{"id":6618,"date":"2026-10-02T06:05:38","date_gmt":"2026-10-02T06:05:38","guid":{"rendered":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/"},"modified":"2026-10-02T06:05:38","modified_gmt":"2026-10-02T06:05:38","slug":"what-the-fuck-are-passkeys-and-why-are-they-everywhere-now","status":"publish","type":"post","link":"https:\/\/dev95.site\/ar\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/","title":{"rendered":"What the fuck are passkeys and why are they everywhere now?"},"content":{"rendered":"<div id=\"dev95-4167903877\" class=\"dev95-- dev95-entity-placement\"><script async=\"async\" data-cfasync=\"false\" src=\"https:\/\/pl27862732.profitableratecpmnetwork.com\/2ad7a50e0bbc23ac6801d7b77c501463\/invoke.js\"><\/script>\r\n<div id=\"container-2ad7a50e0bbc23ac6801d7b77c501463\"><\/div><\/div><div id=\"dev95-2634653681\" class=\"dev95-before-content dev95-entity-placement\"><p style=\"text-align: center;\"><strong>Stop wasting time on dead links! \ud83d\uded1 This smart platform automatically detects your device and country to give you the exact best offer instantly. Check it out now 100% free! \ud83d\udc47<\/strong><br data-sfc-root=\"ep\" data-sfc-pl=\"|||[]\" data-complete=\"true\" data-copy-service-computed-style=\"font-family: Arial, sans-serif, &quot;Noto Color Emoji&quot;; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);\" \/><a href=\"https:\/\/www.profitableratecpmnetwork.com\/pvhx5mbcc?key=ff7d362db3c20bc86fad685cc94f1fc4\">\ud83d\udd17 <strong class=\"rQesXe MPyX\" data-sfc-cp=\"\" data-sfc-root=\"ep\" data-complete=\"true\" aria-owns=\"action-menu-parent-container\" data-copy-service-computed-style=\"font-family: Arial, sans-serif, &quot;Noto Color Emoji&quot;; font-size: 16px; font-weight: 700; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);\">[Click here]<\/strong><\/a><\/p>\n<\/div><div>\n<p><em>This is a writeup of a talk I gave at <\/em><a href=\"https:\/\/minnestar.org\/minnebar\/?ref=blog.danlew.net\" rel=\"noreferrer\"><em>Minnebar 20<\/em><\/a><em>.<\/em><\/p><div id=\"dev95-2320338614\" class=\"dev95- dev95-entity-placement\"><center>\r\n<script>\r\n  atOptions = {\r\n    'key' : '4ba6b6513c00e0ba76511f798ae56401',\r\n    'format' : 'iframe',\r\n    'height' : 50,\r\n    'width' : 320,\r\n    'params' : {}\r\n  };\r\n<\/script>\r\n<script src=\"https:\/\/www.highrevenueformat.com\/4ba6b6513c00e0ba76511f798ae56401\/invoke.js\"><\/script>\r\n\t<\/center><\/div>\n<p><em>Originally, I threw in some Matrix references to make the talk more fun &amp; engaging. Those jokes work better in person, so I\u2019ve mostly omitted the Matrix from this writeup (though some vestiges remain).<\/em><\/p>\n<hr>\n<p>It seems like every time I log into a website these days, I get one of these fucking screens asking me use passkeys:<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-1-1.png?resize=199%2C400&#038;ssl=1\" class=\"kg-image\" alt=\"CVS's website asking me to &quot;create a passkey to save time&quot;\" loading=\"lazy\" width=\"199\" height=\"400\"><\/figure>\n<p>So far, I&#8217;ve ignored these websites&#8217; pleas to convert. A year ago I did some cursory research on passkeys, failed to understand why they were any better than passwords, and didn&#8217;t see a reason to upgrade. Given that no one was forcing me to use them, I decided it was safe to ignore.<\/p>\n<p>That was the situation until a few months ago. I was at a family gathering and my mom asked what she should do about these passkey things that websites keep pestering her about.<\/p>\n<figure class=\"kg-card kg-image-card kg-card-hascaption\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-3-1.png?resize=711%2C400&#038;ssl=1\" class=\"kg-image\" alt=\"My mom, on a couch, with a cute dog snuggling her\" loading=\"lazy\" width=\"711\" height=\"400\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/image-3-1.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-3-1.png 711w\"><figcaption><span style=\"white-space: pre-wrap;\">My mom with my sister&#8217;s dog<\/span><\/figcaption><\/figure>\n<p>At this moment, I failed as family tech support. I&#8217;d been shirking my responsibilities and had no answer for her. Should she be using passkeys? Are people better off using them? What the fuck are they, really?<\/p>\n<p>Let&#8217;s take a journey together through passkey\u2019s history: why passwords are deficient, how passkeys fix those defects, and what are passkey&#8217;s own problems. And by the end of this post, we should be able to answer whether or not my mom should use passkeys.<\/p>\n<h1 id=\"passwords\">Passwords<\/h1>\n<p>Let&#8217;s start by defining some terminology.<\/p>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Authentication?ref=blog.danlew.net\"><strong><u>Authentication<\/u><\/strong><\/a> is the act of verifying a user is who they say they are. I show websites I am who I say I am with some proof (like a password).<\/p>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Authorization?ref=blog.danlew.net\"><strong><u>Authorization<\/u><\/strong><\/a> is a related topic: checking whether a user has permission to do something. For example, a wiki might have verified I\u2019m Dan Lew, but still not allow me to edit content because I\u2019m only authorized to view it.<\/p>\n<p>Passwords &amp; passkeys are part of <strong>authentication<\/strong>, so we\u2019ll set aside authorization for now. (I just wanted to define these terms since they\u2019re easily confused\/conflated together.)<\/p>\n<p>Electronic passwords were first used in the 1960s as part of MIT&#8217;s Compatible Time-Sharing System. They needed a way to identify each user, and passwords were a straightforward solution. However, security on these passwords was nonexistent; all user\/password combinations were stored in plaintext on a file anyone could access (and, indeed, <a href=\"https:\/\/www.wired.com\/2012\/01\/computer-password\/?ref=blog.danlew.net\"><u>someone did fess up later<\/u><\/a> to printing out that file so they could get extra time on the system).<\/p>\n<p>Over the years, we&#8217;ve improved the security of passwords from these humble beginnings: we added <a href=\"https:\/\/en.wikipedia.org\/wiki\/Cryptographic_hash_function?ref=blog.danlew.net\"><u>hashing<\/u><\/a> so passwords aren&#8217;t stored in plaintext, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Salt_(cryptography)?ref=blog.danlew.net\"><u>salting<\/u><\/a> to prevent rainbow table attacks, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Key_derivation_function?ref=blog.danlew.net\"><u>expensive hashing algorithms<\/u><\/a> to slow brute force attacks, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Multi-factor_authentication?ref=blog.danlew.net\"><u>multi-factor authentication<\/u><\/a> to defend against stolen passwords, and the dreaded <a href=\"https:\/\/en.wikipedia.org\/wiki\/Password_strength?ref=blog.danlew.net\"><u>minimum password requirements<\/u><\/a>.<\/p>\n<p>But these weren&#8217;t enough. Passwords still have major, seemingly insurmountable problems:<\/p>\n<p><strong>Weak passwords<\/strong> &#8211; People regularly use passwords that are easy to guess or short enough to brute force.<\/p>\n<p><strong>Password reuse<\/strong> &#8211; People reuse the same password on multiple sites; if one of those sites leaks its passwords, then attackers can use <a href=\"https:\/\/en.wikipedia.org\/wiki\/Credential_stuffing?ref=blog.danlew.net\"><u>credential stuffing<\/u><\/a> to get into a user&#8217;s other accounts.<\/p>\n<p><strong>Data breaches<\/strong> &#8211; Sites and data breaches: name a more classic combo. I get a letter every other month from some medical provider telling me that all my personal info has been stolen <strong>again<\/strong>. When a database leaks, even a hashed password can eventually be cracked (especially if it&#8217;s not particularly strong).<\/p>\n<p><strong>Phishing<\/strong> &#8211; You thought you were logging into <a href=\"http:\/\/danlew.net\/?ref=blog.danlew.net\"><u>danlew.net<\/u><\/a>, but you were actually at <a href=\"http:\/\/evil-danlew.net\/?ref=blog.danlew.net\"><u>evil-danlew.net<\/u><\/a>. Passwords don&#8217;t care which domain they\u2019re used on, so now the phisher has your password.