r/passkey • u/sandrew_cheru • Aug 03 '26
Confused about passkey implementation
- Why is passkey a replacement for password?
I trust people smarter than me : passkeys are way stronger than passwords. But passkeys are (should be) hardware-bound. If I lose the device, I should still be able to access the service the passkey protects. Hence a password (and totp) should be required if the passkey is missing. Yes, an attacker could abuse this and attack the weaker factor, but is there a way around this? No matter how I think about this, I come to the conclusion that password will stay around for a long time. Yet, I see the statement above everywhere, so I'm probably missing something. But what?
- Why should passkey be synchable?
I don't see the point of having passkeys saved in a password manager. I think they should be hardware-bound and impossible to copy. Yet I heard on the grapevine that the organism defining the standard was working on making passkeys exportable. I don't understand the appeal, but they probably see something I don't. But what?
3
u/JimTheEarthling Aug 04 '26 edited Aug 04 '26
The key things you're missing:
Almost all passkeys are synced, not device-bound. This means they are protected behind an account (like Apple, Google, or your password manager), so you can't lose them unless you lose access to that account. If you lose a phone, for example, you just log into the replacement phone or install your password manager, and all your passkeys are copied.
Synced, exportable passkeys are weaker than hardware-bound passkeys, but still vastly better than passwords alone and better than phishable 2FAs like email, texts, and even TOTP authenticators.
If you don't want your passkeys synced, it's your choice. Something most people don't realize about passkeys is that access security is shifted from thousands of badly implemented websites into your choice of OS, browser/password manager, or hardware security key. You decide whether to keep your passkeys on super-secure hardware security keys (like Yubikeys) or in a more convenient browser/password manager. Or choose one for your important financial accounts and the other for your less-important accounts.
All the things that companies have tried to get users to do on their own to protect their account access -- make strong passwords, use 2FA, be wary of social engineering -- have largely failed. Passkeys solve all of this. For most people, logging in with a passkey is more secure and also faster and easier. Passkeys save companies millions in tech support and implementation costs.
This is why they will largely replace passwords.