Passkeys


Passwords are the absolute bane of everyone's online existence. The best practices for making passwords safe and secure are numerous, complicated, and tedious. Consequently, hardly anyone does it right.

People outright reuse passwords. They are tricked into giving up passwords, usually by typing them into realistic but fake login prompts. Passwords are stolen en masse during data breaches. They are successfully guessed-at. And there's a dozen other ways that passwords fail us.

Well, what if I were to say that passwords are finally... meeting their maker? coming to an end? rolling into the station? (cue the dead parrot sketch. iykyk)

In this article, we'll discuss Passkeys, what they are, how they work, and why they are better than passwords in very nearly every possible way.


If you want to skip my usual historical blurb, then scroll down to "The death knell of passwords"

Ancient Times


In today's modern tech world, with all the crazy changes we've seen, it may seem that passwords are a pretty ancient way to prove yourself -- to grant you access to your bank account, email, or whatever. And you'd be right. Passwords are ancient. They predate computers by at least 2,000 years.

One of the earliest recorded examples of password usage comes from the Roman military. The Greek historian Polybius described in the second century BCE how watchwords were used by Roman sentries (guards). The military camps used the watchword to verify that soldiers moving through were friend, not foe.

The watchword was changed nightly and communicated through the camp via small wooden tablets called a tessera which was distributed in a safe and controlled fashion before making the return trip back to the tribune. The tesserae themselves bore identifying marks that allowed the tribune to determine which distribution chains had successfully returned their tablets and which had not.

Military watchwords were used for centuries as a way to identify friendlies in otherwise suspicious circumstances.

The watchwords were simple. You either knew the watchword or you didn't. It didn't identify who you were, just that you were a friendly. For those ancient needs, that was generally good enough.

The Modern Era

In the modern era, a shared password served much the same purpose. That is, to demonstrate that you belong to the same group as the person trying to verify your membership or your claim of belonging.

e.g. The NYPD street crimes division had a "color of the day" password scheme so that plainclothes officers could identify themselves to uniformed officers if or when they got caught up in a sweep or raid. The daily color was communicated throughout the department during roll call or other times when officers would receive briefings.

Passwords, or sometimes a "secret knock", would be used to gain access to a speakeasy* or other secretive membership organization. Resistance groups during times of war would be another good example. The secret knock was useful because if someone did not knock "correctly", they'd simply be ignored rather than being told to go away. The visitor wouldn't have any indication that the place was even occupied.

And to further that imperative to not look occupied, that could be why the term "speakeasy" came about. That is, patrons of an illegal establishment were encouraged to keep the noise level low, to speakeasy, so as to avoid unwanted detection from the outside.

* For the youngins' reading this, a speakeasy was a secret, illegal club or bar where alcohol was served during Prohibition in the US in the early 20th century.

The Computer Age

Passwords may have existed since (at least) the second century BCE but their basic structure didn't change much in the intervening centuries. But when time sharing mainframe computers became a thing, passwords really found their purpose and grew quickly.

Early mainframe computers had no passwords. Access control was physical. You had to be in the computer room to access it and that meant having a key to unlock the door or being allowed in by someone who knew you.

But once remote access time sharing became possible (multiple users accessing the mainframe via terminals scattered throughout a building) then simply locking the computer room door wasn't good enough. We needed digital locks whereby only authorized users could "log in" and use the mainframe. Without login credentials, those terminals were useless even if you had physical access to them.

Passwords were pretty simple because most of the mainframes in the earlier time-sharing days were not networked outside their own building, so attacks from afar were not really a thing. But as computers started becoming networked and more disparate people were using them, then passwords and their management grew in complexity.

New rules evolved, like requiring passwords to be a certain length and making you change them every 30 days or whatever.

Explosive Growth

The real explosive growth in password management complexity came in the 1990s and beyond. This is when the larger world of regular people started using passwords for the first time. And as time marched on, those same people (by now, that's everyone) were collecting more and more passwords. Having several hundred passwords is not unusual.