<\/p>\n<p>There are ways folks can mitigate some of these attacks (like using a password manager and 2FA). But passwords regularly fail to protect people because of these core deficiencies.<\/p>\n<h1 id=\"webauthn\">WebAuthn<\/h1>\n<p>Where there&#8217;s a problem, there&#8217;s a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Working_group?ref=blog.danlew.net\"><u>working group<\/u><\/a>.<\/p>\n<p>The <a href=\"https:\/\/www.w3.org\/?ref=blog.danlew.net\"><u>Wide Web Consortium (W3C)<\/u><\/a> and <a href=\"https:\/\/fidoalliance.org\/?ref=blog.danlew.net\"><u>Fast IDentity Online (FIDO) Alliance<\/u><\/a> got the band together to try to fix passwords. They&#8217;ve come up with a better standard called\u2026.<\/p>\n<figure class=\"kg-card kg-image-card\"><a href=\"https:\/\/en.wikipedia.org\/wiki\/WebAuthn?ref=blog.danlew.net\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-7.png?resize=1280%2C342&#038;ssl=1\" class=\"kg-image\" alt='A logo that says \"WebAuthn\"' loading=\"lazy\" width=\"1280\" height=\"342\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/image-7.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/image-7.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/image-7.png 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w2400\/2026\/05\/image-7.png 2400w\" sizes=\"auto, (min-width: 720px) 720px\"><\/a><\/figure>\n<p>Maybe you thought I was going to say &#8220;passkeys&#8221; here, but passkeys are just one part of WebAuthn. The spec, as a whole, defines how to do authentication in a new, more secure way.<\/p>\n<p><em>As an aside: why &#8220;WebAuthn&#8221; instead of just &#8220;WebAuth&#8221;? Well, that&#8217;s because &#8220;auth&#8221; is ambiguous; it could mean either &#8220;authentication&#8221; or &#8220;authorization&#8221;, since they both start with &#8220;auth.&#8221; Though, I still find &#8220;authn&#8221; confusing because both those words <strong>also<\/strong> end with the letter &#8216;n&#8217;!<\/em><\/p>\n<p>WebAuthn was first proposed in 2013. They finalized <a href=\"https:\/\/www.w3.org\/TR\/webauthn-1\/?ref=blog.danlew.net\"><u>the level 1 spec<\/u><\/a> in 2019, and released <a href=\"https:\/\/www.w3.org\/TR\/webauthn-2\/?ref=blog.danlew.net\"><u>the level 2 spec<\/u><\/a> in 2021. At that point, WebAuthn was still a niche technology, rarely implemented or used.<\/p>\n<p>The big turning point came in 2022 when <a href=\"https:\/\/www.macrumors.com\/2022\/06\/08\/apple-passkeys-next-generation-passwords\/?ref=blog.danlew.net\"><u>Apple released passkeys<\/u><\/a>. This release had two big effects: first, Apple coined the term &#8220;passkey&#8221;. A brilliant move, IMO, because it doesn&#8217;t sound like technojargon &amp; evokes the idea of passwords (but better). The second big effect was that it brought WebAuthn to the masses: anyone with an iOS device could start using it.<\/p>\n<p>Once Apple was in the WebAuthn game, everyone else followed: websites &amp; apps started implementing WebAuthn, and all the other major players got in on the action as well &#8211; platforms like Microsoft &amp; Google, credential managers like 1Password and Dashlane, and browsers like Chrome &amp; Firefox.<\/p>\n<p>WebAuthn is still evolving. As of writing, there&#8217;s <a href=\"https:\/\/www.w3.org\/TR\/webauthn-3\/?ref=blog.danlew.net\"><u>a level 3 spec<\/u><\/a> that\u2019s at the \u201cCandidate Recommendation Snapshot\u201d phase. I&#8217;m not too familiar with the pace of W3C standard adoption so I have no idea when it&#8217;ll get finalized.<\/p>\n<h2 id=\"passkeys\">Passkeys<\/h2>\n<p>What is a passkey, if it&#8217;s only a part of WebAuthn?<\/p>\n<p>For a while, that question was left as an exercise for the reader. While Apple coined the term, they did not specify <em>exactly <\/em>what type of WebAuthn credential it was. This has led to some chaos that still persists to this day, as you&#8217;ll easily find different, conflicting definitions of what, exactly, a passkey is.<\/p>\n<p>Thankfully, passkeys are becoming part of the official WebAuthn spec now. They are synonymous with a pre-existing idea: <a href=\"https:\/\/www.w3.org\/TR\/webauthn-3\/?ref=blog.danlew.net#passkey\"><u>a discoverable credential<\/u><\/a>.<\/p>\n<p>A passkey has three properties:<\/p>\n<p>1. It&#8217;s a <strong>WebAuthn credential<\/strong>&#8230;<\/p>\n<p>2. &#8230;that&#8217;s <strong>passwordless<\/strong> (as all WebAuthn credentials are).<\/p>\n<p>3. &#8230;and <strong>usernameless<\/strong> (that&#8217;s the &#8220;discoverable&#8221; part).<\/p>\n<p>When done right, you can login to a website without needing anything but your passkey.<\/p>\n<p>Let&#8217;s take a look at how the process looks, using the demo site <a href=\"https:\/\/webauthn.io\/?ref=blog.danlew.net\" rel=\"noreferrer\">webauthn.io<\/a>.<\/p>\n<figure class=\"kg-card kg-video-card kg-width-regular\" data-kg-thumbnail=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/webauthn-registration_thumb.jpg\" data-kg-custom-thumbnail>\n<div class=\"kg-video-container\">\n                <video src=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/webauthn-registration.mp4\" poster=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/webauthn-registration_thumb.jpg\" width=\"1908\" height=\"1070\" playsinline preload=\"metadata\" controls><\/video><\/p><\/div>\n<\/figure>\n<p>The first step is to <strong>register<\/strong> a passkey with the site. In this step, I enter a username, signal to the site that I would like to register a passkey, then save the generated passkey to my credential manager (1Password).<\/p>\n<figure class=\"kg-card kg-video-card kg-width-regular\" data-kg-thumbnail=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/webauthn-authentication_thumb.jpg\" data-kg-custom-thumbnail>\n<div class=\"kg-video-container\">\n                <video src=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/webauthn-authentication.mp4\" poster=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/webauthn-authentication_thumb.jpg\" width=\"1908\" height=\"1070\" playsinline preload=\"metadata\" controls><\/video><\/p><\/div>\n<\/figure>\n<p>Now that I&#8217;m registered, I can use my passkey to <strong>authenticate<\/strong> with the website. (Notice how I do <em>not<\/em> have my username entered.) I click on the &#8220;authenticate&#8221; button, which starts the passkey authentication flow. 1Password offers to let me use the passkey they stored, and bam, I&#8217;m in!<\/p>\n<p>Convenient, eh?<\/p>\n<h2 id=\"passkey-protocol\">Passkey Protocol<\/h2>\n<p>What the fuck is actually happening under the hood?<\/p>\n<p>To explain that, I first need to explain how <a href=\"https:\/\/en.wikipedia.org\/wiki\/Public-key_cryptography?ref=blog.danlew.net\"><u>public-key cryptography<\/u><\/a> works. In particular, using keys to do <a href=\"https:\/\/en.wikipedia.org\/wiki\/Digital_signature?ref=blog.danlew.net\"><u>digital signatures<\/u><\/a>.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.035-1.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt='A scenario with two characters, Neo and Trinity. Neo is sending Trinity a message saying \"Trinity, help!\"' loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.035-1.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.035-1.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.035-1.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.035-1.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Let&#8217;s imagine that we&#8217;re sending an important message from Neo to Trinity. Everything is fine, right?<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.038.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"The same scenario as before, only now a third character, Cypher, is intercepting the message. He's manipulating it so that instead of saying &quot;Trinity, help!&quot; it instead says &quot;no problems here!&quot;\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.038.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.038.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.038.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.038.