Passkeys vs Passwords: What's Actually Different
Passkeys are showing up on more sign-in screens every month. Here's what they actually are, and whether they're worth switching to where offered.
How passkeys work
A passkey is a cryptographic key pair created on your device, tied to your account and unlocked with your existing device biometric or PIN (Face ID, fingerprint, screen lock). Instead of typing a shared secret that a server stores, the site only ever holds a public key that's useless to an attacker on its own โ the private key never leaves your device.
Why that matters
- Phishing-resistant: passkeys are tied to the specific website's domain, so a fake look-alike login page simply can't accept your passkey the way it could trick you into typing a password.
- Nothing to leak in a breach: since the private key never leaves your device, a server-side data breach can't expose a "password" the way traditional breaches have for decades.
- Nothing to remember: your device's existing lock (biometric or PIN) does the authentication instead of a memorised string.
Should you switch?
Where a site offers passkeys โ increasingly common for major platforms โ it's worth turning on; it's a genuine security upgrade with no real downside for most people. For everything else, a password manager generating and storing unique passwords per site, combined with two-factor authentication, remains the sensible baseline.
Shopping for security keys or new devices?
Compare live NZ prices on Twisti across JB Hi-Fi, Noel Leeming and PB Tech, plus an AI verdict on whether now's a good time to buy.
Compare prices now โ