More password rules were created and every site had their own specific set of rules -- nothing was standardized.

Passwords rules such as:

  • A certain minimum length
  • More complex (some or all of the following: uppercase, lowercase, numeral, and special character)
  • Changed every x days
  • Changed passwords could not closely match previous passwords
  • Certain "popular" words were disallowed
  • Being told to not write them down

No one except security-aware nerds are managing their passwords correctly. So, one person in five or even ten, maybe?

It was (and still is) out of control and is easily one of the major headaches of online life. And unlike some other online headaches, doing this thing incorrectly can have real consequences.

Since the early aughts and continuing today full steam ahead are data breaches. Approximately 30% of the breaches of individual people came about due to a password being compromised. Of that 30%, about half were due to the individuals themselves being phished (tricked into revealing a password) and the other half from a password obtained by the attackers in other ways, such as from a previous mass data breach.

So in all this, it's become painfully clear that passwords aren't the best way to secure your online life.

IF you manage your passwords like a security professional then you're in much better shape and less likely to be compromised.

But the fact is, people aren't security professionals nor should they have to be to safely exist. So, even today, with all the password hygiene advice abound, the large majority of people are still abjectly terrible at managing passwords! No amount of admonition is going to fix that, either.

So, what do we do?

The Death Knell of Passwords

Passwords need to die and the sooner the better. Technology firms are finally doing something meaningful about it.

You've probably noticed recently when logging into certain online accounts that an offer to create a passkey appears. What's this passkey thing and do I want one?

Increasingly, the answer is yes. But not so fast! You'll want to read the rest of this article first.

Passkeys have these advantages, most of which passwords do not:


  • Nearly impossible to phish (that is, tricking you into revealing it)
  • Nothing to memorize or write down, nor any reason to
  • Automatically unique, reuse is impossible
  • Immune from website data breaches
  • Cannot be guessed or brute forced
  • Cannot be compromised by a keylogger (malware that records what you type)
  • Two-factor authentication, the kind using code numbers, no longer necessary
  • Like passwords, (some) passkeys can by synced between your devices
  • Can automatically authenticate you to, say, a web account, using your device's PIN, password, or biometric like your face or fingerprint.

Who is in charge of and promoting passkeys?

The FIDO* Alliance is an industry consortium that includes most of the Big Tech companies. It has been leading the push to replace passwords for more than a decade with that effort culminating in passkeys in 2022.

* FIDO stands for Fast IDentity Online.

Some fun facts: Among numismatists (collectors of coin and paper money), FIDO stands for Freakish, Irregular, Defective, or Odd. It's a word to describe imperfect coins, bank notes, tokens, and that sort of thing. Such imperfections often increase collector value.

"Fido" is also a comically clichéd name for a dog. But here's an extra bit of fun: Fido evolved from the Latin root fides, meaning faithfulness and trust, which is presumably why it became an apt name for dog in the fist place -- man's best friend, after all. I suspect that's why the FIDO alliance chose this for a name and then fleshed it out as an effective backronym by cooking up "Fast IDentity Online".

Muddled and Mangled Messaging

With all these advantages, then why haven't we started using them sooner?


I think the main reason comes down to messaging, education, and implementation which has been a disaster. It's not that passkeys don't work -- they do work. But they are complicated -- not only technically, which doesn't really matter to most people, but also in practice, which matters a lot. It's too easy to do it wrong and get into a bind.

While the FIDO Alliance developed the technology and standards that brought us passkeys, they do not singularly control implementation or user education. As long as consortium members, and other organizations that want to use passkeys, adhere to the standards, they are free to implement passkeys and their various features however they see fit.

The messaging and implementation from one company to another about how to establish, store, and use passkeys on their respective sites can vary wildly. It's inconsistent, poorly described, and negative outcomes are all to easy to experience as a result.

