Skip to main content

Security

Passkeys, explained without the jargon

A passkey is not a password you cannot see. It is a different mechanism, and it removes the single most common way accounts are taken over.

Tom AshworthPrincipal Security Engineer4 minute read

A password has a design flaw that no amount of length or complexity fixes: you have to send it to whoever is asking. If the thing asking is a convincing copy of your bank, you have just handed over the key.

What a passkey actually is

When you create a passkey, your device generates two related keys. One stays on the device, protected by your fingerprint, face or device passcode, and never leaves it. The other is given to us. To log in, your device proves it holds the private key by signing a challenge we send. The secret itself is never transmitted.

There is nothing for a counterfeit site to capture, because nothing secret is sent. And the passkey is bound to our real domain, so it will not even offer itself to a lookalike.

What it means day to day

  • Logging in is a fingerprint or a glance, not a password and a code.
  • There is nothing to remember, reuse, or leak in someone else’s data breach.
  • A phishing page cannot collect it, however good the copy.
  • It syncs across your devices through your platform’s keychain, so a lost phone is not a lockout.

Is it safer than a password and a text code?

Meaningfully, yes. A one-time code sent by text is better than nothing, but it can be read out to a convincing caller, intercepted by a SIM swap, or entered into a counterfeit page in real time. A passkey cannot be given away, because there is nothing to give.

  • passkeys
  • log in
  • phishing

Banking that agrees with itself

Every figure on this site comes from the same catalogue the bank runs on. Open an account in about five minutes.