Most online accounts rely on a username and password for protection, but recently, vulnerabilities in login credentials have become a serious concern. Users’ personal information is being compromised and may end up on the dark web.
But what if there’s a more secure way to log in?
Well, there is—a solution you might not even be familiar with yet. Major tech companies have created a more secure option using passkeys, though many websites and apps are still hesitant to adopt this technology.
What is a passkey?
You may have heard of passkeys due to the buzz around the internet. Essentially, they are digital credentials that are linked directly to your user account. Unlike traditional passwords, a passkey doesn’t require you to remember complex combinations of letters, numbers, and symbols. Instead, it exists as encrypted lines of code on your device, allowing you to access your account when needed.
From a user’s standpoint, passkeys offer great convenience—they eliminate the need to memorize passwords. If you forget a password, there’s no need to go through a reset process. All you have to do is use biometric sensors, like facial or fingerprint recognition, or enter a lock screen PIN to verify your identity and log into supported applications and services.
For platform owners, passkeys enhance security compared to conventional login information, making unauthorized access significantly more difficult. Since passkeys are stored on the user’s device rather than in a password database, a hacker would need both physical access to your device and knowledge of your lock screen PIN to bypass the security.
However, there’s a slight downside. If you use multiple device platforms, you might find managing passkeys a bit cumbersome. For instance, passkeys stored in Apple’s system are tied to its ecosystem, while those in Google’s and Microsoft’s systems are confined to their respective platforms. Although Big Tech is likely working on a solution for cross-platform interoperability, currently, you’ll need to create separate passkeys for each platform and supported website.
Getting to know passkeys
Passkeys were introduced slowly across Apple, Google, and Microsoft platforms in 2022 and 2023. If you’re using any of these platforms, it might be worth focusing your efforts there. Each company has easy-to-follow guides for setting up a passkey for your accounts.
Despite this, by 2026, passkeys haven’t become as widespread as anticipated. Web developers still need to decide whether to implement them, and otherwise, users are reverted back to the familiar username and password dynamic. So, the change hasn’t entirely taken off yet.
Another resource worth checking out is a website that tracks the top 50 online sites, showing which ones do and don’t support passkeys. Entities like Google, Apple, and Microsoft offer this protection, but, surprisingly, platforms like Instagram, Netflix, and Spotify seem lagging. Currently, around 36% of the leading websites still don’t utilize passkeys, leaving many users in a bind. Why is that?
There are various reasons this might be happening. Transitioning from traditional credentials to a passkey system involves time and costs for development. Plus, the lack of coherence across different device platforms could create a headache for users—one that website owners may prefer to avoid. Lastly, some website owners might feel that conventional passwords are sufficiently secure and see no need to change things up. In other words, they might think that if it works, why fix it?
Should you use a passkey?
In short, yes! For any account that supports it, you should definitely opt for passkeys. The security benefits vastly surpass the inconveniences stemming from limited cross-platform support. With the rise in hacking incidents and breaches—like the recent issues faced by Dashlane—passkeys emerge as a straightforward and effective solution to protect your accounts in this evolving digital environment fraught with cybersecurity threats.