Old fashioned passwords, by comparison, are dead simple to understand. I mean, they've been with us for over 2,000 years! Even though most people don't manage them well, they still understand how they work and know, more or less, kinda sorta, how to keep track of them.

Passkeys, on the other hand, are technically complicated and opaque as a brick wall. There's no tangible, visible bit of information that you can point to and say "That's my Gmail passkey". It requires a leap of faith in a way that passwords never did.

And that, understandably, makes people nervous.

Hopefully, FIDO will get all this messaging worked out and passkeys will eventually replace passwords. At least on websites that are highly sensitive in nature, like your email, bank, retirement account, and so on. Anything involving your money or personal information is highly sensitive.

But until the FIDO Alliance and various tech companies get their shit together on messaging and education, passkeys will continue to elude and frustrate most of us.

The next section is going to discuss the more technical aspects of how passkeys work.

Introduction to Passkeys


I can keep this mostly non-geeky, but there are a lot of moving parts here. I may gloss over certain aspects of passkeys that I don't recommend you using.

First and foremost, if you have already started using passkeys but did not get a thorough introduction and don't really understand how they work then stop making new ones until you've read all this. Getting chest deep into passkeys without a good understanding can land you in considerable trouble.

I'm going to make certain recommendations on what you should do and I'll help justify them by discussing what can happen if you don't.

Passkey Management

Before you delve into passkeys, I strongly recommend that you subscribe to a password manager called 1Password. If you are unfamiliar, 1Password is a cross platform and cross browser password and passkeys storage and sync manager.

What does all that mean?

  • Cross platform: 1Password runs on Windows, MacOS, Android and iOS devices (phones and tablets), and many Linux distributions -- basically every kind of consumer computing device.
  • Cross browser: 1Password officially supports Firefox, Safari, Edge, Chrome, and Brave. It unofficially supports several more.
  • Storage: Securely stores your passwords and passkeys in a local and hosted encrypted vault. If your device dies or goes missing, you will not lose your passkeys nor will they be compromised.
  • Sync: Automatically syncs your passwords and passkeys across all your devices.

1Password consistently ranks among the best of the password managers. Yes, it's another subscription, but it's not expensive. If you're going to start using passkeys, then I cannot overstate how much better your experience will be if you use 1Password to manage them. You can subscribe to 1Password for less than the cost of one latte per month. Don't cheap out on this!

Where the Passkeys are stored

For most practical purposes and without getting into the deep weeds, there are three places where passkeys can be stored and accessed. And where they are stored affects how they can be used.

Let's talk about those three places and how that affects usage.

Passkeys can be stored on a...


  1. Computer (Windows, Mac, various Linux boxes)
  2. Hardware Security Key. This plugs into a USB port and looks just like a flash drive.
  3. Password Manager, such as 1Password

Now let us discuss those three points in greater detail, yes?

1. Computer

Passkeys stored on your computer are device-bound, meaning they work only on that computer. You cannot export or copy that passkey for, say, an email account, and then use it to access that email account elsewhere.

Why would you want to do this? There could be several reasons...

When a computer serves a role rather than a person, say a front-desk computer used by a receptionist, having a device-bound passkey on the email account* used at that computer can prevent the account from being easily accessed elsewhere.

* A front-desk receptionist computer would probably have a generic email account, like "office or info@companyname.com".

There could be other high security, high sensitivity cases where a device bound passkey is desirable, to limit access.

2. Hardware Security Key


Quick Note: Don't confuse passkeys with hardware security keys.

  • Passkeys is the new password-less system for accessing online accounts. That's what we're dissing in this article.
  • A hardware security key is a flash drive-sized device that plugs into a USB port that can store passkeys.

These security keys are often called Yubikeys (pron: YOU-beh-key) because Yubico is the name of a prominent maker of these devices or "keys". There are other brands that do the same thing. I use one made by Thetis.

