September 18, 2026

Passkeys Are Not Ready

Google calls it "Skip password when possible." Microsoft says "go passwordless." The tech industry has decided passkeys are the future, and they will remind you every single time you log in until you comply.

The cryptography is sound. Passkeys are bound to the site they are created for, so they cannot be phished by a fake login screen. If a server breach happens, the asymmetric keys cannot be recovered from stored data. For a corporate environment where IT controls the devices and the recovery paths, this is genuinely better.

For individuals, the tradeoff is worse.

The real risks for most people are not man-in-the-middle phishing proxies. They are permanent account lockout, automated account bans, and device loss. Passkeys trade a rare attack vector for a higher probability scenario: losing access to your own accounts entirely.

Consider the recovery problem. An account's security is dictated by its weakest recovery method: SMS, email links, security questions. Passkeys do not eliminate these. They add a stronger front door while the back door stays the same. If recovery methods are not enabled, the risk of permanent lockout is real.

Hardware keys get expensive fast

You cannot back up a passkey. By design, passkeys on a hardware key can be added or deleted but never moved. You need 2 to 3 hardware keys, enrolled for every site, and top-of-the-line keys max out at around 300 accounts. Once you exceed the limit, you buy another key or start deleting accounts. This does not scale.

Synced passkeys anchor you to one platform

Apple and Google want your identity locked to their operating systems. Synced passkeys tie everything to your Apple or Google account. If their automated systems ban you, you irreversibly lose access to all your passkeys across all third-party accounts too. FIDO is working on interoperability, but the export experience is still fragmented and inconsistent across providers.

Third-party managers fight the platform

Storing passkeys in Bitwarden or KeePassXC means fighting the operating system. Android's Credential Manager and similar APIs exist, but the UX lacks the decades of polish password autofill has. Native app autofill remains inconsistent. This will improve, but it is not there yet.

What actually works today

A combination of randomly generated passwords in a third-party password manager, paired with an independent TOTP app, gives users control without sacrificing flexibility. For people who reused passwords across sites, passkeys are a big upgrade. For everyone else using a password manager already, switching to passkeys today is a step backwards in practical resilience.

The ecosystem needs a few more years. Until then, I will keep my passwords and my TOTP codes, and I will keep dismissing the "Skip password when possible" prompt.

Sources

[1] Original article: hawksley.dev

[2] Google "Skip password when possible": support.google.com

[3] Microsoft passwordless: support.microsoft.com

[4] YubiKey account limits: support.yubico.com

← All posts