CYBERSECURITY

Passkeys and security keys without the jargon

How a passkey differs from a password, SMS code, and authenticator code — and how to switch without losing account access.

Tomek7 min readBEGINNER

A passkey lets you sign in without typing a password. The service stores the credential’s public key. The private key remains in a device or security key; when passkeys are synced, an encrypted copy may reach your other devices. The service never receives it. When you sign in, the device asks for a fingerprint, face, or PIN. That approves use of the passkey locally — the service does not receive your fingerprint or device PIN.

The main practical difference is that a passkey is tied to the correct website. A fake page that resembles your bank or email provider should not receive a credential made for the real domain. This does not stop every kind of attack, but it removes a common failure: entering both a password and a code on a scam page.

Passwords, SMS, TOTP, and passkeys

  • A password can be entered on a fake page, reused, or stolen from a database. A password manager still matters where passkeys are unavailable.
  • An SMS code adds a second step, but it depends on your phone number and carrier. SIM takeover, message access, and scams that persuade you to read out the code remain possible.
  • TOTP is a usually six-digit code from an authenticator app. It does not need mobile reception, but it can still be entered on a fake page. You also need a safe way to move or restore the generator when changing phones.
  • A passkey has no secret for you to copy into a form. It may be synced through a trusted device-provider account, or kept only on a particular device or physical key.

A physical security key is a small USB, NFC, or Bluetooth device. It can hold a passkey or act as a second sign-in factor. It is useful as a backup independent of your phone, but only where the service supports it.

What if the phone is lost?

Losing a phone does not have to mean losing your accounts. Access may remain on a second device, a spare security key, or a secure recovery method. Passkeys synced through an Apple, Google, or Microsoft account may appear on a new device after you complete that account’s recovery process. Details differ by provider, so do not assume that “the cloud will restore everything.”

The risky setup is one phone that holds the only passkey, the only TOTP app, the only SMS number, and the only copy of the recovery codes.

A safe migration

Do not remove the old method after one successful sign-in. First:

  1. Enable a passkey on one important account and test it in a new private browser session.
  2. Add another route in: a different device, a second key, or recovery codes stored away from the phone.
  3. Confirm that you know the recovery process for the main account that syncs your passkeys.
  4. Only after testing, decide whether to keep the password or TOTP as a fallback. Remove SMS only if the service permits it and another method works.
  5. Repeat separately for email, your password manager, Apple/Google/Microsoft accounts, banking, and social media.

Do not move everything at once. Isolation has a simple meaning here: the failure of one phone or syncing account should not close every recovery route.

Use the passkey and MFA migration checklist to work through your accounts. The FIDO Alliance passkeys page explains the standard and lists deployments.

Want this in a lab or in production?

The article stays free. The form is for scope, not a paywall.

The inquiry is stored on the server. You will get a short confirmation from hello@tomek.st. The operator is also notified on Telegram and email.