Passkeys beat passwords on security, but they only protect you when you secure the place that holds them. This guide shows you how passkeys work, where attackers still get through, and what to set up today.

Are Passkeys Safer Than Passwords?
A passkey removes the shared secret that phishers and data thieves rely on.
When you create a passkey, your device generates two linked keys. The website keeps the public key. Your device keeps the private key and never sends it anywhere. To sign in, your device proves it holds the private key after you approve with a fingerprint, face scan, or PIN.
This design blocks three common attacks:
- Phishing: A passkey only works on the exact site that created it, so a fake lookalike page gets nothing usable.
- Data breaches: A hacked server exposes only public keys, which attackers cannot use to log in.
- Password reuse: Each passkey is unique to one site, so one leak cannot unlock your other accounts.
The technology comes from the FIDO Alliance, and Google, Apple, and Microsoft all support it. FIDO figures tied to World Passkey Day in May 2026 put the number of active passkeys at about five billion worldwide.
Where Are Passkeys Stored? Synced vs Device-Bound
Those protections only hold while the private key stays safe, and that depends on whether the passkey syncs through the cloud or stays on one device.
- Synced passkeys: Phones, password managers, and browser accounts such as Chrome with a Google account or Edge with a Microsoft account store passkeys in the cloud. They follow you to every signed-in device.
- Device-bound passkeys: A Windows PC protected by Windows Hello or a hardware key such as a YubiKey or Google Titan Security Key holds the passkey locally. It never syncs.
Synced passkeys give you convenience. Device-bound passkeys give you a smaller attack surface, because no cloud account exists for an attacker to break into.
How to Secure Cloud-Synced Passkeys
Whoever controls the account that holds your synced passkeys controls the passkeys themselves.
Take these steps:
- Give that account a strong, random, unique password.
- Turn on two-factor authentication for it.
- Consider an independent password manager instead of relying only on your browser account. PCWorld notes that Google’s synced passkeys become a target when someone is signed into Chrome, and researchers have already demonstrated a malware attack that hijacked Google-synced passkeys.
- Lock your phone and computer with a strong screen lock, since anyone who unlocks the device gains access to its passkeys.
How to Secure Device-Bound Passkeys on Windows and Security Keys
A local passkey is only as strong as the PIN or biometric that guards it.
- Windows PC: Set up Windows Hello and use a PIN of at least six to eight digits if you skip biometrics.
- Hardware security key: If you use one, set a PIN of at least six digits. Yubico recommends a six-digit minimum for all YubiKeys, and business editions require it.
- Brute force protection: A YubiKey wipes and resets after eight failed PIN attempts, so guessing your PIN repeatedly does not work.
Can Malware Bypass Passkeys? The Session Cookie Risk
Locking down storage protects the passkey itself, but a passkey only secures the login moment, and malware can still steal the session that follows.
Security researcher Trevor Hilligoss of SpyCloud told PCMag that criminals can bypass a passkey entirely by stealing a validated browser cookie with malware. The website sees a valid session and never asks for a login. Two habits reduce this risk:
- Choose the shortest session duration when a site offers the option in its cookie or user data settings.
- Keep your devices free of malware with system updates and a trusted security tool.
How to Back Up Passkeys So You Never Get Locked Out
Attackers are not the only risk. A lost device with no backup can lock you out, and nobody can reset a passkey the way a support team resets a password.
Use this checklist:
- Cloud passkeys: Create a second passkey for the same account on your PC or on a hardware security key. Keys start around $30 to $35, and some retailers such as Best Buy sell YubiKeys.
- Spare device: Keep an old phone that still receives security updates and stays signed in to the account that holds your synced passkeys.
- Device-bound passkeys: Register the passkey on at least two hardware keys, or on one PC and one key. More copies give you more safety.
- Emergency access: Consider giving a trusted contact one backup key.
- Fallback login: Keep the old password or another recovery method active until you confirm the passkey works on two devices.
Why Weak Account Recovery Undermines Passkeys
Backups cover a lost device, but attackers also go after recovery flows because the passkey itself is hard to break.
If a service lets anyone reset access with only an email link or a text code, an attacker can skip your passkey completely. Review the recovery options on your email, banking, and password manager accounts. Replace weak methods with stronger ones, such as a backup passkey or hardware key, wherever the service allows it, and secure the email account tied to recovery first.
Which Accounts Should You Switch to Passkeys First?
Start with the accounts that unlock everything else, beginning with email, since most recovery resets route through it.
- Your primary email account
- Your password manager
- Banking and payment accounts
- Work and developer accounts
Keep a password manager for every service that does not support passkeys yet, since coverage remains uneven across banks, healthcare portals, and government sites.
Frequently Asked Questions
Are passkeys safe if I lose my phone?
Yes, if you use a synced passkey. Your passkeys restore on a new device after you sign back in to the cloud account that stored them. Device-bound passkeys on a single hardware key do not restore, so keep a backup key.
Can hackers steal my passkey?
Hackers cannot guess or phish a passkey the way they can a password, and a breached website exposes only a public key. The realistic risks are someone unlocking your device, an attacker breaking into the cloud account that syncs your passkeys, or malware stealing your session cookie.
Is a passkey the same as two-factor authentication?
No. Two-factor authentication adds a second check on top of a password. A passkey replaces the password and already combines your device with a fingerprint, face scan, or PIN.
Should I use a hardware key or a synced passkey?
Most people do well with synced passkeys in a secured password manager plus one hardware key as backup. People at higher risk, such as journalists and executives, often prefer device-bound hardware keys because no cloud account can expose them.
Do I still need a password manager?
Yes, for now. Many services still lack passkey support, and a password manager stores those passwords. Several managers, including NordPass and Proton Pass, also store and generate passkeys.
What PIN length should I use on a security key?
Use at least six digits. A longer PIN adds more protection, and the key’s reset after eight failed attempts blocks brute force guessing.