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Wrong! Imagine Cypher manages to <a href=\"https:\/\/en.wikipedia.org\/wiki\/Man-in-the-middle_attack?ref=blog.danlew.net\"><u>man-in-the-middle<\/u><\/a> the message and manipulate it. Without any sort of security, Trinity can&#8217;t tell that the message she received is illegitimate. What we need is a way for Trinity to verify that she got the message Neo actually sent.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.041-1.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"Neo now has two keys: a private key and a public key (represented as icons)\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.041-1.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.041-1.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.041-1.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.041-1.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>To do that, Neo <strong>generates a private and public key<\/strong>. They&#8217;re large numbers that have interesting properties when used together. (My hand-wavey explanation is about as specific as you need, and also about as much as I understand of the math.)<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.043.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"Neo has given his public key to Trinity\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.043.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.043.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.043.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.043.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>As their names imply, Neo keeps the private key to himself, but <strong>sends the public key to Trinity<\/strong>. What&#8217;s important to note here is that <strong>we don&#8217;t care who has the public key<\/strong>. Cypher could have it as well, but it doesn\u2019t matter (for reasons that will become clear shortly).<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.046.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt='Neo is now sending the message again, but before sending it, he uses his private key to sign it. The new package has both the message \"Trinity, help!\" and a hexadecimal signature.' loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.046.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.046.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.046.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.046.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>This time, before transmission, Neo <strong>signs the message with the private key<\/strong>. With the power of math, some extra numbers (the signature) are attached to the message.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.048.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt='Trinity verifies the package using the public key, and now knows that \"Trinity, help!\" was an unaltered message.' loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.048.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.048.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.048.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.048.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>When Trinity receives the message, she can take the original message, the signature attached to it, and Neo&#8217;s public key to <strong>verify that the message wasn&#8217;t altered<\/strong>. Now she can rest assured that Neo sent the original message and that it wasn&#8217;t modified.<\/p>\n<p><em>(Remember how I said it didn\u2019t matter who had the public key? That\u2019s because all anyone with a public key can do here is verify, not manipulate, the message.)<\/em><\/p>\n<p>I&#8217;m going to do a <strong>magic trick<\/strong> now. Let&#8217;s see what happens when I replace &#8220;Neo&#8221; and his private\/public keys with &#8220;you&#8221; and your keys. I&#8217;ll replace &#8220;Trinity&#8221; with &#8220;a server.&#8221; And the message is now an authorization statement.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.051.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"The same scenario as before, only Neo is you, Trinity is the server, and the message says &quot;it's me!&quot;\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.051.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.051.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.051.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.051.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Behold! I&#8217;ve now proven to a server that I am who I say I am. That&#8217;s authentication! When I first registered my passkey with the server, I generated a private &amp; public key, and gave the server the public key. When I later authenticate, I can sign a message proving that I&#8217;m the holder of the private key, and the server can verify that with the public key.<\/p>\n<p>There are <em>many<\/em> more details to the WebAuthn flow than what I&#8217;ve presented here &#8211; details that protect against a variety of potential security issues &#8211; but digital signatures are at the core of it. Now you have a basic mental model of what passkeys are doing.<\/p>\n<h2 id=\"passkey-benefits\">Passkey Benefits<\/h2>\n<p>The cool thing about passkeys is that they solve all the problems I wrote about earlier with passwords.<\/p>\n<p><strong>Weak passwords<\/strong> are replaced with <strong>strong passkeys<\/strong>. There is no such thing as a weak passkey, it&#8217;s using complex math to make big strong numbers.<\/p>\n<p><strong>Password reuse<\/strong> is replaced by <strong>unique passkeys<\/strong>. Passkeys, by design, are unique for every website; there&#8217;s no way to reuse a passkey.<\/p>\n<p><strong>Data breaches<\/strong> still happen, but <strong>we no longer care<\/strong>. The server only has our public key; we don\u2019t care who has it.<\/p>\n<p><strong>Phishing<\/strong> is now <strong>impossible<\/strong>. One other detail of WebAuthn is that a credential is linked to a domain, so you can&#8217;t even use a passkey on a different website.<\/p>\n<p>Not only have we triumphed over the weaknesses of passwords, but passkeys are also more convenient. All you need is your authenticator (usually your phone) + a way to unlock it (pin, fingerprint, face). No more username or password entry.<\/p>\n<p>And, theoretically, you don&#8217;t even need to use 2FA anymore! The point of 2FA is to provide multiple proofs you are who you say you are, so that attackers can&#8217;t get anywhere with just a single factor. Three common factors are &#8220;something you know&#8221;, &#8220;something you have&#8221;, and &#8220;something you are.&#8221;<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.066.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt='A slide showing three authentication factors: \"something you know\", \"something you have\" and \"something you are.\" The \"something you know\" is a password, the \"something you have\" is SMS, and the \"something you are\" is a fingerprint. SMS\/Fingerprints are highlighted, as they are the 2nd factors when using a password as authentication.' loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.066.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.066.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.066.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.066.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>A password is &#8220;something you know.&#8221; That means a 2nd factor would have to be &#8220;something you have&#8221; (like SMS or <a href=\"https:\/\/en.wikipedia.org\/wiki\/Time-based_one-time_password?ref=blog.danlew.net\"><u>TOTP<\/u><\/a>) or something you are (like biometrics). Since websites don&#8217;t want to store your biometric data, you almost always end up proving your 2nd factor with &#8220;something you have.&#8221;<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.069.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt='A slide showing three authentication factors: \"something you know\", \"something you have\" and \"something you are.\" The \"something you know\" is a PIN, the \"something you have\" is a passkey, and the \"something you are\" is a fingerprint. PIN\/fingerprint are highlighted as they are the second factor for passkeys.' loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.069.