Vol. XVI · No. 267Thursday 24 September 2026World Edition
TheNewsRupt coat of arms crest

The NewsRupt

Reported

What Passkeys Actually Fix — and What They Do Not

The password replacement is finally arriving at scale. It kills phishing dead, and creates a new set of problems nobody has fully priced in.

By The NewsRupt Desk·San Francisco desk·Thursday 24 September 2026·7 min read

The passkey rollout has crossed the threshold from early-adopter experiment to default setting. The largest platforms now prompt users to create one, the browser and operating system vendors have built the plumbing, and the sign-in flow — a fingerprint or face glance instead of a typed secret — is genuinely better than what it replaces. After two decades of password managers, breach dumps and credential-stuffing attacks, the industry has shipped a real fix. It is worth being precise about which fix it is.

The core achievement is phishing resistance. A password can be typed into a fake site; a passkey cannot. The credential is bound to the domain that created it, and the browser simply will not offer it to an impostor page, no matter how convincing the lookalike. This eliminates the single most common account-takeover technique at a stroke, and it does so without asking the user to make any judgement calls. Security features that depend on users being careful fail; this one does not.

The secondary benefits are real too. There is nothing to reuse across sites, so the domino effect of one breach unlocking other accounts disappears. There is nothing for a breached server to leak that an attacker can replay. Login becomes faster, which sounds cosmetic until you count the abandoned sign-ups and support tickets that friction costs.

Now the honest accounting. The first problem is lockout. A password lives in your head; a passkey lives on your devices. Sync through platform clouds helps enormously, but it ties your credential recovery to your platform account, and losing access to both is a scenario the recovery flows handle unevenly. Some services treat a passkey as the whole identity and leave users who lose their devices with no path back but a support queue.

The second problem is portability. A password manager let you carry your credentials from one ecosystem to another. Passkeys, for now, mostly do not travel. Standards work on export is under way, and the security community is rightly cautious about making phishing-resistant credentials too easy to move — an export mechanism is an attack surface. But the interim state is a quiet deepening of platform lock-in, arrived at for good security reasons and with real competitive consequences.

The third problem is the long tail. The major platforms are passkey-ready; the enterprise SaaS tools, government portals and regional services where most people actually do business are years behind. Users will run mixed models — passkeys here, passwords there, SMS codes somewhere else — for the rest of the decade. Mixed models are where confusion, and therefore risk, lives.

None of this argues against adoption. The guidance is simple: turn on passkeys everywhere they are offered, keep a second device enrolled, and know your recovery path before you need it. The limitations of this assessment: rollout quality varies enormously by service, recovery flows are the least standardised part of the stack, and export standards remain a work in progress that could change the portability picture within a couple of years.

How we report

Every claim above is sourced to a document, a named person, or a record we hold. Where we could not verify a claim, we say so. Read our standards and corrections policy →