What is a Passkey? - Keeper Security (2024)

  • IAM Glossary
  • What is a Passkey?

A passkey is a modern passwordless authentication technology that allows users to log into accounts and apps using a cryptographic key instead of a password. A passkey leverages biometrics (fingerprint, face recognition, etc.) to confirm the user's identity.

What’s the Difference Between Passkey and Password?

Despite having similar names, passkeys are very different from passwords.

What is a Password?

A password is a string of characters that users must provide when logging into a website or app, usually in conjunction with a username. To prevent data breaches and account takeovers, NIST recommends that passwords consist of the following:

  • A minimum of eight characters
  • The ability to use all special characters, but no special requirements to use them
  • Restrict sequential and repetitive characters (e.g., 12345 or aaaaaa)
  • Restrict context specific passwords (e.g. the name of the site)
  • Restrict commonly used passwords (e.g. qwerty, password123) and dictionary words

What is a Passkey?

A passkey is a new authentication technology that uses public key cryptography to enable users to log into websites and apps without having to enter a password. Instead, users authenticate the same way they unlock their phones and tablets: with their fingerprint, face or other biometrics; by using a swipe pattern; or by entering a PIN. For purposes of convenience, most people will opt for biometric authentication.

Instead of creating a password to log into an account, users generate a passkey – which is actually a pair consisting of one private and one public key – using an “authenticator.” This “authenticator” can be a device, like a smartphone or a tablet, a web browser, or a password manager that supports passkey technology.

Before generating a passkey, the authenticator will require that the user identify themselves using a PIN, swipe pattern or biometrics. The authenticator then sends the public key (which is roughly equivalent to a username) to the account web server for storage, and the authenticator securely stores the private key locally. If the authenticator is a smartphone or other device, the private key will be stored in the device keychain. If the authenticator is a password manager, the private key will be stored in the password manager’s encrypted vault.

How Does a Passkey Work?

To create a new passkey, the user signs into their account normally and then enables the passkey option from the security settings screen of the website or app. The website or app then prompts the user to save a passkey associated with their device. The web browser or operating system will then request biometric authentication to approve the request, and the passkey is stored locally.

Subsequent logins to the website will then prompt the user to use a passkey from their device to login, instead of a password. If the web browser supports synchronization of passkeys between devices, the passkey will be available across those devices.

If the user is using a device that doesn't have a passkey for the website or app, they may have the opportunity to use another device. If the browser supports cross-device authentication, the browser may prompt the user with a QR code that can be scanned by a mobile device to complete the sign-in. Cross-device authentication also involves the use of Bluetooth to ensure proximity.

This is what the end user sees. Let’s take a look at what’s going on behind the scenes, at the server level. When an end user attempts to log into their account with a passkey, the account server sends a “challenge” to the authenticator, consisting of a string of data. The authenticator uses the private key to solve the challenge and sends a response back, a process known as “signing” the data and verifying the user’s identity.

Notice that at no time during this process does the account server need to access the user’s private key, which also means that no sensitive information is ever transmitted. This is possible because the public key – which the server stores – is mathematically related to the private key. The server needs only the public key and the signed data to verify that the private key belongs to the user.

Are Passkeys More Secure?

Passkeys are more secure than passwords, for numerous reasons:

  • For passwords to work, account servers must store them – or at least their hashes – so they can compare the stored data with the password the user enters. As mentioned in the previous section, passkey technology doesn’t require account servers to store users’ private keys, only their public keys. If the account server is breached, threat actors will access only public keys, which are useless without the accompanying private keys.
  • Most people have poor password hygiene. They use passwords that are too short, or contain dictionary words, or biographical information that’s easy to guess. They reuse passwords across multiple sites. And instead of using a password manager, they store their passwords on sticky notes or in unencrypted text files. Passkeys, on the other hand, are generated by the user’s authenticator, so they’re always highly complex and unique to every user and every account, every time.
  • Many people also don’t secure their accounts with two-factor authentication (2FA). Passkeys depend on 2FA by design; to use a passkey, an end user must have their authenticator close by, satisfying the criteria of something you are (the biometric) and something you have (the authenticator).
  • Unlike passwords, passkeys can’t be compromised in phishing schemes, because it’s impossible to trick a user into entering a passkey on a phony lookalike site.

Will Passkeys Replace Passwords and Password Managers?

While passkeys may eventually replace passwords, they won’t replace password managers. Instead, password managers will become even more important. This is because passkeys are tied to an authenticator. Users have a choice as to whether to use a device – usually a smartphone, but a tablet, laptop or desktop could work – or a password manager that supports passkeys.

At first, using a smartphone as an authenticator may seem like the logical option, as most people have their phones with them all the time. However, since most people use multiple devices, this quickly becomes inconvenient. If a user wants to access an account or app on a different device, like their laptop or tablet, they would have to generate a QR code on that device, then scan it with their authenticator, then use their biometrics to finally sign in.

A password manager like Keeper, which will be rolling out support for passkeys in early 2023, will greatly simplify this process by tying the passkey to an application instead of a physical device.

What Companies Support Passkeys?

