Skip to content
lesson Identity, passwords and access Intermediate 3 min read

Passwords vs passkeys: what’s the difference?

A password is a secret you share with a website. A passkey shares nothing. How the two compare, and how a business moves from one to the other.

A password is a secret that you know and type in. A passkey is a key that your device holds and uses for you, once you confirm with your fingerprint, face or PIN. Both prove who you are, and they fail in different ways.

The real difference

A password is shared. You know it, and the website keeps a scrambled copy to check against, so it can leak from either end. A passkey has two halves. The private half never leaves your device or password manager, and the website holds only a public half, which cannot be used to sign in.

  • Guessing. A password can be guessed. A passkey is made by the device and there is nothing to guess.
  • Reuse. One password often ends up on many accounts. Every passkey is unique to one account.
  • Fake sign-in pages. A password can be typed into a look-alike page. A passkey works only on the website it was created for.
  • A breach at the website. Stolen password records can be cracked. Stolen public keys are no use to the thief.
  • Extra steps. A password needs a second factor beside it. The Australian Signals Directorate (ASD) says a passkey provides multi-factor authentication by itself.

What passkeys do not fix

  • Not every service offers them yet.
  • Anyone who can get past the screen lock can use the passkeys on that device. Screen locks matter more, and shared computers are the wrong place for a passkey.
  • Adding a passkey usually leaves the old password and recovery methods on the account. Until they are removed or tightened, they are still a way in.
  • On a work account, the administrator decides whether staff may sign in with a passkey alone.

How to choose

There is rarely a real choice to make. Where a service offers passkeys, use them. Where it does not, ASD’s advice is a long, unique password for each account, kept in a password manager, with multi-factor authentication turned on. Most businesses will run both for some years.

Moving a business across

  1. List the accounts the business depends on and note which ones offer passkeys. Put email and administrator accounts at the top.
  2. Decide where passkeys will be kept. Passkeys synced by a password manager suit most staff. Passkeys held on a physical security key suit administrators.
  3. Check that every phone and computer has a screen lock and is up to date.
  4. Allow passkeys in the admin settings of Microsoft 365 or Google Workspace, then have each person register one.
  5. Give everyone a second way in, such as a passkey on another device or a spare security key, and test it.
  6. Once people are settled, remove the weakest sign-in methods, starting with codes sent by text message.
  7. Keep long, unique passwords, stored in a password manager, for everything that is left.

Sources

  1. Use passkeys: personal cyber security handbook (Australian Signals Directorate) cyber.gov.au
  2. Securing accounts and identities: small business cyber security handbook (Australian Signals Directorate) cyber.gov.au
  3. How passkeys work (FIDO Alliance, Passkey Central) passkeycentral.org
  4. SP 800-63B-4: Digital identity guidelines, authentication and authenticator management (NIST) pages.nist.gov
  5. Sign in with a passkey instead of a password (Google Account Help) support.google.com
  6. Authentication methods in Microsoft Entra ID: passkeys (FIDO2) (Microsoft Learn) learn.microsoft.com
  7. Implementing phishing-resistant MFA (CISA) cisa.gov

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.