![]() Keeping clients' computers safe and profitable for over 30 years | |||
Home Forms About Current Newsletter subscribe Search All Articles
Browse by Category
![]() |
Passkeys![]() Preview:Passkeys are all the rage, but I'm unimpressed. It seems like a miniscule benefit for significant potential problems. They are not worth using.
Passkeys are quite the rage. They claim all sorts of wonderful conveniences. Passwordless account entry. Better security, and so forth. What are they really? They use public-private key encryption to verify your access instead of a username and password. A private key is stored in a secure vault on your computer, phone, or tablet. That safe, secure key is matched to your account and used instead of a password. So, if that vault is just as secure as your password manager, then you will gain an infinitesimal security benefit. I wrote an article explaining public-private key encryption here. So that's a good thing, right? Well, maybe. You'll still need your password manager to handle the 95% of logins that require a username and password. Furthermore, you need to log into your passkey vault with a password. Sometimes the private key is stored on your device, so logging into your device provides someone with access to all your passkey accounts. If you use your password manager or have a passkey application, then you can use a good password to secure it. But if they store on your device, you'll need a strong password to access your device. So, what we have is one more application handling 5% of our accounts or requiring us to beef up our device login protection. There are other downsides:
I remain entirely unimpressed and recommend sticking to your secure password manager. Date: June 2025
![]() This article is licensed under a Creative Commons Attribution-NoDerivs 3.0 Unported License. |
||
|