Welcome to “Ask a security trainer,” the column where the digital security training team at Freedom of the Press Foundation (FPF) answers your burning questions at the intersection of journalism and security. Submit yours here! Let’s jump right into this week’s question.
Dear DST,
I’ve recently been seeing alerts in my email inbox that I’ve saved a “passkey” when I log into an account. I looked it up, but I still don’t think I understand what this means. Could you explain, and do you recommend it?
Signed,
Locking Good
–
Hi Locking,
Normally, when you log into a website or service, you enter a username and password. The problem with that is that anyone can use these credentials. For example, if your password is stolen in a phishing attack, if a website loses control of your password in a data breach, or if you simply use a short and predictable password, this makes it much easier for an attacker to log in and masquerade as you.
Passkeys are an emergent authentication technology designed to solve this problem. We recommend using them when you can.
A passkey is a login credential that is stored on your device and accessed by demonstrating you are the rightful account holder. For example, you can use your fingerprint, face scan, or a prompt on a phone or other device you have already unlocked. You can also store a passkey on a piece of physical hardware in your possession, such as a security key, a little USB device you can plug into your phone or computer to demonstrate you are the rightful owner of an account. Once you have demonstrated you have a credentialed device, you can log in.
Entire textbooks are dedicated to the encryption we depend on to generate a passkey, and while I personally find it fascinating, I will spare you the details about how it works. (If you want a short and accessible introduction, watch this!)
In any case, a passkey on your device is just a credential in the form of a private key, which, like the key to your house, is required to prove you are entitled to enter. The private key is represented by a lengthy set of random letters and numbers, so long that it will be nearly impossible to guess.
So, passkeys are much stronger than standard passwords, and you can’t enter them into a phishing page. This is exciting technology because it’s significantly more secure than traditional login methods.
Companies like Google tout how simple it is to use passkeys. I somewhat disagree here. I do think this can be confusing to people. You know exactly what a password is and how to use it. By comparison, a lot of people don’t know what a passkey is. There's a good bit of research that shows people sometimes have a tough time with account recovery and sharing passwords with others whom they trust.
Likewise, using a passkey can sometimes be a challenge because a variety of actors are competing to store it for you. For example, they can be stored at the level of your operating system, in a browser, or in your password manager. Depending on where you store them, you may or may not be able to easily access them from another device. So I’d recommend keeping them in a trusted password manager that you use on your phone, computer, and elsewhere.
Industry actors have pushed to implement passkeys on many major websites, and while they are a strong option, as an emergent technology, passkeys aren’t yet supported everywhere. Check if your favorite website supports passkeys. You’re probably going to see more of these prompts to add a passkey to your phone or computer in the future. But traditional passwords aren’t dead yet.
If you want to learn more about getting started with passkeys, read our guide! Meanwhile, I’ll leave you to lock up around here.
Best,
Martin Shelton




