For decades, the password has stood as the primary gatekeeper between human identity and digital life — imperfect, forgettable, and endlessly exploited. Now, a quieter architecture is emerging: passkeys, which bind authentication to the body and the device rather than to memory, are spreading across the web's most-visited destinations. The shift is not yet complete, and the path is uneven, but the underlying logic is sound — a lock that cannot be copied, tricked, or guessed represents a fundamentally different relationship between people and the systems that ask them to prove who they are.
Passkeys Emerge as Password Alternative, But Adoption Remains Uneven
When the primary factor's un-phishable, other factors aren't necessary.
Why does it matter that passkeys are biometric instead of typed? Couldn't a password manager already remember your passwords for you?
A password manager is better than memorizing, sure, but it's still storing a secret string of characters. If that string gets exposed in a breach, or if you're tricked into typing it on a fake website, it's compromised. A passkey is cryptographically bound to the specific website it was created for. There's nothing to steal and nothing to type into the wrong place.
So the real advantage is that you can't be phished?
That's the core of it. Phishing works because humans can be fooled into entering their password on a fake login page. A passkey doesn't care what page you're on—it only works with the real service. The attacker has nothing to steal.
But you mentioned the setup is confusing. If it's so much better, why isn't everyone using it?
Because we're still in the early phase. The technology is sound, but different companies have implemented it differently. Some make it simple. Others have unclear prompts or compatibility issues. And there's a psychological barrier—people are used to passwords. The idea of going passwordless feels risky even though it's actually safer.
What happens if someone steals your phone?
If your passkeys are stored in a cloud-based password manager, they're not really on the phone—they're in the cloud, protected by your password manager's security. You can log in from another device and access them. If you're using a physical security key, it's different. The key itself is the only copy. That's why experts recommend keeping a backup hardware key.
So the real bottleneck right now is just that companies haven't all adopted it yet?
That, and the user experience needs to be more consistent. Once twenty percent of the top hundred websites support it, and the setup is as easy as it is on Google or LinkedIn, adoption will accelerate. But we're not there yet.
El Pulso
- Passwords have long been the weakest link in digital security, and phishing attacks, data breaches, and brute-force exploits have made that vulnerability impossible to ignore.
- Passkeys — using biometrics and encrypted code pairs tied to specific websites — eliminate the very mechanisms that make those attacks possible, offering a structural fix rather than a behavioral one.
- Adoption is accelerating but uneven: roughly one in five of the world's top hundred websites now support passkeys, yet setup experiences range from seamless to genuinely confusing, and major holdouts like Facebook and Netflix have yet to join.
- Real-world friction persists — passkeys that fail on certain browsers, redundant verification steps that undercut the technology's promise, and recovery complications when devices are lost.
- Experts advise a measured transition: start with the most critical accounts, maintain passwords as a fallback, and keep multi-factor authentication active while the ecosystem matures.
For decades, the password has stood as the primary gatekeeper between human identity and digital life — imperfect, forgettable, and endlessly exploited. Now, a quieter architecture is emerging: passkeys, which bind authentication to the body and the device rather than to memory, are spreading across the web's most-visited destinations. The shift is not yet complete, and the path is uneven, but the underlying logic is sound — a lock that cannot be copied, tricked, or guessed represents a fundamentally different relationship between people and the systems that ask them to prove who they are.
There's a small but meaningful prompt appearing on websites many people visit every day — an invitation to sign in with a fingerprint or a face instead of a password. It's easy to dismiss, but it signals a genuine shift in how digital identity is being renegotiated.
Passkeys work by splitting authentication into two encrypted halves: one stored with the user, either in a cloud-based password manager or on a physical security key, and one held by the service being accessed. The two halves only function together, and a passkey is bound to the specific site it was created for — meaning phishing pages and brute-force attacks lose their leverage entirely. There is no password to steal, guess, or replicate.
The technology gained real momentum about eighteen months ago when Google began accepting passkeys, building on Apple's earlier iOS rollout. Today, PayPal, Amazon, Microsoft, LinkedIn, and WhatsApp are among the major platforms on board. The FIDO Alliance, the industry group behind the standard, considers broader adoption a matter of when, not whether.
But the experience of actually setting passkeys up varies considerably. Some services make it straightforward; others present confusing prompts or unexpected failures. Cross-device setups — combining cloud-based and hardware key methods — can produce authentication errors and unclear guidance. Even after setup, inconsistencies remain: passkeys that don't function on certain browsers, or services that still request additional verification steps despite the technology's built-in protections.
