong as the text message. Review the recovery options.
Do passkeys stop all phishing?
No. Passkeys stop password theft. Criminals still send fake invoices, call pretending to be your bank, and talk help desks into resetting accounts. People remain the target, so keep training them to slow down and verify.
Your next step
Add a passkey to your email account today. It takes two minutes. Then list the five accounts your business can’t afford to lose and check each one for passkey support. Cerberus Cybersecurity helps small businesses write access policies and train staff on changes like this one. Review our services or contact us.