Passkeys can be safely stored on these portable security keys. The key is protected with a PIN, much like your phone, so if its lost, compromise is highly unlikely. After 8 incorrect PIN attempts (in a row, without an intervening success), the security key is frozen and must be reinitialized to work again, which destroys all the stored keys.

To use, simply plug in the hardware security key like you would a flash drive. Then user your browser, you'll access whatever online account that key is protecting. You'll see a PIN request appear on the computer screen. You'll type in that PIN and you'll also demonstrate "User Presence" by touching a button on the security key.

Similar to how it works on a computer, passkeys stored on a hardware security key are also device-bound -- in this case, bound to the security key, not the computer. That means they cannot be copied or exported. But the security key itself can be used on as many devices as needed. So while the passkey is device-bound to the hardware security key, the security key is portable. It's like having several padlocks protecting different things that all work with the same key, but the key cannot be copied.

This is actually a pretty darned good way of securing company accounts.

This method...

  • Strongly protects against compromise if the security key is lost or stolen
  • Prevents the employee from sharing passwords which is virtually always against company policy.
  • Extremely resistant to phishing-based credential theft (this is true for passkeys in general, not just hardware security keys)

However... If you lose a hardware security key and you don't have a backup security key then you may have to perform the account recovery function on every site whose passkeys were stored on the now lost security key. That could be a major PITA, especially for sites where password access methods were disabled.

Recall what I said above -- passkeys are device-bound to the security key. That means you can't just "make a backup" of the security by copying all the passkeys to a second security key. But you can create your passkeys on additional security keys. People who use only hardware security keys will often have two or more security keys and they'll create their new passkeys on each one, side by side.

This is one of the big downsides that is not adequately covered when introducing a person to passkeys. Well now you know.


The next item, #3, discusses a much better solution.

3. Password Manager

This gives you the most convenient way to use passkeys. Your passkeys are stored in a password manager vault (like 1Password) and synchronized across all your devices and stored in the password manager's online vault. This gives you all the pros of additional passkey security without having to worry about losing a passkey just because you lose a particular device -- or even all of them.

Using this method, your passkeys are not device-bound in the normal sense. They are stored in 1Password, but since 1Password itself is portable and installable on just about every platform you'd ever be likely to use, you have maximum flexibility.

While it's true that you still cannot "write down" your passkeys, a password manager can provide a recovery method that lets you regain access to your vault, and therefore all your stored passkeys, even if you lose all your devices. For example, 1Password provides an "Emergency Kit" containing the information (code numbers) you'll need to regain access to your account from a new device. Combined with your super secret 1Password master password, this gives you a way to recover even if all your previously authenticating* devices are lost.

The recovery kit doesn't include your master password. But there's a line provided where you can write it down if you aren't sure you'll remember it. But the idea with password managers is to have a single, complex, super secret master password, that unlocks everything else. You only have to remember one really good password in exchange for not having to remember or write down any others. That's a pretty good tradeoff if you ask me.

I have a really great master password that nobody will ever figure out and that I'll never forget! But I don't have to remember any others.


For most people that don't want to become passkey experts, this really is the best way to use them. 1Password relieves you from the risks of locking yourself out of everything because you didn't understand passkeys well enough to take appropriate precautions.

* An authenticator is any device that manages passkeys, like your computer or phone, that can provide credentials to a requesting service.

▶︎ How to choose which one to use, device bound or synced?

Unfortunately, you aren't simply asked which type you want to create. That would be too easy, lol. Instead, you may be offered multiple options about where or which authenticator you want to use, if more than one is available. The choices aren't always neatly laid out as a list of "pick one" options, either. Sometimes you must click a link that displays additional options. Yes, I know, another UX (User eXperience) fail. The people that design this stuff really need to get out more and meet regular people.

Which authenticator you choose and its capabilities determine whether you create a device bound passkey or a synced passkey.

I can't predict what all choices may appear when the offer is made to you. It depends on a number of factors including which OS you're using and on which browser or apps that are making the offer.

