Passkeys vs. Passwords
For decades, I.T. industry pundits have declared that passwords were obsolete and would soon be replaced by more secure methods of proving you're who you say you are when you try to access your email account, online file storage, social media, news site subscription, or your work network. Yet, as you read this, either you have a long list of passwords in a spreadsheet, you use a password manager, or you use the same password for all your accounts, right?
The big problem with a password is it's just a string of letters and numbers that someone else can either guess, find in your spreadsheet, or get you to tell them. And with only the password protecting access to your account, if any of that happens, a so-called bad actor can get your private files, send communications impersonating you, or take money out of your bank account.
Additional checks can help foil all but the most sophisticated bad actors. For example, most systems secured with a password now require some complexity to make simply guessing it impossible. But this doesn't protect against someone getting the password some other way.
Or, a web site might notice you're logging in from a web browser you haven't used before (because it can't find a "cookie" file it left in your browser last time you logged in), or from a foreign location (based on IP address). In response, it might to send you a random string of numbers (a "verification code") via SMS or to your email, and ask you to type that in within a few minutes, ostensibly to prove it's still you. The idea is it shows you have handy whatever device you use to receive SMS or email, using a phone number or email address it has on file for you. But still, the code supposedly proving this is still just information that can be intercepted. That is, if a criminal calls a victim impersonating an agent from their bank, and tricks the victim into telling the criminal his password, it's trivial to get the victim to tell the criminal the verification code the real bank sends to confirm the victim's identity. Then the criminal is logged in from his computer as the victim, simply through information exchange. Or, without having to call the victim, if a criminal can steal his password from a breached list and intercept SMS messages to his phone, he's in just the same.
Multi-factor authentication (MFA), which we started seeing in corporate environments around 2000, provided a little more technological protection to what is still a knowledge-only authentication method. The idea is similar to SMS or email verification codes, but with less capability for interception. A unique, secret cryptographic key is set up for each user, shared with the website that holds your account. This key is stored in some sort of physical device each user must have, which generates temporary verification codes every thirty seconds or so using a combination of the shared secret key and the current time.
Back in 2000, a common MFA device was called RSA SecurID, a little gadget that people could have on their keychain, with a tiny screen to display the verification code, called a "token" or a "one-time password" (OTP) back then. This was eventually replaced with mobile phones, where something called an authenticator app performs the same function as the RSA SecurID did. So when a user logs in with a password and then is prompted to enter the temporary verification code, the login server uses its saved copy of the secret key for the user and the current time to generate a code, which will match what the user is typing in. As you can see, if a criminal steals a potential victim's password to a secure system and tries to log in to the victim's account, now he needs a code, but has no way to get it, because it is not transmitted at all, let alone via an insecure communications medium like SMS or email. But, even though it is temporary, the code is still just information the criminal may somehow be able to acquire to get past this obstacle. There are two ways. One is the same as what works with SMS/email; that is, he is in contact with the victim and tricks him into reading out the code. The other is if the system the criminal is trying to log into is breached, and the shared secret cryptographic keys for each user are exposed. With those, the criminal could generate the codes himself.
With a secure architecture on the part of the web server, and vigilance by potential victims, this should be rare. But, still, what if there was a way where to make it so a criminal, even if he's told all the information his potential victim needs to log in, can never log in?
That's what passkeys were designed to do.
So what is a passkey? The word is similar to "password", but the concept and function are quite different. In short, it's an authentication system that relies on asymmetric cryptography and modern device capabilites to eliminate the need for any strings of letters or numbers to be known, let alone transmitted, to prove your identity.
It's pretty new, really appearing in 2022, and starting to get wide use in 2023. It requires some sort of device that supports the advanced cyptographic functions passkeys rely on. Mobile phones and computers use a combination of software and special hardware designed for performing these functions, meaning passkeys cannot be implemented directly on older devices. For those older devices, though, users can purchase a physical security device that supports passkeys and plugs into a computer via USB, or connects to a mobile device via Bluetooth. Whether it's built-in or implemented with a separate connected security device, we'll call it a "passkey device" from here on.
As mentioned, passkeys rely on the magic of asymmetric cryptography. The user's passkey device (modern mobile/computer, or connected security device) generates an insanely large random secret number that never leaves the passkey device*, along with a cryptographically related number (called a "public key") that is then sent to the web site where the user has an account. The secret key and public key together are called a "key pair". The magic is in the fact that the public key can be captured by a criminal, but with just that it is virtually impossible to derive the secret key that is stored on his potential victim's device.
So, the web site stores the public key in the user's account, and can disable his password. When the user wants to log in later, the server relies on yet another magical aspect of asymmetric cyptography. Here's what it is: Ordinary data (such as, for example, the text on this page) can be encrypted (meaning all scrambled up so it's not readable) using a process (called an algorithm) that uses one key of an asymmetric key pair as part of the mathematical function that determines the actual contents of the text in its encrypted state. One can take that encrypted text, know the exact algorithm used, and even have the key used to encrypt it, but it's impossible to unencrypt it! The way the algorithm works (and this is why it's called asymmetric), the other key of the keypair must be used to restore the data to its original, unencrypted state.
