The tech industry keeps telling you passkeys are the future of logging in. Google tells you to skip passwords when possible. Microsoft wants you to make your account passwordless. The pitch is simple: passkeys are safer than passwords because they can’t be stolen from a server. That’s the good news. The bad news is passkeys might lock you out of your accounts for good.
Why Passkeys Are Safer Than Passwords
Passkeys are a great fit for corporate security. They are bound to the site they were created for, so a hacker can’t steal them by tricking you into typing your password somewhere else. If a site suffers a data breach, passkeys are asymmetric, meaning hackers can’t recover them from server-side details. That makes them nearly impossible to phish.
But for personal security, passkeys create a bigger problem than they fix. The biggest risks for an individual are permanent account lockout, automated account bans, and losing a device. Passkeys protect you from man-in-the-middle attacks, but they increase the chances of losing access to your accounts entirely.
The Lockout Problem
Phishing is gone with passkeys. That’s the point. But it creates a false sense of security. Your account’s actual security depends on the weakest recovery method you’ve set up elsewhere: SMS, email links, security questions. If those recovery methods aren’t enabled, you still risk permanent lockout.
Hardware Keys Are Limited
Hardware keys are supposed to solve this. You can add passkeys to a physical device. But you can’t back them up. You can only add or delete them, not move them. So you need to buy 2-3 hardware keys and enroll each one on every site. That gets expensive fast.
These keys also have limits. A hardware key can hold only 25-100 accounts per site, with some top-end keys reaching up to 300. Once you hit the cap, you either delete accounts or buy another set of keys.
Synced Passkeys Tie You to One Vendor
Apple and Google want your identity tied to their operating systems. Their “happy path” is to use synced passkey management linked to your Apple or Google account. If their automated systems decide to ban your account one day, you lose access to all your passkeys across all third-party accounts. It’s irreversible.
The FIDO alliance is working on making passkeys more portable, but the experience is still fragmented and inconsistent across providers. It’s getting better, but it’s not ready yet.
Third-Party Managers Are Fragile
Storing passkeys in a password manager like Bitwarden or KeePassXC is the current compromise. But it fights the platform. Operating systems have started introducing APIs, like Android’s Credential Manager, for third-party tools to hook into. The experience is still fragmented and lacks the decades of polish built around password autofill.
Autofill outside the browser and inside native apps is especially inconsistent. In the future, third-party passkeys will likely be the way forward. We’re not there yet.
What Happens When Passkeys Don’t Work
Logging into accounts on devices you own works great with passkeys. On a colleague’s computer, it gets awkward. You can plug in a hardware key, but you don’t always have access to the ports. You can sign in and use a synced passkey, but that means trusting the computer to not leak all of your other passkeys.
The last option is “Hybrid Transport,” where you scan a QR code and connect via Bluetooth simultaneously to the computer. It’s secure in theory, but reality is plagued with edge cases where connections fail or Bluetooth is straight-up unsupported.
The Bottom Line
| Security Feature | Enterprise Fit | Personal Fit |
|---|---|---|
| Passkeys | Perfect | Poor |
| Passwords | Known phishing risks | Easy to recover |
Enterprise users have good reason to use passkeys. The ecosystem isn’t mature enough for individuals yet. TOTP codes have known phishing risks, but the recovery and lockout risks of passkeys pose a greater day-to-day risk to most people than an AiTM proxy.
For users who previously reused passwords across all their sites, passkeys are a huge step up. For everybody else, it’s currently a step back.
Source material: “I don't like passkeys,” hawksley.dev.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

