Knowledge

Passkeys: signing in without a password, and why that is safer

A passkey replaces the password with something you cannot give away, because you never see it yourself. Signing in becomes simpler, not harder.

What a passkey is

A passkey is a pair of keys. The website you sign in to gets the public half. Your device keeps the secret half, protected by whatever you already unlock it with: fingerprint, face or PIN.

When you sign in, the website sends a random challenge, your device signs it with the secret half, and the website checks the signature with the public half. No secret ever travels over the network. Your fingerprint does not either: it only unlocks the key on the device.

Why a passkey cannot be phished

A password can be typed into a fake page. A passkey cannot: it is bound to the address of the website it was created for, and the browser offers it on no other. A copy of the sign-in page at a similar address simply gets nothing.

And because the website stores only the public half, a break-in there leaves nothing to steal that anybody could sign in with.

Where the passkey is kept

Usually in the device's password manager, iCloud Keychain or Google Password Manager. From there it is copied, encrypted, to your other devices, and a new phone has it again once set up. A hardware security key, by contrast, keeps it on itself only; that is stricter, but if the key is lost, so is the passkey.

When the phone is lost

A synced passkey is still there on your other devices. For everything else an account needs a second way in, such as the password with a second factor, or recovery codes. That is why, at most services, a passkey does not replace the password entirely but sits beside it.

How EAuth does it

With EAuth, passkeys are on for every application, without a developer having to set anything. On the account page you add one after confirming with your password. Where the browser can, it offers the passkey right in the email field. The password with a second factor stays as the second way in.

Sources

  1. Passkeys, FIDO Alliance
  2. Web Authentication: An API for accessing Public Key Credentials, W3C
  3. Passkeys in EAuth, docs.elchi.dev