IT security

Passkey

Also known as: FIDO2/WebAuthn sign-in

In short

A passkey is a device-bound cryptographic key that lets you sign in with biometrics or a device PIN instead of typing a password.

A passkey replaces the password with a key pair based on the FIDO2/WebAuthn standard: a private key stays securely stored on the device, and a public key sits with the service provider. During sign-in, the device uses the private key to prove it belongs to the right user, released by a fingerprint, face scan, or device PIN.

In practice, on a service that supports passkeys, a fingerprint or a glance at the camera replaces typing a password. A passkey is also tied to the exact web address of the service it was created for, and it simply won't work on any other address, even one that looks identical.

That binding to the correct address is exactly what makes passkeys the most effective progress against phishing to date: a fake login page can't capture a passkey. A common misconception is confusing a passkey with a password saved in a browser – a passkey never leaves the device.

What it means in practice

For a business, moving to passkeys means accounts that support them become considerably more resistant to the single most common attack: stolen or phished passwords. A sign there's untapped potential here is a business where important services are still secured by password alone even though the provider already offers passkeys. NDVDL advises where switching to passkeys pays off first.

Is this handled properly at your site?

We look at how it actually stands with you — and say honestly whether anything needs doing.

IT security & firewall

A term from your quote missing here?

Send us the passage you do not follow. We will explain it — with no obligation to order anything.