Passkeys, Plainly —
The Password's Replacement, Explained
Last verified: August 2026
Websites keep offering to let you sign in with your face or fingerprint instead of a password — and half my customers assume it's a trick. It isn't. It's the first genuinely good idea the sign-in world has had in decades. Here's what a passkey is, how to make your first one, and why scammers hate them.
The password is being retired — slowly, and for good reason
Passwords have one fatal flaw no cleverness fixes: the website keeps a copy. When crooks break into a company's computers — and they do, constantly — millions of passwords walk out the door at once, yours included, no matter how careful you were. That's why you get those "your information may have been involved in a data breach" letters. The industry spent twenty years patching the password, and finally decided to replace it instead.
The replacement is the passkey: a digital key that lives on your device and unlocks with the same fingerprint, face, or PIN you already use to wake the phone. Nothing to remember, nothing to type — and nothing stored on the website for crooks to steal. Apple, Google, and Microsoft built it into phones and computers starting in 2022; since May 2025, new Microsoft accounts start life with a passkey and no password at all. The choice is coming to you either way — usually as a pop-up at the worst possible moment. I'd rather you meet it calmly, at the kitchen table, with coffee.
A key and a lock — that's the whole idea
When you create a passkey for, say, your Google account, your device makes a matched pair: a key, which stays on your device and never leaves, and a lock, which is handed to Google. Signing in is just your device showing the lock that it holds the matching key. Before it does, it checks that the person holding the phone is you — with the fingerprint, face, or PIN that already unlocks the phone. That check happens on your device and nowhere else. Your fingerprint is never sent to Google, Amazon, or anyone. It never leaves your phone. Full stop. And if you'd rather not use your face or finger at all, the PIN does everything the face does.
What crooks can't do to a passkey
- They can't steal it in a data breach. The website only holds a lock, and a lock opens nothing. A breach at the website can't leak a passkey, because the website never had it.
- They can't phish it. A passkey checks the site's true identity — something no human eye can do — and flatly refuses to work on a look-alike fake. Even on your worst, most tired day, a passkey cannot be handed to a fake website.
- They can't guess it. A passkey isn't a word; it's hundreds of digits of randomness your device made up. No number of tries helps.
- And a passkey is an addition, not a swap — your passwords keep working right alongside. Don't delete anything; the old password stays as the spare key for the sites that don't take passkeys yet.
What signing in actually feels like
- On your phone: tap Sign in, a panel slides up asking "Use your passkey for this site?", you look at the phone or touch the sensor — and you're in. Ten seconds, no typing, no waiting for a texted code.
- On a Windows computer: a small "Making sure it's you" box asks for your Windows Hello PIN, fingerprint, or face. On a Mac, it's Touch ID or your Mac password.
- On someone else's computer — the library, a grandchild's laptop — the screen shows a QR code. Point your phone's camera at it, approve with your fingerprint or face, and the computer signs in. Nothing about you stays on that computer afterward.
- Passkeys quietly replace most of those "enter the 6-digit code we just sent you" hoops. Fewer steps and safer — a rare combination in this business.
Your first passkey: the Google account, step by step
- Email is the best first passkey — it can reset nearly everything else. In your browser, go to myaccount.google.com and sign in.
- Tap Security, then under "How you sign in to Google," tap Passkeys and security keys.
- Tap the blue Create a passkey button, then approve with your fingerprint, face, or PIN when the panel slides up.
- Look for the confirmation — "Passkey created" — listed with today's date. (Google sometimes creates one automatically on newer phones, so one may already be sitting there. Lovely — you were protected before you finished your coffee.)
- Prove it worked: sign out, then sign back in with the passkey. Outlook or Hotmail folks: same idea at account.microsoft.com under Security — and if Microsoft offers to delete your password afterward, my advice for most folks is not yet.
"But what if I lose my phone?"
- The right first question — and the calm answer is that your passkeys aren't trapped in the phone. They're backed up, encrypted, through your Apple or Google account. The phone is just the wallet; the account is the vault.
- New phone, same brand: sign in to your Apple or Google account during setup and your passkeys arrive with your photos and contacts. Nothing to redo.
