Passkeys vs. Passwords: What They Actually Fix (and What They Don't)
Apple, Google, and Microsoft have spent the last few years pushing passkeys as the end of the password. They're not wrong about the upside — but the pitch tends to skip the parts that are still genuinely rough.
What a passkey actually is
A passkey is a public/private keypair, generated per-site, using the WebAuthn standard. When you "create a passkey" for a site, your device generates a new keypair: the private key stays on your device (or in your password manager's encrypted vault), and only the public key is sent to the site. Signing in means the site sends a random challenge, your device signs it with the private key, and the site verifies the signature against the public key it already has. Nothing secret ever crosses the network.
What passkeys genuinely fix
- Phishing. This is the real win. A passkey is cryptographically bound to the exact origin it was created for. A fake login page at
paypa1.comsimply cannot trigger your real PayPal passkey — the browser won't even offer it. Compare that to a password, which you can absolutely be tricked into typing into a lookalike site. - Nothing worth stealing in a breach. If a site's database leaks, all it had was your public key — mathematically useless for impersonating you. No password hash to crack, no reused-password chain reaction across other sites.
- No more password reuse problem, for the sites that support it. Every passkey is unique to its site by construction; there's no way to accidentally reuse one across accounts the way people constantly do with passwords.
What the rollout doesn't fix yet
- Ecosystem lock-in. A passkey created in iCloud Keychain syncs beautifully across your Apple devices — and is genuinely awkward to use from a Windows PC or Android phone that isn't signed into the same Apple account. The "passkeys are portable" pitch is true within one vendor's ecosystem and much shakier across them.
- Recovery is still the weak link. Lose the device holding your only copy of a passkey, and many sites fall back to... a password, an SMS code, or an email link — often weaker than the passkey you were trying to avoid needing in the first place.
- Adoption is partial. Plenty of sites don't support passkeys at all yet, so you're managing a mix of passkeys and passwords for the foreseeable future, not a clean replacement.
- "Which passkey did I use for this site, again?" is a real, mundane problem once you have more than a handful, especially if they're scattered across an OS keychain, a couple of apps, and a browser.
Where a password manager fits in
This is really an argument for keeping passkeys somewhere that isn't tied to a single OS vendor's account system — the same place you already keep your passwords. A password manager that can also act as a WebAuthn authenticator gives you a few concrete things the platform-native flow doesn't:
- Passkeys sync alongside your passwords and 2FA codes in one place, not siloed in a separate OS-level keychain.
- They're portable across Chrome and Edge, and not locked to a single hardware vendor's ecosystem.
- You get one interface for "how do I sign into this site" regardless of whether that site happens to support passkeys yet.
How Spassword handles this
Spassword can act as a software WebAuthn authenticator on sites that support passkeys — creating and using them the same way a hardware key or your OS's built-in authenticator would, with the private key encrypted and synced alongside the rest of your vault. Every creation or sign-in shows an on-page confirmation you have to approve first; nothing happens silently in the background.
To be upfront about where this currently falls short: it's a software-only authenticator, not an OS-level platform authenticator, and it doesn't yet support conditional UI (the autofill-style suggestion dropdown some sites show for passkeys). A very small number of sites that do strict attestation allow-listing may not accept it. We'd rather list that plainly than have you discover it mid-signup.
Passwords and passkeys, in the same encrypted vault
Free Chrome & Edge extension, zero-knowledge by design.
See how passkeys work in Spassword