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.069.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.069.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.069.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>But a passkey is &#8220;something you have!&#8221; That means the 2nd factor can be &#8220;something you know&#8221; (like a pin) or &#8220;something you are&#8221; (like a fingerprint). And what&#8217;dya know &#8211; you already unlocked your authenticator by using a pin or biometrics! By the time you&#8217;re handing over your passkey, you&#8217;ve already used two factors.<\/p>\n<p>Everything looks peachy for passkeys!<\/p>\n<p>&#8230;Right?<\/p>\n<h1 id=\"passkey-problems\">Passkey Problems<\/h1>\n<p>Given all these advantages, why isn&#8217;t everyone using passkeys already?<\/p>\n<p>It turns out there are some serious usability problems with passkeys. While passkeys solve many of the inherent security flaws in password-based authentication, it somewhat left ease-of-use by the wayside.<\/p>\n<p><em>(There are many problems I could raise, but I&#8217;m going to focus on what I consider the three most salient ones and skip the more nit-picky issues.)<\/em><\/p>\n<h2 id=\"problem-1-passkeys-are-confusing\">Problem #1: Passkeys are confusing<\/h2>\n<p>All across the internet, I\u2019ve found takes like this:<\/p>\n<figure class=\"kg-card kg-image-card\"><a href=\"https:\/\/bsky.app\/profile\/tcarmody.bsky.social\/post\/3mjroltnwtc2l?ref=blog.danlew.net\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-04-21-at-7.25.07---PM.png?resize=1280%2C426&#038;ssl=1\" class=\"kg-image\" alt='A post on BlueSky from Tim Carmody (@tcarmody.bsky.social): \"I am a highly educated and technically proficient person, but passkeys are the first new ubiquitous web technology that regularly make me think I am just a stupid big baby man\"' loading=\"lazy\" width=\"1280\" height=\"426\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/Screenshot-2026-04-21-at-7.25.07---PM.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/Screenshot-2026-04-21-at-7.25.07---PM.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-04-21-at-7.25.07---PM.png 1524w\" sizes=\"auto, (min-width: 720px) 720px\"><\/a><\/figure>\n<p>For reference: Tim Carmody is a longtime tech writer, so he should know his stuff. I&#8217;m with him, to be honest; I\u2019ve been researching passkeys for months now and I still don\u2019t feel like I understand every detail of it.<\/p>\n<p>I believe the problem is that it\u2019s difficult to form a working mental model of passkeys. There are two sources of confusion here: <strong>passkeys are complex<\/strong>, and <strong>passkey implementations are inconsistent<\/strong>.<\/p>\n<h3 id=\"passkey-complexity\">Passkey Complexity<\/h3>\n<p>Let\u2019s try explaining passwords to someone who doesn\u2019t know what they are: it\u2019s a secret word we share. Whenever you tell me that word I know it\u2019s you because you\u2019re the only person who knows it.<\/p>\n<p>See how easy that was? Passwords, from a user standpoint, are simple. Sure, there\u2019s a lot going on under the hood (hashing, salting, etc.) but you don\u2019t need to know about that to use passwords correctly.<\/p>\n<p>Now let\u2019s try the same exercise with passkeys. It\u2019s not a word; it\u2019s a private\/public key pair. What\u2019s that? Well, there\u2019s a long explanation earlier in this post. When you want to use your passkey, you have to use your thumbprint. Why? Because you have to unlock your authenticator. What\u2019s an authenticator? It\u2019s your phone, but also maybe your credential manager, or a hardware key. Wait, what\u2026?<\/p>\n<p>It\u2019s tempting to think of a passkey as simply a fancy password, but they\u2019re not. That mental model falls apart quickly: Why can\u2019t I share passkeys as easily as passwords? Why does a passkey work on my browser, but not on the app? Why do I have to press a button, then enter a pin, on my hardware authenticator?<\/p>\n<p>Passkeys, from a user standpoint, are complex. Most people aren\u2019t going to take the time to dig into the protocol; they want something to Just Work.<\/p>\n<h3 id=\"passkey-inconsistency\">Passkey Inconsistency<\/h3>\n<p>In terms of Just Working, passkeys often aren\u2019t cutting it either. Websites implement passkeys in wildly different ways, which leads to great deal of confusion.<\/p>\n<p>Let\u2019s start by looking at a variety of sites asking you to create passkeys\u2026<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/data-src-image-5f375fec-aa3d-44c4-936b-26ca68a3570e-1-1.png?resize=200%2C400&#038;ssl=1\" class=\"kg-image\" alt='A CVS page asking you to \"create a passkey to save time\", with a single button at the bottom to create a passkey.' loading=\"lazy\" width=\"200\" height=\"400\"><\/figure>\n<p>Here\u2019s CVS. It\u2019s fairly straightforward; it tells you what you\u2019re getting into and gives you a single button press to start using passkeys. Great!<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/data-src-image-b21d9423-e4af-43c4-9dd5-1bf664ea856c-1.png?resize=273%2C400&#038;ssl=1\" class=\"kg-image\" alt='A Lowes page asking you to \"skip the passwords\" by creating a passkey. Crucially, it includes a checkbox which has a bunch of legalese you agree to first before using a passkey.' loading=\"lazy\" width=\"273\" height=\"400\"><\/figure>\n<p>Here\u2019s Lowe\u2019s. They add a checkbox with some scary sounding phrases, like \u201cconsent\u201d, \u201cfingerprint recognition\u201d, \u201cterms and conditions.\u201d Why is there a checkbox here and not on CVS? No idea!<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/data-src-image-058b5496-0642-4a45-a68d-7da96067e870-1.png?resize=496%2C400&#038;ssl=1\" class=\"kg-image\" alt=\"A Home Depot page asking you to &quot;sign in faster on this device&quot; by enabling &quot;face or fingerprint ID&quot;. There's no mention of passkeys.\" loading=\"lazy\" width=\"496\" height=\"400\"><\/figure>\n<p>Home Depot doesn\u2019t even mention passkeys. They call it \u201cface or fingerprint ID\u201d. No wonder people (wrongfully) think your biometrics are being sent to servers when using passkeys.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/data-src-image-d3e12222-809c-464d-b305-a69406bdd1c8-1.png?resize=269%2C400&#038;ssl=1\" class=\"kg-image\" alt=\"An NVIDIA page to &quot;secure my account&quot; using a &quot;hardware security device&quot;. It doesn't mention passkeys at all.\" loading=\"lazy\" width=\"269\" height=\"400\"><\/figure>\n<p>Many sites use passkeys solely as 2FA instead of auth. That\u2019s the case for Nvidia, in which passkeys are registered as \u201chardware security device\u201d, even though I\u2019m using 1Password, which isn\u2019t hardware at all. Huh?<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/data-src-image-e3cb59d2-76f7-45b1-a191-58047bb76eda-1.png?resize=556%2C400&#038;ssl=1\" class=\"kg-image\" alt=\"The Dropbox login page. It opened my 1Password extension to save a passkey after I logged in.\" loading=\"lazy\" width=\"556\" height=\"400\"><\/figure>\n<p>The absolute worst offender is Dropbox, who had no message whatsoever. They simply started registering a passkey with my credential manager the moment I logged in. Yet again, tech does not understand consent!<\/p>\n<p>Let\u2019s take a look at authentication now.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.102.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"The CVS login page; it asks me for a username first before letting me use my passkey\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.102.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.102.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.102.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.102.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Did I mention earlier that passkeys are usernameless? CVS still asks me for an identifier before letting me use my \u201cusernameless\u201d passkey.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.103.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"The Vanguard login page; it asks me for a username &amp; password first before letting me use my passkey\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.103.