- The lost phone itself is useless to whoever found it — your passkeys sit behind the phone's own screen lock. Meanwhile you're not locked out: other devices still work, and the old password still works too. A lost phone is an errand, not an emergency.
- Two locks guard everything: your phone's screen lock (a 6-digit passcode, not "nothing") and your Apple or Google account password. Guard that account password like the master key it is.
- Mixed household — an iPhone plus a Windows PC, or family sharing accounts? A password manager (Bitwarden free, 1Password about $3/month) can hold passkeys too, and it's the one keeper that works on every brand at once.
The moments that feel wrong — and what they actually are
- "It suddenly wants my fingerprint!" — that's the passkey working. Your device is checking, privately, that the person holding it is you. Nothing is photographed for the website; nothing leaves the phone.
- "A big square barcode took over the screen!" — that's the QR code, the computer politely asking your phone to vouch for you. Didn't mean to be here? Cancel is always free; nothing happens without your fingerprint, face, or PIN.
- "It says my face didn't match!" — glasses, low light, a bandaged finger. The sensor shrugs and falls back to your PIN automatically. Not trouble, and nobody is alerted.
- "It's asking me to make a passkey and I never said anything!" — sites offer them on their own now. Legitimate — but you're allowed to say "Not now" forever.
- The rule that covers all four: machines prompting is normal. Strangers directing is not.
What scammers do about passkeys — and can't do
- A passkey has nothing to steal over the phone — no word to read aloud, no code to recite. So crooks go after you instead, by talking you around it.
- "Read me your passkey to verify it" — there is nothing to read. Anyone asking is a scammer, instantly, no further analysis needed.
- "Your passkey is corrupted — click here to fix it" — passkeys don't expire or corrupt. That link leads to a fake page fishing for your password, the old key they can still steal.
- "Let me remote into your computer to set it up" — passkey setup never needs remote access. That's the tech-support scam in a new coat.
- "Approve the prompt I just sent you" — a caller triggers a real sign-in on your account, then sweet-talks you into approving it. The prompt is real; the person is the fake. Never approve a sign-in you didn't start yourself.
What's in the 27-page PDF
- What a passkey is, in plain English — the key-and-lock idea, and why the fingerprint check never leaves your phone
- The three ways accounts actually get broken into, and what a passkey does to each one
- Why every big company is pushing passkeys now — the timeline from 2022 to today
- What signing in feels like, on your phone, your computer, and via the QR-code trick
- Making passkeys on iPhone, Android, and Windows — one recipe page for each, compared side by side
- Where passkeys live: iCloud Keychain, Google Password Manager, Windows Hello, and password managers
- Lost phones, new phones, and switching between iPhone and Android
- When you still need the old password — and how to keep it safely without burning the boats
- The "why does it want my face?!" moments, taken seriously and taken apart
- Step-by-step first passkeys on your Google and Microsoft accounts
- The scam angle: the four scripts crooks use to talk you around a passkey, and the rules that beat them
- Kitchen-table questions, a plain-English glossary, and a by-the-computer cheat sheet
Why I wrote this
Passkeys arrived with terrible explanations. The companies say "cryptographic credential" when they mean "a key on your phone that can't be stolen in a data breach" — and so half the people I visit have been saying "Not now" to the safest sign-in they'll ever be offered, because nobody explained it plainly. I write these guides as printable handouts so the answer is by the computer when the strange screen appears, not buried in a website. And if you'd rather do it together — your top three accounts, the phone, the backups — that's one flat $99 visit anywhere in Portage County, 30-day follow-up included. — Bill
Want your first passkeys set up together?
One $99 flat visit: we'll set up passkeys on your email, Amazon, and bank, make sure the backups are in place, practice the sign-in until it's boring, and leave the cheat sheet by the computer. 30-day follow-up included — no jargon, no rushing, no upsell.
Would you rather I just do this for you?
No shame in it — plenty of folks would rather hand it off, and that's what I'm here for. I'll come to your home, set it up right, and make sure it's working before I leave. Flat $99 per visit — no jargon, no upsell, and every visit is 30-day come-back-free.
Not a hardware job? I can often fix it remotely for $49 — a secure screen-share, up to 2 hours, that you watch the whole time and can end whenever (included free for $39/mo Support Plan members, and it counts toward the $99 if it turns out I need to come out).