Passkeys vs. Passwords: What They Actually Fix (and What They Don't)

Apple, Google, and Microsoft have spent the last few years pushing passkeys as the end of the password. They're not wrong about the upside — but the pitch tends to skip the parts that are still genuinely rough.

What a passkey actually is

A passkey is a public/private keypair, generated per-site, using the WebAuthn standard. When you "create a passkey" for a site, your device generates a new keypair: the private key stays on your device (or in your password manager's encrypted vault), and only the public key is sent to the site. Signing in means the site sends a random challenge, your device signs it with the private key, and the site verifies the signature against the public key it already has. Nothing secret ever crosses the network.

What passkeys genuinely fix

What the rollout doesn't fix yet

  • Ecosystem lock-in. A passkey created in iCloud Keychain syncs beautifully across your Apple devices — and is genuinely awkward to use from a Windows PC or Android phone that isn't signed into the same Apple account. The "passkeys are portable" pitch is true within one vendor's ecosystem and much shakier across them.
  • Recovery is still the weak link. Lose the device holding your only copy of a passkey, and many sites fall back to... a password, an SMS code, or an email link — often weaker than the passkey you were trying to avoid needing in the first place.
  • Adoption is partial. Plenty of sites don't support passkeys at all yet, so you're managing a mix of passkeys and passwords for the foreseeable future, not a clean replacement.
  • "Which passkey did I use for this site, again?" is a real, mundane problem once you have more than a handful, especially if they're scattered across an OS keychain, a couple of apps, and a browser.

Where a password manager fits in

This is really an argument for keeping passkeys somewhere that isn't tied to a single OS vendor's account system — the same place you already keep your passwords. A password manager that can also act as a WebAuthn authenticator gives you a few concrete things the platform-native flow doesn't:

How Spassword handles this

Spassword can act as a software WebAuthn authenticator on sites that support passkeys — creating and using them the same way a hardware key or your OS's built-in authenticator would, with the private key encrypted and synced alongside the rest of your vault. Every creation or sign-in shows an on-page confirmation you have to approve first; nothing happens silently in the background.

To be upfront about where this currently falls short: it's a software-only authenticator, not an OS-level platform authenticator, and it doesn't yet support conditional UI (the autofill-style suggestion dropdown some sites show for passkeys). A very small number of sites that do strict attestation allow-listing may not accept it. We'd rather list that plainly than have you discover it mid-signup.

Passwords and passkeys, in the same encrypted vault

Free Chrome & Edge extension, zero-knowledge by design.

See how passkeys work in Spassword
← Previous: What "Zero-Knowledge" Means Next: Moving Off Chrome's Password Manager →