1234
ABC
WRITING · 5 June 2026

Passkeys: Easier for you, harder for attackers

Passkeys eliminate passwords entirely — nothing to remember, type, or steal. Here's how they work and why they're worth adopting.

You've heard the rules. Your password should be long, complex, and unique for every site. Now be honest: do you actually do that?

Most people don't. We reuse passwords. We pick ones we can remember. We don't change them unless we're forced to. And that's not because we're lazy — it's because the rules are impossible to follow at scale.

Here's the problem: one breach, and that reused password unlocks everything.

But what if you didn't need a password at all?

Enter passkeys

A passkey is a new way to log in — and it's simpler than what you're doing now.

Instead of typing a password, you unlock access with your face, fingerprint, or device PIN. That's it. No password to remember. No password to type. No password to steal.

Behind the scenes, your device holds a private key that's never shared with the sites you log into. When you log in, your device proves you're you — without sending any secret across the internet.

The core idea: no one can steal a password that doesn't exist.

Why it's easier

I've been using passkeys everywhere I can. The experience is simple: I scan my face or tap my fingerprint, and I'm in. No typing. No "forgot password" flows. No digging through a password manager.

Even better — passkeys sync across your devices. Set one up on your phone, and it's available on your laptop and tablet too. One setup, access everywhere.

"But what if I lose my phone?"

This is the fear everyone has. And it's a fair question.

The answer: passkeys sync to your cloud account (Apple, Google, or your password manager). Lose your phone? Your passkeys are still on your other devices. Get a new phone? Sign into your account, and they're back.

It's no different from losing a phone today — except now there's no password for someone to guess or steal.

Why it's safer than password + MFA

You might think: "I use two-factor authentication. I'm already secure."

MFA is better than passwords alone. But it's not bulletproof:

  • Real-time phishing: A fake site can capture your password AND your MFA code as you enter them — then use both immediately.
  • SIM swapping: Attackers convince your carrier to move your number to their SIM. Now they get your text codes.
  • MFA fatigue: Attackers spam you with login notifications until you accidentally approve one.

Passkeys sidestep all of this:

  • Nothing to type, nothing to intercept. Your private key is never shared with the sites you log into.
  • Site-specific. A passkey only works on the exact site it was created for. Fake site? The passkey won't even activate.
  • Built-in two-factor. Possession (your device) + biometrics (your face or fingerprint). It's MFA by design — but phishing-proof.

The ask

Next time a website — your bank, a shopping site, a social platform — asks "Would you like to use a passkey?" say yes.

It's easier to use. It's harder to break. And there's no password to steal.

The future of logging in is already here. Try it.

← All writing
Project
GABRIEL ZEHNDER — IAM → SECURITY
Location
COPENHAGEN, DK
Focus
SECURITY ARCHITECTURE
Rev
C