With a passkey, the private key remains with the authenticator while the service stores a public key. The signature is bound to the legitimate origin, resisting conventional phishing.
Security also depends on synchronisation, device protection, recovery and fallback. A weak alternative sign-in can completely bypass the passkey's strength.
Three verification questions
- 01Is sign-in bound to the correct origin?
- 02How do recovery and fallback work?
- 03Can individual passkeys be revoked?
