← all writing

Passkeys: Finally a Realistic Alternative to Passwords

Sep 2026 · 1 min read

Passwords are a poor security model. People reuse them, phishing sites collect them, and databases leak them. Passkeys aim to remove the whole problem.

How they work

Your device holds a private key and the website stores only the matching public key. To sign in, you prove possession of the private key with a fingerprint, face scan, or device PIN. There is no shared secret to steal from the server.

Why they resist phishing

A passkey is bound to the real website's domain. A lookalike site cannot use it, so there is nothing to type into a fake page.

Adoption realities

Sync across your devices works through platform providers, which makes recovery easier but ties you to an ecosystem. Sites still need a fallback for people who lose access, and that fallback is often the weakest link.

If you build apps

Offer passkeys alongside existing sign-in, not instead of it at first. Libraries now handle much of the protocol, so the work is mostly in the user experience and account recovery.

Chat on WhatsApp