As of this writing, the number of websites and apps that support this technology is still small. Apple, Microsoft, Best Buy, GoDaddy, PayPal, Kayak and eBay are among the major names that support passkeys right now.

However, because of their convenience and security, passkeys are rapidly growing in popularity. Google rolled out passkey support to Chrome stable M108 for Windows, Android and macOS in December 2022, with support for iOS and Chrome OS in the works, as well as a new API set that will bring passkeys support to Android apps.

What is a Passkey? - Keeper Security (2024)

FAQs

What is a passkey Keeper? ›

A passkey is a modern passwordless authentication technology that allows users to log into accounts and apps using a cryptographic key instead of a password. A passkey leverages biometrics (fingerprint, face recognition, etc.) to confirm the user's identity.

Can passkeys be hacked? ›

No shared secret is transmitted, and the server does not need to protect the public key. This makes passkeys very strong, easy to use credentials that are highly phishing-resistant.

Is the Keeper app safe to use? ›

Frequently Asked Questions About Keeper

Keeper's security features are top-notch, making it one of the safest ways to store your passwords, credit cards, and other personal information.

Is a passkey safer than a password? ›

Introduction. Passkeys are a safer and easier alternative to passwords. With passkeys, users can sign in to apps and websites with a biometric sensor (such as a fingerprint or facial recognition), PIN, or pattern, freeing them from having to remember and manage passwords.

What is the disadvantage of passkey? ›

Many websites haven't adopted passkeys, meaning traditional passwords remain necessary. Additionally, passkey compatibility is limited to modern devices with the latest operating systems. This leaves users of older devices at a disadvantage, as their technology may never be updated to support passkeys.

Can passkeys be stolen? ›

Passkeys also can't be stolen in a data breach. Only the public key is stored on an app or website's server, and it's useless without the corresponding private key. Without physical access to your device (and a way to unlock it), no one can log in to your passkey-protected accounts.

What is the problem with passkeys? ›

They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this.

Can I still use a password if I have a passkey? ›

You can have a passkey and password for the same app or website, and find them both under the same account in Settings > Passwords. You can also save a passkey to a hardware security key.

How do I activate passkeys? ›

Set up passkeys
  1. Tap Create a passkey Use another device.
  2. Follow on-screen instructions. You'll be required to insert your hardware security key and enter its PIN or touch the fingerprint sensor on the key.

Which password managers have never been hacked? ›

Keeper Password Manager is safe to use. According to Keeper's website, it's never been hacked or breached. Because it uses the zero-trust, zero-knowledge system, it makes it a more secure product.

Does Keeper cost money? ›

How Much Does Keeper Cost? Keeper's paid plans start at $2.91 per month ($34.99 annually) for Keeper Unlimited. Subscribers to Unlimited can store an unlimited number of passwords in Keeper, as well as any number of other documents like payment cards, and this data can be synced across an unlimited number of devices.

How do I get rid of Keeper? ›

Open Control Panel. Navigate to Programs > Programs & Features. Right Click "Keeper Commander" and select "Uninstall"

How much does passkeys cost? ›

Passkeys Are Free—Security Keys Are Not

Although you'll need to start using a password manager, the free options that come with your device or web browser may support passkeys. Security keys can cost around $25 to $85 each, and you may want to purchase at least two in case one is lost or damaged.

What is the safest password in the world? ›

Create complex passwords or passphrases
  • An English uppercase character (A-Z)
  • An English lowercase character (a-z)
  • A number (0-9) and/or symbol (such as !, #, or %)
  • Ten or more characters total.

What is a passkey and how does it work? ›

Passkeys are a built-in capability of all major operating systems and browsers that allow users to log in without a username and password, and even skip any two-factor authentication steps. Learn more about the technical details that make passkeys work below.

How do I use my phone as a passkey? ›

On your phone, tap Use passkey.
  1. To verify your identity on your phone, you'll be prompted for your fingerprint, face unlock, or phone PIN.
  2. The next time you sign in with this computer and phone combination, you'll automatically get a notification on your phone to complete the identity verification process.

Where is my Amazon passkey? ›

When signing in to Amazon from another device that uses the same cloud service account, passkey will automatically be displayed as a sign in option. If passkey is not automatically displayed, select Sign in with passkey. You will be prompted to use your Face ID, fingerprint, or device PIN to sign in using passkey.

Who accepts passkey? ›

Learn more about what passkeys are here.
  • Adobe.
  • Amazon.
  • Apple iCloud.
  • Bitwarden.
  • Coinbase.
  • Discourse.
  • GitHub.
  • Google.

Top Articles
Latest Posts
Article information

Author: Carlyn Walter

Last Updated:

Views: 5781

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Carlyn Walter

Birthday: 1996-01-03

Address: Suite 452 40815 Denyse Extensions, Sengermouth, OR 42374

Phone: +8501809515404

Job: Manufacturing Technician

Hobby: Table tennis, Archery, Vacation, Metal detecting, Yo-yoing, Crocheting, Creative writing

Introduction: My name is Carlyn Walter, I am a lively, glamorous, healthy, clean, powerful, calm, combative person who loves writing and wants to share my knowledge and understanding with you.