But if you have both the 1Password product and the 1Password browser extension installed, then it (should) be one of the choices offered to you, even if you have to click another link to find it. And by choosing 1Password as your choice, you'll be creating a synced passkey. That's what you want!

If you don't have a syncable password manager like 1Password installed, then any passkeys you create could be device-bound to either the computer or hardware security key (if you have one) and not be syncable. It's also quite possible this passkey will be the only one you have for accessing that account. If you lose that account's passkey for whatever reason, like your device malfunctioning, then you might need to resort to whatever account recovery features are offered. Better to avoid that altogether by using 1Password.

How to start creating passkeys for my websites?

These days, when you log into a website that you've used before or, especially when creating an account on a new website, you may be asked to create a passkey in addition to or possibly instead of a password. You should accept that offer. Sometimes that offer is not made during login but can be activated by bringing your account profile then selecting security, password, or login options.

There's half a dozen ways at least that websites present that to you. You may have to dig around for it. And it might not even be available. Lots of websites don't support passkeys yet.

If you followed my recommendation and have 1Password properly installed, then it will appear alongside the passkey creation screen as one of the places to save the passkey. You'll then choose 1Password.

Depending on the device type, you may be asked for biometric (face or fingerprint) authentication, PIN, or device password. Or you might not see that, depending on how you've configured the device's authentication settings.

Anyway, if you selected 1Password as the authenticator, the you should see a popup that asks if you want to create a new 1Password entry for that site or to update an existing entry. You'll probably choose to update an existing entry when shown that choice. Then, boom, that should be it. Next time you login to that site on this device or on a synced device then it should work.

Two Factor Authentication

Another terrific advantage to passkeys is you can (usually) dispense with two-factor authentication. 2FA was a great idea when it came about and it did/does help. But 2FA ultimately suffers from the same fatal flaw as passwords. It is, at its core, just a another password that you must type in. And it's just as easily phishable.

If you're tired of typing in code numbers every time you want to login to whatever, then setup a passkey if possible, and be free of regularly using 2FA on those sites.

n.b. 2FA may still be required when accessing a site via old and insecure passwords. But for day-to-day, usually not.

An Alternative

A lot of the weaknesses in passwords -- not all, but a lot -- can be mitigated by just following good password hygiene. Alas, that's something that hardly anyone does. The 1Password manager can help do that without necessarily having to convert everything over to passkeys. At least for right now while there's still a significant number of sites that do not support passkeys.

One of the non-technical, human nature advantages to passkeys is that removes the need to practice good password hygiene in the first place. Passkeys force you away from your previous, sloppy password habits. But it does so at the cost of introducing its own complexity and unfamiliarity -- requiring that leap of faith I mentioned earlier.

And while I did say above that passwords need to die, the fuller truth is that passwords can be used more safely and effectively. The huge problem, of course, is that people don't do that. But if you allow 1Password to manage your passwords in the most optimum way, then you'll actually be in a pretty good security posture without necessarily having to use passkeys. You can have your cake and eat it, too.

One particularly valuable way 1Password can help is by letting it generate a long, truly random password that you don't need to remember or even write down. By letting 1Password fill in the password when needed, it's highly unlikely that a phishing attempt to steal it will succeed. That's because 1Password can't be fooled by a fake login screen the way a human can. And if you don't know the long, random password, then you can't succumb to the phishing attempt, either. By having 1Password doing the password autofill, there's no reason for you to know it!

Your posture is simple: Let 1Password fill in the credentials. If it refuses, there's a good chance the login screen is a fake.

But, really, passkeys is the preferred way going forward.

Assistance

Passkeys are a radical departure from the simple password scheme that some of us, -cough-, have been using for decades. Adopting passkeys and dumping passwords is a pretty big step in how you access your online stuff.

I can help you with whichever way you'd like. Start introducing passkeys or beefing your password hygiene to eliminate most of the downside of passwords.

¿Por que no los dos