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.103.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.103.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.103.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Even worse &#8211; Vanguard has me enter both username &amp; password before using my passkey! That\u2019s because they\u2019re using passkeys as 2FA. Their little guide even shows a hardware key even though I\u2019m using 1Password. What is a passkey &#8211; authentication or 2FA?<\/p>\n<p>Not only do websites have wildly different implementations, but vendors also trip over each other while fighting to be your credential manager.<\/p>\n<figure class=\"kg-card kg-video-card kg-width-regular\" data-kg-thumbnail=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/double-auth_thumb.jpg\" data-kg-custom-thumbnail>\n<div class=\"kg-video-container\">\n                <video src=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/double-auth.mp4\" poster=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/media\/2026\/05\/double-auth_thumb.jpg\" width=\"1920\" height=\"1096\" playsinline preload=\"metadata\" controls><\/video><\/p><\/div>\n<\/figure>\n<p>When I signed in this time, I refused to use 1Password\u2019s passkey. Subsequently, Chrome\u2019s credential manager pops up to say hello. Why can\u2019t I just cancel the passkey flow once?<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-05-10-at-4.03.58---PM-1.png?resize=391%2C400&#038;ssl=1\" class=\"kg-image\" alt=\"Facebook's passkey page; it lets me use a bunch of methods to use a passkey (like iCloud keychain or hardware key), but doesn't activate 1Password\" loading=\"lazy\" width=\"391\" height=\"400\"><\/figure>\n<p>I tried creating a passkey on Facebook and failed because 1Password never popped up as an option. Sure, Chrome popped up, as did Apple Keychain, but for unknown reasons, 1Password wasn\u2019t eligible.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-05-20-at-8.49.17---AM.png?resize=1280%2C921&#038;ssl=1\" class=\"kg-image\" alt=\"Discord app login page; it only gives me two options for using a passkey, scanning a QR code or using a hardware security key\" loading=\"lazy\" width=\"1280\" height=\"921\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/Screenshot-2026-05-20-at-8.49.17---AM.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/Screenshot-2026-05-20-at-8.49.17---AM.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/Screenshot-2026-05-20-at-8.49.17---AM.png 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-05-20-at-8.49.17---AM.png 2026w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Discord has a website &amp; I created a passkey on it. It also has an app, but the app wouldn\u2019t launch 1Password to look for a passkey. I tried logging on with my phone (using the QR code), but the phone wouldn\u2019t use 1Password when using QR code passkey auth. Ouch.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-4-1.png?resize=586%2C400&#038;ssl=1\" class=\"kg-image\" alt=\"eBay's authentication page on Safari. In the foreground, Safari is telling me I don't have a passkey. In the background, 1Password is asking me if I want to use my passkey.\" loading=\"lazy\" width=\"586\" height=\"400\"><\/figure>\n<p>Safari always assumes you\u2019re using Apple Keychain first and foremost. As a result, this hilarious image exists: Apple telling me there\u2019s no passkey for eBay, while in the background, 1Password is trying to let me sign in using the passkey that definitely exists.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-5-1-1.png?resize=1280%2C855&#038;ssl=1\" class=\"kg-image\" alt=\"The Apple store; it's saying I could sign in using passkeys, but it &quot;requires a device with iOS 17 or later&quot;\" loading=\"lazy\" width=\"1280\" height=\"855\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/image-5-1-1.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/image-5-1-1.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/image-5-1-1.png 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-5-1-1.png 2000w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Apple&#8217;s store is particularly hostile. They don\u2019t even let you use a passkey if it\u2019s not being stored on an iOS device!<\/p>\n<p>There\u2019s all sorts of inconsistencies that pop up constantly with passkeys. It can vary based on the website\/app, the operating system (Windows, iOS, Android), the browser (Chrome, Safari, Firefox), the credential manager (Apple keychain, Google password manager, 1Password), and whether you\u2019re using a hardware authenticator (Yubikey).<\/p>\n<p>A far cry from how passwords generally work: two input fields, close to each other.<\/p>\n<hr>\n<p>What all of this adds up to &#8211; between a complex interaction model and inconsistent implementations &#8211; is a very confusing experience for anyone trying to get a grasp on how passkeys work.<\/p>\n<p>I think Mike Pound (on Computerphile) said it best: \u201cPeople are not famously that interested in taking in things they don&#8217;t understand.\u201d Why would people take up passkeys when they\u2019re so confusing?<\/p>\n<h2 id=\"problem-2-passkey-technical-issues\">Problem #2: Passkey technical issues<\/h2>\n<p>The section above &#8211; with all its inconsistencies &#8211; still were \u201ccorrect\u201d implementations of passkeys. But it turns out that implementing passkeys can be hard to get right, and so there\u2019s plenty of straight-up bugs out there.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-6-1.png?resize=1280%2C549&#038;ssl=1\" class=\"kg-image\" alt='An error screen. It says \"Unable to use passkey; this passkey could not be used to sign in\"' loading=\"lazy\" width=\"1280\" height=\"549\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/image-6-1.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/image-6-1.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/image-6-1.png 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-6-1.png 2000w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Early on in my passkey testing, I ran into the above error when trying to authenticate with eBay. I\u2019d just created a passkey a minute earlier, and it didn\u2019t work. No idea why! (A minute after that, it did start working again.)<\/p>\n<figure class=\"kg-card kg-image-card\"><a href=\"https:\/\/bsky.app\/profile\/goose.art\/post\/3mjpi2pkrlk23?ref=blog.danlew.net\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-04-22-at-6.20.08---PM-2.png?resize=1180%2C764&#038;ssl=1\" class=\"kg-image\" alt=\"A BlueSky post from @goose.art: *prompted to create a passkey* \/ okay, *creates passkey* \/ &quot;We're sorry, your device does not support passkeys&quot; \/ *checks password manager, there is a passkey* \/ hmm\" loading=\"lazy\" width=\"1180\" height=\"764\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/Screenshot-2026-04-22-at-6.20.08---PM-2.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/Screenshot-2026-04-22-at-6.20.08---PM-2.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-04-22-at-6.20.08---PM-2.png 1180w\" sizes=\"auto, (min-width: 720px) 720px\"><\/a><\/figure>\n<p>I perused social media to see what problems people had been posting about recently and found this. Classic problem.<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-04-22-at-6.24.38---PM.png?resize=1280%2C409&#038;ssl=1\" class=\"kg-image\" alt='A BlueSky post from @apjanke.bsky.social: \"I hit a new record this week. To log in to TurboTax, I had to dismiss a sequence of *seven* prompts asking me to use a passkey.\"' loading=\"lazy\" width=\"1280\" height=\"409\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/Screenshot-2026-04-22-at-6.24.38---PM.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/Screenshot-2026-04-22-at-6.24.38---PM.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/Screenshot-2026-04-22-at-6.24.38---PM.png 1480w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>My record is four prompts I had to dismiss in a row (on Amazon). Seven is both impressive and horrifying.