Losing a device changes the calculus depending on storage method. Cloud-based passkeys can be recovered through a password manager; physical keys cannot be restored without a backup. Redundancy — keeping multiple methods — is the practical answer.
Experts suggest starting with the most important accounts rather than converting everything at once. The setup experience is still maturing, and keeping passwords with multi-factor authentication active remains sensible in the interim. The password won't disappear overnight, but the architecture replacing it — one that works more like a physical key than a memorized secret — is already taking hold.
You've probably noticed the option appearing on websites you visit regularly: a button that says "Sign in with passkey" or "Use your fingerprint." It's a small thing, easy to skip past if you're in a hurry. But it represents something larger—a quiet shift in how we prove we are who we say we are online.
Passkeys are a new kind of digital lock. Instead of typing a fourteen-character password full of symbols and numbers you'll never remember, you use your face, your fingerprint, or a PIN you already know. The technology works by splitting authentication into two encrypted pieces—one half lives with you, stored either in a cloud-based password manager or on a physical security key. The other half stays with the service you're trying to access. When you log in, these two halves communicate directly with each other. Neither piece alone is useful; they only work together. It's a fundamentally different approach to the problem passwords have never quite solved.
The momentum started building about eighteen months ago when Google began accepting them. Apple had introduced passkeys to iOS in 2022, but Google's adoption gave the technology real traction. Now roughly one in five of the world's largest hundred websites support them. PayPal, Amazon, Microsoft, and eBay are on board. LinkedIn and WhatsApp have them too. Facebook and Netflix have not yet made the move, but according to Andrew Shikiar, the CEO of the FIDO Alliance—the industry group that developed the underlying technology—it's simply a matter of time.
The security advantage is real and specific. A passkey won't work on any website except the one it was created for, which means phishing scams lose their power. A criminal can't trick you into entering your details on a fake login page because the passkey itself is bound to the legitimate site. And because passkeys use cryptographic security, brute-force attacks—where someone tries thousands of passwords from previous data breaches—simply don't work. The attacker has no password to guess.
But adoption remains uneven, and the user experience varies wildly depending on which service you're setting up. Setting up a passkey on Google is straightforward: a few clicks, a prompt from your password manager, and you're done. Adding one to Microsoft requires more head-scratching over confusing prompts, though it's eventually manageable. LinkedIn and Amazon are easy. Then you try to add multiple passkeys across different devices—one on your password manager, another on a physical security key—and suddenly you're wrestling with authentication failures and unclear error messages. When one journalist tried to add a second passkey to her Google account on a Windows laptop using a Yubico physical key, the password manager authentication failed. She had to try again with her Google Authenticator app. It worked, but only after some frustration.
Logging in, once everything is set up, can be seamless—a click or two and you're in. But friction persists in unexpected places. PayPal's passkeys don't work on Firefox. Amazon asked for a one-time verification code from an authenticator app even though the whole point of passkeys is supposed to be eliminating the need for additional authentication steps. Shikiar explained that it depends on the individual service, and theoretically a passkey has enough built-in protection that other factors shouldn't be necessary. "When the primary factor's un-phishable, other factors aren't necessary," he said. But not every company has implemented it that way.
If you lose the device holding your passkey, the outcome depends on how you stored it. Cloud-based passkeys—the typical method on phones—can be recovered by logging back into your password manager from another device. Physical security keys, though, aren't synced to the cloud. Lose the key and the passkey is gone unless you've kept a backup hardware key. The solution is redundancy: use both cloud and hardware methods, or keep multiple keys.
Experts don't recommend converting all your accounts to passkeys immediately. The setup experience is too inconsistent, and the technology is still in early adoption. Better to start with your most important accounts—email, banking, social media—and get those right. As for your old passwords, you could delete them in theory. Some services like Microsoft already offer that option. But Shikiar says it should be a personal choice. Some people feel extremely nervous about going passwordless, and that's reasonable. If you keep your passwords, just make sure multi-factor authentication is turned on. The transition to passkeys won't happen overnight. But as more services implement them and the setup experience smooths out, the friction will fade. The password, after decades of dominance, is slowly being replaced by something that works more like a key—something you don't memorize, something you can't lose in a phishing attack, something that only opens the door it was made for.
Citas Notables
It's just a matter of time for more and more sites to start offering this.— Andrew Shikiar, CEO of the FIDO Alliance
Some people may feel extremely nervous about going passwordless, and that should be a personal preference.— Andrew Shikiar, CEO of the FIDO Alliance