See how this can be useful? When someone who has a passkey set up tries to log in, the server just has to generate some random data, encrypt it with the public key of the user (which it has), and send it to whoever is trying to log in. Only the passkey device belonging to the actual user will hold the related secret key (remember, it never leaves the passkey device). The passkey device performs the decryption using the secret key, and then communicates back to the server to prove it has the original data that the server had sent encrypted. All this just happens on the passkey device and in communications between the passkey device, web browser, and the web server, which the user doesn't even see. There is nothing to type in, so no information a criminal can intercept or trick a user into telling him.
And because the web browser on the user's device only uses the passkey capabilities of the device itself, or a passkey directly connected (by USB, NFC, or Bluetooth), it can only work on the user's device. To illustrate: As described above, if a far-away criminal knows his victim's password and, even though the victim has his mobile phone securely in his possession, the criminal is somehow able to get the victim to read him the MFA code from his phone, the criminal types all that into the website in his browser on his computer, and he's logged in as the victim. But with passwords disabled on the account, what could the criminal do? If he gets his victim to plug his passkey device into his own computer, that only logs in the victim on his computer. The criminal will have no access.
Another capability of passkeys that makes them so much more secure is that it uses a system to confirm the identity of the web server a user might try to connect to on his device, and if it doesn't match, it won't even proceed with a login attempt. This system has actually been around about as long as the web (mid-1990s), and you've heard of it. It's called SSL or HTTP/S. Part of this system is that your computer relies on a world-wide system of trust, all implemented with the same asymmetric cryptographical identity confirmation that passkeys use to prove you are who you are, to confirm the identity of the website you intended to visit.
With passwords and MFA authenticator apps, even with HTTP/S, if someone is tricked into visiting a web site that looks like his bank's, but is run by criminals, it can prompt him for his password and then MFA code, relaying the information typed in by the victim from the back end of the criminals' network to the victim's actual bank, and then the criminals are logged in from their network! But part of the passkey protocol involves the passkey device verifying the identity of the web server the browser is connected to before it will proceed with logging in. So there is no way a criminal can successfully victimize the user of passkeys with an impostor website, whether it's an alternate website (with a different domain name) or whether the criminal managed to insert himself between the user and the bank's website (using the bank's actual domain name). None of it will ever work with an account using passkeys only.
You might be thinking, using a passkey and disabling the password will prevent far-away criminals from getting into your account. But what about if your device is stolen? Or someone sits down at your computer while you're away? You might not save your passwords in your devices just for this scenario, but if the device is set up to use passkeys, then the thief gets right in to all your accounts.
Well, they won't, because passkey devices require that a PIN code be set, which you must type in to activate each passkey login. A thief with your device in hand can't log in to your accounts without typing the PIN. But so now we're back to you having to remember something to type in? Not really, as the PIN can be as few as four digits, and it applies to the passkey device itself, not each account, so there's only one to remember. No need for a spreadsheet to keep track of your PINs.
Even though it can be only four digits, the PIN is considered highly secure, so long as you don't share it with anyone. If someone steals your device, you'd think maybe with enough time they could guess it. But, when a passkey device prompts for a PIN, if it's typed wrong too many times, the passkey device will either lock the device for a period of time, or eventually may wipe out your secret keys, meaning even if the criminal guesses your PIN later, the secret keys necessary to log in to any of your accounts are gone. That will be quite a pain if you get your phone back, but at least your accounts are all secure from breach.
Also, if you suspect your PIN is known and fear your device being stolen, it's easy enough to change the PIN, since it's entirely used locally by your device to secure your secret keys, and won't affect any of your accounts on any web sites.
Finally, your passkey device can be secured with biometric capabilities of your laptop or mobile device, such as facial recognition or fingerprint scanning, making unlocking your passkeys even easier than typing four digits.
Are there any drawbacks? The most significant one is if you have only one device, and the device is lost or dies, then you lose access to any accounts for which you have passkey-only authentication set up. If you get a new computer or phone, and try to log in, you may need to go through an arduous process to prove your identity to the service provider and get back in. We all know the "Forgot password?" link, but there can never be a "Reset passkey?" link if your password was disabled and you're not logged in already.
Here's another: If you have multiple devices all by the same provider (major ones being Google for Android, Apple for iOS, and Microsoft for Windows), these systems do support syncing passkey secret keys between devices, but only those that are on the same platform. So if you set up a passkey to access your Google Account on an Android phone and also log in to the same Google Account on an Android tablet, you could use that same passkey on that tablet after syncing.
By the way, it was stated above that the secret keys never leave your passkey device, but you see there is an exception here. The syncing process for these providers, however, is implemented with modern zero-knowledge architecture, wherein the keys are encrypted by your device before being sent to another, using keys only your devices know. So in other words, if someone with full administrator access to Google's servers watching communication between your Android devices captured your communications while you were syncing passkey information between them, it would all be encrypted with encryption keys that only exist on your devices.
If you use devices from multiple providers (say, you have an iPhone and a Windows laptop), and want to log into the same Google Account using passkeys, you would have to set up separate passkeys. Google Accounts support multiple passkeys per account. But, other providers might not, meaning if you want to disable passwords on the account and use only passkeys, you would have to choose whether to log in to the account on your iPhone or Windows laptop.