<\/p>\n<figure class=\"kg-card kg-image-card\"><a href=\"https:\/\/techcrunch.com\/2025\/11\/12\/elon-musks-x-botched-its-security-key-switchover-locking-users-out\/?ref=blog.danlew.net\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-8.png?resize=1280%2C681&#038;ssl=1\" class=\"kg-image\" alt='An article headline: \"Elon Musk\u2019s X botched its security key switchover, locking users out\"' loading=\"lazy\" width=\"1280\" height=\"681\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/image-8.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/image-8.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/image-8.png 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w2400\/2026\/05\/image-8.png 2400w\" sizes=\"auto, (min-width: 720px) 720px\"><\/a><\/figure>\n<p>Surprising no one, Elon Musk fucked something up. Because passkeys are tied to a domain, everyone lost their passkey authentication when Twitter became X. There\u2019s a way they could\u2019ve solved it (using related origins) but they didn\u2019t, so whoops, some people got locked out.<\/p>\n<p>There\u2019s all sorts of issues I found people complaining about online:<\/p>\n<p><strong>One passkey at a time<\/strong> &#8211; you\u2019re supposed to be able to create multiple passkeys for any given server, which is crucial if you\u2019re using hardware keys &amp; want backups. But some sites only let you register one passkey at a time.<\/p>\n<p><strong>One passkey, ever <\/strong>&#8211; some sites would let you create a passkey\u2026 but if you deleted it, it would never let you create another passkey again.<\/p>\n<p><strong>Passkey linked to cookie<\/strong> &#8211; some sites would link your passkey to a browser cookie (presumably so they\u2019d know when to initiate the passkey flow in the future). Only, this meant you could <strong>only <\/strong>use the passkey on the browser that originally created the passkey, not any other devices.<\/p>\n<p><strong>Can\u2019t initiate passkey flow<\/strong> &#8211; authenticating with a passkey is something the website has to initiate. Sometimes you have a passkey but the site just won\u2019t ask for it!<\/p>\n<p><strong>Can\u2019t find passkey<\/strong> &#8211; you might have a passkey, but the site can\u2019t seem to find it.<\/p>\n<p><strong>Just plain broken<\/strong> &#8211; you just get a random error (like I did above).<\/p>\n<p>The source of all these problems became clearer to me when I stumbled across <a href=\"https:\/\/www.corbado.com\/blog\/passkey-implementation-pitfalls-misconceptions-unknowns?ref=blog.danlew.net\"><u>this blog post<\/u><\/a> about how passkey implementation is harder than you think. <em>(Yes, it\u2019s partially an advertisement, but it\u2019s got a lot of good technical details as well.)<\/em> The basic case might be easy, but handling all the corner cases can be tricky.<\/p>\n<p>Lest you think it\u2019s only the sites having problems, credential managers themselves have also had severe issues. William Brown, the author of <a href=\"https:\/\/github.com\/kanidm\/webauthn-rs?ref=blog.danlew.net\"><u>webauthn-rs<\/u><\/a>, has had <a href=\"https:\/\/fy.blackhats.net.au\/blog\/2024-04-26-passkeys-a-shattered-dream\/?ref=blog.danlew.net\"><u>his Apple keychain\u2019s passkeys completely wiped four times for no reason<\/u><\/a>. Royce Williams, a security architect, researcher, and <a href=\"https:\/\/infosec.exchange\/@tychotithonus\/112346738155571973?ref=blog.danlew.net\"><u>collector of hardware keys<\/u><\/a> has <a href=\"https:\/\/infosec.exchange\/@tychotithonus\/115341947864402280?ref=blog.danlew.net\"><u>seen multiple Android devices simply lock him out of his passkeys<\/u><\/a>. These are people who know the technology well and are still getting slapped by them.<\/p>\n<p>Passkeys are still relatively new on the scene, and they clearly could use a bit more polish.<\/p>\n<h2 id=\"problem-3-passwords-are-still-here\">Problem #3: Passwords are still here<\/h2>\n<p>Passkeys solve the security problems of passwords, but for the most part, passwords haven\u2019t gone anywhere!<\/p>\n<p>Let\u2019s say I\u2019m logging into a Google account with a passkey\u2026<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.133.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"Google authentication screen asking me to &quot;use your passkey to confirm it's really you.&quot; There's an option to &quot;try another way&quot; at the bottom of the screen.\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.133.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.133.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.133.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.133.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>I don\u2019t have my passkey with me, so lets \u201ctry another way.\u201d<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.135.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt='Google authentication screen showing me other ways to sign in. One of them is \"Enter your password\"' loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.135.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.135.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.135.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.135.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Oh ho ho! One of the options is to use my password!<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/data-src-image-2419dd85-0dc8-46e9-9c99-bd589996e7c9.png?resize=1280%2C719&#038;ssl=1\" class=\"kg-image\" alt='Meme from Lord of the Rings: an orc says \"looks like passwords are back on the menu, boys!\"' loading=\"lazy\" width=\"1280\" height=\"719\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/data-src-image-2419dd85-0dc8-46e9-9c99-bd589996e7c9.png 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/data-src-image-2419dd85-0dc8-46e9-9c99-bd589996e7c9.png 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/data-src-image-2419dd85-0dc8-46e9-9c99-bd589996e7c9.png 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/data-src-image-2419dd85-0dc8-46e9-9c99-bd589996e7c9.png 2048w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>Remember all those problems with passwords? Well, as long as they&#8217;re available as a fallback authentication method, passkeys don\u2019t offer any extra protections at all!<\/p>\n<figure class=\"kg-card kg-image-card\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.141.jpeg?resize=1280%2C720&#038;ssl=1\" class=\"kg-image\" alt=\"A chart showing that we start with just passwords, then go to a world with both passwords and passkeys, and ultimately end up in a world with just passkeys\" loading=\"lazy\" width=\"1280\" height=\"720\" srcset=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w600\/2026\/05\/passkeys.141.jpeg 600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1000\/2026\/05\/passkeys.141.jpeg 1000w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/size\/w1600\/2026\/05\/passkeys.141.jpeg 1600w, https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/passkeys.141.jpeg 1920w\" sizes=\"auto, (min-width: 720px) 720px\"><\/figure>\n<p>There needs to be a period of transition wherein we support both passwords and passkeys, so that eventually we can delete the passwords. But to get any of the advantages now, sites need to start letting you delete your passwords once you\u2019ve created a passkey.<\/p>\n<p>I\u2019m being a bit unfair to Google, as they are one of the only services that let you lock your account to passkeys with their <a href=\"https:\/\/landing.google.com\/intl\/en_in\/advancedprotection\/?ref=blog.danlew.net\"><u>advanced protection program<\/u><\/a>. However, they\u2019re the exception, not the rule. Most sites with passkeys have no clue that a passkey should make passwords obsolete.<\/p>\n<p>As long as password authentication lives, passkeys only exist to be more convenient. (But as shown above, sometimes they are significantly less than convenient.)<\/p>\n<h1 id=\"conclusion\">Conclusion<\/h1>\n<p>Passkeys are in limbo. Will passkeys gain mass adoption &amp; become a ubiquitous technology, like passwords before it? Or will it be relegated to the world of techies &amp; company IT, who understand it well enough to use it effectively?