Data & Privacy
A passkey removes the secret you could be tricked into giving away
There is no shared string to type, leak or hand to the wrong site. The device signs a challenge, and the signature only works for one origin.

Both approaches to passkeys work. What differs is what they cost you, and the cost is what this sets out.
The difference in one place
- The private key never leaves the device and is never sent to the site.
- The signature is bound to the site's origin, which defeats phishing.
- Recovery and account transfer remain the difficult part.
Nothing shared means nothing to steal
A password is a secret both you and the service know, which means the service stores something that can be stolen. A passkey is a key pair, where the service holds only the public half and the private half stays on your device. Because the private half is never transmitted, a breach of the service exposes nothing that can be used to sign in.
There is also nothing for you to remember, retype into the wrong window or reuse across unrelated accounts. The change is structural: it removes an entire category of failure rather than making that category less likely.
Proving possession without revealing it
When you sign in, the service sends a random challenge that has never been used before and will not be reused. Your device signs that challenge with the private key and returns the signature, which is meaningless for any other challenge. The service verifies the signature against the stored public key and learns only that the correct device participated.
In practice, an intercepted signature is useless afterwards, because the next attempt will involve a completely different challenge. The device usually requires a biometric check or a screen unlock before signing, which is what ties the key to a person.
Origin binding is the part that defeats phishing
Each credential is registered against a specific site identity, and the browser includes that identity in what gets signed. A fraudulent site with a similar name presents a different origin, so the browser will not offer the credential at all. Even a convincing replica cannot obtain a usable signature, because the check is performed by software rather than by your judgement.
This is the difference from codes typed into a page, which a person can be persuaded to enter anywhere. It also means a passkey cannot be relayed by an attacker sitting between you and the genuine service.
Where the private key actually lives
Keys are held in a secure element or equivalent protected storage, separated from ordinary applications on the device. Access requires the device unlock, so an unattended unlocked device remains the obvious weak point in the arrangement.
Hardware security keys hold credentials on a separate physical object that must be present and often touched. Device-bound credentials cannot be copied anywhere, which is excellent for security and unforgiving when the device is lost.
That trade is why most consumer implementations chose a different approach by default.
Synchronisation changes the threat model
Most platforms synchronise passkeys through an account so they are available on every device you own. The keys are encrypted in transit and at rest, and the platform account becomes the thing protecting everything. This is genuinely convenient and it reintroduces a central point whose compromise would matter a great deal.
Whether that is acceptable depends on how well that account is protected and what the alternative would cost you. Some services allow both, letting a synchronised credential handle daily use with a hardware key held in reserve.
Firmware updates change this behaviour more often than hardware does.
Recovery is the unresolved part
Losing every device holding a credential means proving who you are through some other route entirely. That fallback is frequently an email link or a code sent by text, which is precisely the weaker mechanism being replaced. An account is only as strong as its weakest recovery path, and a strong credential does not remove a weak one.
Registering a second credential on a separate device is the practical answer and is easy to forget until it matters. Moving credentials between platforms remains awkward, and standards work on transfer is still developing.
Side by side
| Consideration | What it means in practice |
|---|---|
| Nothing shared means nothing to steal | The private key never leaves the device and is never sent to the site. |
| Proving possession without revealing it | The signature is bound to the site's origin, which defeats phishing. |
| Origin binding is the part that defeats phishing | Recovery and account transfer remain the difficult part. |
The takeaway
The improvement is not a stronger secret; it is having no shared secret at all.
Understanding the failure mode tells you more than the feature list does.
Questions readers ask
What happens if I lose my phone?
If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.
Is a passkey the same as biometric login?
No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.





