Article
Security & Privacy

The end of passwords is here

Passkeys are a simpler, phishing‑resistant alternative to passwords. What they are, why they’re safer, and how to start using them without getting locked out.

by Whatsnew Newsroom

Passkeys are being promoted as the long‑term replacement for passwords. Backed by public‑key cryptography and supported by the FIDO community and many big tech companies, passkeys aim to make signing in faster and far harder to steal than a typed password or an SMS code.

What passkeys are and why they’re safer

A passkey is not a memorable word you type: it’s a cryptographic credential stored on your device. When a website or app asks you to sign in, the service challenges your device, which proves your identity with a private key. A matching public key is held by the service — there’s nothing for an attacker to phish because you never hand over a secret string that can be copied.

That design brings three big advantages:

- Phishing resistance: you can’t be tricked into typing your passkey into a fake site, because the private key never leaves the device and will only work for the real service. - Better than SMS codes: one‑time codes sent by text are vulnerable to interception and SIM swap attacks. Passkeys don’t rely on a phone number or on sending codes over an insecure channel. - Convenience: passkeys usually unlock with a device PIN, fingerprint or face unlock, so signing in can be quicker than hunting for a complex password.

The technology relies on standard public‑key protocols rather than a single vendor, and a growing number of services and platforms have been adding support. Some websites and apps already offer passkeys as an alternative to passwords, while others are preparing to roll them out.

How to start using passkeys (and how to avoid getting locked out)

If you want to try passkeys, look in the security or sign‑in settings of accounts you use often. When a service supports passkeys you’ll usually see an option to create one as a “Sign in method” or “Add passkey.” Setup is typically device‑driven: your phone or computer will create the credential and ask you to confirm with your fingerprint, face, or a PIN.

Two practical points to keep in mind:

1. Backups matter. Because passkeys are stored on devices, you should make sure your platform offers a reliable backup or sync option and enable it if you want seamless recovery when you replace a device. Many major platforms provide encrypted cloud sync for passkeys tied to your account; where that isn’t available, add a secondary device as a backup.

2. Keep recovery options updated. Until passkeys are everywhere, services often let you keep a fallback method — an old password, a recovery email, or a recovery code. Store any recovery codes in a password manager or a secure place so you’re not locked out if a device is lost.

What else to expect: organisations may let administrators enable passkeys for work accounts, and you’ll find a mix of accounts that already support them and ones that still require passwords. Passwords will probably remain around during the transition, but passkeys are a practical, more secure alternative worth adopting when available.

If a service you use offers passkeys, it’s worth trying: they reduce the risk of being phished, remove the need to remember or reset passwords, and make signing in quicker. Just make sure you set up device sync or a backup device and keep recovery methods current so you don’t lose access.

by Whatsnew Newsroom
whatsnew. APPS · WEB TOOLS · SECURITY · AI

Know what’s new.

The useful side of the internet. Covered properly.

Set as preferred →