<\/p>\n<p>In my mind, the tech world jumped the gun a bit. Passkeys are everywhere because they are technically superior to passwords, but we didn\u2019t spend enough time concerning ourselves with user experience.<\/p>\n<p>If we want passkeys to win (and I think we&#8217;d be better off if they did, since passwords are a security nightmare), I think passkeys need three things:<\/p>\n<ol>\n<li><strong>Better understood &amp; trusted<\/strong> &#8211; there needs to be a way to present passkeys such that an everyday person understands them, and thus they gain their trust.<\/li>\n<li><strong>Stable &amp; consistent<\/strong> &#8211; sites &amp; credential managers need to get their act together so passkeys work in a consistent manner.<\/li>\n<li><strong>Rough edges polished<\/strong> &#8211; there are deficiencies in passkeys that need to be addressed in the spec (such as a lack of passkey export protocol, which has been a <a href=\"https:\/\/fidoalliance.org\/specifications-credential-exchange-specifications\/?ref=blog.danlew.net\"><u>work in progress<\/u><\/a> for a long time).<\/li>\n<\/ol>\n<p>Are the problems of passkeys solvable? Or are they fundamental to the way passkeys were designed? I honestly don\u2019t know, and don\u2019t care to speculate (as whatever prediction I make will just make me look foolish someday). Maybe someday we\u2019ll all be using passkeys. Maybe not.<\/p>\n<p>As for my mom: I told her to skip passkeys for now. It\u2019s just not baked enough for your average user IMO. Plus, she\u2019s already using a password manager, which solves some of the major problems with passwords, making the security upgrade between \u201cpassword\u201d and \u201cpasskey\u201d smaller.<\/p>\n<p>As for you, the reader: if you feel inclined, why not give it a try? Especially on your most important accounts (like email). Worst-case scenario, you can always fall back to using passwords. Hah!<\/p>\n<p>I, myself, have adopted passkeys now. Sometimes they are brilliant. Sometimes they are frustrating. Sometimes they are broken. As a techie, I\u2019m used to that, and I\u2019m willing to put up with it. For now.<\/p>\n<h1 id=\"further-reading-thanks\">Further Reading &amp; Thanks<\/h1>\n<p>If you want to learn more about passkeys, I\u2019ve got four places I\u2019d start, depending on the level of detail you desire:<\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=xYfiOnufBSk&amp;feature=youtu.be&amp;ref=blog.danlew.net\"><u>How Passkeys Work<\/u><\/a> &#8211; excellent video explaining more details on how, exactly, passkeys work.<\/p>\n<p><a href=\"https:\/\/opensourcesecurity.io\/2026\/2026-01-passkey-william-brown\/?ref=blog.danlew.net\"><u>WTF is a passkey with William Brown<\/u><\/a> &#8211; fantastic podcast about the history of authentication, how we ended up with passkeys, and issues with them.<\/p>\n<p><a href=\"https:\/\/www.corbado.com\/blog\/passkey-implementation-pitfalls-misconceptions-unknowns?ref=blog.danlew.net\"><u>Why Passkey Implementation is 100x harder than you think<\/u><\/a> &#8211; informative article on the many pitfalls of implementing passkeys in your app.<\/p>\n<p><a href=\"https:\/\/www.imperialviolet.org\/tourofwebauthn\/tourofwebauthn.html?ref=blog.danlew.net\"><u>A Tour of WebAuthn<\/u><\/a> &#8211; a detailed deep dive on the inner workings of passkeys.<\/p>\n<p>Also, many thanks to <a href=\"https:\/\/infosec.exchange\/@firstyear?ref=blog.danlew.net\"><u>Wiliam Brown<\/u><\/a> for his valuable input on the original talk.<\/p>\n<\/div>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_6618\" class=\"pvc_stats total_only  \" data-element-id=\"6618\" style=\"\"><i class=\"pvc-stats-icon large\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/i0.wp.com\/dev95.site\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif?resize=16%2C16&#038;ssl=1\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n<div id=\"dev95-2327358937\" class=\"dev95-after-content dev95-entity-placement\"><p style=\"text-align: center;\"><strong>Finally, a link that actually works for your region and device! \ud83c\udf0d Get instant access to the top exclusive offers tailored just for you right now. Don&#8217;t miss out, click here! \ud83d\udc47<\/strong><br data-sfc-root=\"ep\" data-sfc-pl=\"|||[]\" data-complete=\"true\" data-copy-service-computed-style=\"font-family: Arial, sans-serif, &quot;Noto Color Emoji&quot;; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(10, 10, 10);\" \/><a href=\"https:\/\/www.profitableratecpmnetwork.com\/uzeja8ahze?key=bc876be53d6ad0ff6370ab8ea030e479\"><strong>\ud83d\udd17 [Click here]<\/strong><\/a><\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>This is a writeup of a talk I gave at Minnebar 20. Originally, I threw in some Matrix references to make the talk more fun &amp; engaging. Those jokes work better in person, so I\u2019ve mostly omitted the Matrix from<\/p>\n<div class=\"hosteria-entry-more\"><a href=\"https:\/\/dev95.site\/ar\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/\" class=\"no-underline font-light  group-hover:text-primary-800 dark:group-hover:text-primary-300 py-1\">Read more &gt;&gt;&gt;<\/a><\/div>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_6618\" class=\"pvc_stats total_only\" data-element-id=\"6618\" style=\"\"><i class=\"pvc-stats-icon large\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewbox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/dev95.site\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=\"0\" \/><\/p>\n<div class=\"pvc_clear\"><\/div>","protected":false},"author":1,"featured_media":6625,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fp_fajr_begins":"","fp_fajr_iqamah":"","fp_dhuhr_begins":"","fp_dhuhr_iqamah":"","fp_asr_begins":"","fp_asr_iqamah":"","fp_maghrib_begins":"","fp_maghrib_iqamah":"","fp_isha_begins":"","fp_isha_iqamah":"","fp_midnight":"","fp_midnight_name":"","fp_sunrise":"","fp_single_prayer_begins_title":"","fp_single_prayer_iqamah_title":"","fp_prayer_times_for_today":"","fp_hijra_date":"","fp_fajr_name":"","fp_dhuhr_name":"","fp_asr_name":"","fp_maghrib_name":"","fp_isha_name":"","fp_sunrise_name":"","fp_currentDate":"","fp_current_time":"","fp_current_title":"","fp_current_location":"","fp_masjid_name":"","fp_prayer_title":"","fp_next_prayer_iqamah_time":"","fp_next_prayer_iqamah_title":"","fp_next_prayer_begins_time":"","fp_next_prayer_begins_title":"","fp_next_prayer_title":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[9],"tags":[],"class_list":["post-6618","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android"],"a3_pvc":{"activated":true,"total_views":2,"today_views":2},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What the fuck are passkeys and why are they everywhere now? - Dev95<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/dev95.site\/ar\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What the fuck are passkeys and why are they everywhere now? - Dev95\" \/>\n<meta property=\"og:description\" content=\"This is a writeup of a talk I gave at Minnebar 20. Originally, I threw in some Matrix references to make the talk more fun &amp; engaging. Those jokes work better in person, so I\u2019ve mostly omitted the Matrix fromRead more &gt;&gt;&gt;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/dev95.site\/ar\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/\" \/>\n<meta property=\"og:site_name\" content=\"Dev95\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-02T06:05:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-1-1.png\" \/>\n<meta name=\"author\" content=\"dev95\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"dev95\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"21 \u062f\u0642\u064a\u0642\u0629\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/\"},\"author\":{\"name\":\"dev95\",\"@id\":\"https:\\\/\\\/dev95.site\\\/#\\\/schema\\\/person\\\/b807805ffe2916206b04d0938bce0298\"},\"headline\":\"What the fuck are passkeys and why are they everywhere now?