Passkey vs. password: What’s the difference and which is better?

← Back to the feed

Passkey vs. password: What’s the difference and which is better?

Engadget · 2 hours ago

An explainer piece compares passkeys with traditional passwords, setting out how each works and why passkeys are increasingly being promoted as the more secure option. The distinction matters because passwords remain vulnerable to reuse, phishing and data breaches, whereas passkeys are designed to remove many of these risks by tying authentication to a physical device rather than memorised text.

Passwords rely on a secret text string that websites store as a scrambled "hash", but weaknesses arise because people reuse weak passwords and can be tricked into handing them over via phishing sites. Passkeys instead use a public-private key pair, with the private key held securely on a user's device and unlocked via biometrics or a PIN, and are engineered not to work on fake "phishing" versions of a website. The article notes passkeys are not yet supported everywhere, can be trickier to share than passwords, and carry a risk of lockout if access to the storing device is lost, but concludes they are generally worth adopting, particularly for those not already using a password manager.

  • Passkeys use device-based keys and biometrics instead of memorised text.
  • They resist phishing and reuse risks that plague traditional passwords.
  • Not all websites support passkeys yet, and sharing or device loss can complicate use.

Art Celebrity Culture Entertainment

Read the full article at the source →