\",\"datePublished\":\"2026-10-02T06:05:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/\"},\"wordCount\":4222,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/dev95.site\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/image-1-1.png?fit=199%2C400&ssl=1\",\"articleSection\":[\"Android\"],\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/\",\"url\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/\",\"name\":\"What the fuck are passkeys and why are they everywhere now? - Dev95\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/dev95.site\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/image-1-1.png?fit=199%2C400&ssl=1\",\"datePublished\":\"2026-10-02T06:05:38+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#breadcrumb\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/dev95.site\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/image-1-1.png?fit=199%2C400&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/dev95.site\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/image-1-1.png?fit=199%2C400&ssl=1\",\"width\":199,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/dev95.site\\\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/dev95.site\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What the fuck are passkeys and why are they everywhere now?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/dev95.site\\\/#website\",\"url\":\"https:\\\/\\\/dev95.site\\\/\",\"name\":\"Dev95\",\"description\":\"A comprehensive platform for data and knowledge, delivering reliable content that meets the aspirations of readers and enthusiasts.\",\"publisher\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/dev95.site\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/dev95.site\\\/#organization\",\"name\":\"Dev95\",\"url\":\"https:\\\/\\\/dev95.site\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/dev95.site\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/dev95.site\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/rbrrbr-6.png?fit=512%2C512&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/dev95.site\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/rbrrbr-6.png?fit=512%2C512&ssl=1\",\"width\":512,\"height\":512,\"caption\":\"Dev95\"},\"image\":{\"@id\":\"https:\\\/\\\/dev95.site\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/dev95.site\\\/#\\\/schema\\\/person\\\/b807805ffe2916206b04d0938bce0298\",\"name\":\"dev95\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a70a73d950838b20cd80d7ebdc955737e802e8cd896044c5473b32b946c0662a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a70a73d950838b20cd80d7ebdc955737e802e8cd896044c5473b32b946c0662a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a70a73d950838b20cd80d7ebdc955737e802e8cd896044c5473b32b946c0662a?s=96&d=mm&r=g\",\"caption\":\"dev95\"},\"url\":\"https:\\\/\\\/dev95.site\\\/ar\\\/author\\\/mohammad\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What the fuck are passkeys and why are they everywhere now? - Dev95","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/dev95.site\/ar\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/","og_locale":"ar_AR","og_type":"article","og_title":"What the fuck are passkeys and why are they everywhere now? - Dev95","og_description":"This is a writeup of a talk I gave at Minnebar 20. Originally, I threw in some Matrix references to make the talk more fun &amp; engaging. Those jokes work better in person, so I\u2019ve mostly omitted the Matrix fromRead more &gt;&gt;&gt;","og_url":"https:\/\/dev95.site\/ar\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/","og_site_name":"Dev95","article_published_time":"2026-10-02T06:05:38+00:00","og_image":[{"url":"https:\/\/storage.ghost.io\/c\/4a\/b9\/4ab96a0e-cea9-4968-a6a6-e1fa56bf8891\/content\/images\/2026\/05\/image-1-1.png","type":"","width":"","height":""}],"author":"dev95","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"dev95","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"21 \u062f\u0642\u064a\u0642\u0629"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#article","isPartOf":{"@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/"},"author":{"name":"dev95","@id":"https:\/\/dev95.site\/#\/schema\/person\/b807805ffe2916206b04d0938bce0298"},"headline":"What the fuck are passkeys and why are they everywhere now?","datePublished":"2026-10-02T06:05:38+00:00","mainEntityOfPage":{"@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/"},"wordCount":4222,"commentCount":0,"publisher":{"@id":"https:\/\/dev95.site\/#organization"},"image":{"@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/dev95.site\/wp-content\/uploads\/2026\/10\/image-1-1.png?fit=199%2C400&ssl=1","articleSection":["Android"],"inLanguage":"ar","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/","url":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/","name":"What the fuck are passkeys and why are they everywhere now? - Dev95","isPartOf":{"@id":"https:\/\/dev95.site\/#website"},"primaryImageOfPage":{"@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#primaryimage"},"image":{"@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/dev95.site\/wp-content\/uploads\/2026\/10\/image-1-1.png?fit=199%2C400&ssl=1","datePublished":"2026-10-02T06:05:38+00:00","breadcrumb":{"@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#breadcrumb"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#primaryimage","url":"https:\/\/i0.wp.com\/dev95.site\/wp-content\/uploads\/2026\/10\/image-1-1.png?fit=199%2C400&ssl=1","contentUrl":"https:\/\/i0.wp.com\/dev95.site\/wp-content\/uploads\/2026\/10\/image-1-1.png?fit=199%2C400&ssl=1","width":199,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/dev95.site\/what-the-fuck-are-passkeys-and-why-are-they-everywhere-now\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/dev95.site\/"},{"@type":"ListItem","position":2,"name":"What the fuck are passkeys and why are they everywhere now?"}]},{"@type":"WebSite","@id":"https:\/\/dev95.site\/#website","url":"https:\/\/dev95.site\/","name":"Dev95","description":"\u0645\u0646\u0635\u0629 \u0634\u0627\u0645\u0644\u0629 \u0644\u0644\u0628\u064a\u0627\u0646\u0627\u062a \u0648\u0627\u0644\u0645\u0639\u0631\u0641\u0629\u060c \u062a\u0642\u062f\u0645 \u0645\u062d\u062a\u0648\u0649\u064b \u0645\u0648\u062b\u0648\u0642\u0627\u064b \u064a\u0644\u0628\u064a \u062a\u0637\u0644\u0639\u0627\u062a \u0627\u0644\u0642\u0631\u0627\u0621 \u0648\u0627\u0644\u0645\u0647\u062a\u0645\u064a\u0646.","publisher":{"@id":"https:\/\/dev95.site\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/dev95.site\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Organization","@id":"https:\/\/dev95.site\/#organization","name":"Dev95","url":"https:\/\/dev95.site\/","logo":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/dev95.site\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/dev95.site\/wp-content\/uploads\/2026\/07\/rbrrbr-6.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/dev95.site\/wp-content\/uploads\/2026\/07\/rbrrbr-6.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"Dev95"},"image":{"@id":"https:\/\/dev95.site\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/dev95.site\/#\/schema\/person\/b807805ffe2916206b04d0938bce0298","name":"dev95","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/secure.gravatar.com\/avatar\/a70a73d950838b20cd80d7ebdc955737e802e8cd896044c5473b32b946c0662a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a70a73d950838b20cd80d7ebdc955737e802e8cd896044c5473b32b946c0662a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a70a73d950838b20cd80d7ebdc955737e802e8cd896044c5473b32b946c0662a?s=96&d=mm&r=g","caption":"dev95"},"url":"https:\/\/dev95.site\/ar\/author\/mohammad\/"}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/dev95.site\/wp-content\/uploads\/2026\/10\/image-1-1.png?fit=199%2C400&ssl=1","_links":{"self":[{"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/posts\/6618","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/comments?post=6618"}],"version-history":[{"count":0,"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/posts\/6618\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/media\/6625"}],"wp:attachment":[{"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/media?parent=6618"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/categories?post=6618"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev95.site\/ar\/wp-json\/wp\/v2\/tags?post=6618"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}