Additional resource for the lesson “Passkeys: Signing In Without Passwords” — Online Security course
A passkey lets you sign in with the same gesture you use to unlock your phone or computer: your face, your fingerprint or your PIN. There is no password to remember and no code to copy. This resource explains what a passkey is, why it is harder to phish than anything you type, where it is safe to create one, and how to add your first one without losing your way back in: the recovery details that let you into your account when your usual sign-in does not work.
The key idea: with a passkey, the secret moves out of your memory and onto your devices. The site holds no secret worth stealing, and the lock on your device becomes what protects you.
A. Why this matters
Passwords have two weaknesses that no amount of care fully removes: they can be stolen from the sites that store them, and typed into a page that only looks genuine. A second factor helps a great deal, but a code can still be typed into the wrong page.
When you sign in with a passkey, both weaknesses largely go away. The site holds no secret worth stealing, and your device will only answer the site the passkey was made for.
What changes is where the protection sits. The secret no longer lives in your memory but on your devices, and the lock on each device becomes what guards it.
What the official guidance says
The UK’s National Cyber Security Centre (NCSC) recommends using passkeys wherever services offer them, and 2-step verification wherever they do not yet. Passkeys are still fairly new, and not every service offers one, so for now most people will use both.
The clearest practical guidance comes from the platforms that offer passkeys, Apple, Google and Microsoft, listed in section E. Two details from it matter for this resource. Google notes that a passkey cannot be used on a phone without a screen lock. Apple syncs passkeys through iCloud Keychain, which requires two-factor authentication. Both point the same way: with passkeys, the lock on your device and the account that syncs your passkeys are what keep them safe, and your way back in still needs looking after.
B. Key concepts
Six ideas about what a passkey is and what keeps it safe.
Passkey
A sign-in credential made of two matching digital keys, created by your device for one particular website or app. It is based on open standards from the FIDO Alliance, an industry association, so it works with most major systems and browsers.
Why it matters to you: You unlock it the way you unlock your device. There is nothing to invent, remember or reuse.
The public half and the private half
The public half is given to the site, and on its own it is useless. The private half stays with you, on your device or in your password manager, and the site never learns it. When you sign in, the site sends a challenge and your device answers it with the private half.
Why it matters to you: If the site is ever breached, there is no password there to steal and nothing that lets anyone sign in as you.
Bound to one site
Each passkey is tied to the address of the site that created it. The browser and the operating system make sure it can only be used there.
Why it matters to you: A convincing copy of the site gets nothing, because your device does not recognise it. This is what “phishing-resistant” means: the device checks the address for you.
Your screen lock
To use a passkey, you unlock your device with your face, fingerprint, PIN or pattern. The biometric never goes to the site; it only unlocks the device.
Why it matters to you: A passkey is as safe as the lock that opens it. A short or guessable passcode, or a device other people can unlock, weakens every passkey on it.
Synced and device-bound passkeys
Passkeys created on phones and computers are usually synced: backed up in encrypted form through your Apple, Google or password manager account, and restored when you set up a new device. Apple, for example, syncs them with iCloud Keychain, which requires two-factor authentication. Some passkeys never leave a single device, for example those stored on a physical security key.
Why it matters to you: A synced passkey survives a lost phone, provided you can still get into the account that syncs it. That account deserves your strongest protection.
The phone as a bridge
On a computer that does not hold your passkey, the sign-in page can show a QR code. You scan it with your phone, which checks that the two devices are close to each other (usually using Bluetooth), and you are signed in.
Why it matters to you: You can use a passkey on a new computer without creating another one there. Avoid creating passkeys on computers that are not yours.
C. A practical example: the laptop at a friend’s house
Grace is staying with a friend and needs to check her email on the friend’s laptop. When she signs in, the site offers to create a passkey, “so next time is quicker”. It is late, and she nearly clicks yes.
She stops, because she remembers what a passkey is guarded by: the lock on the device. On this laptop, that is her friend’s password, and anyone in the house who knows it could open her email without ever knowing her password.
What changed the outcome
- Grace chose “Not now” on the friend’s laptop and finished signing in with her password and second factor.
- She signed out before handing the laptop back.
- At home, she created the passkey on her own phone, which has a six-digit passcode only she knows.
- The next time she needed her email on another computer, she used the QR code and her phone instead.
Nothing went wrong. The difference was one question: whose lock would be guarding the key?
D. Try it yourself: your first passkey (20 minutes)
Four short steps, in this order. The first one decides how safe the rest is.
Step 1 — Check your screen lock
- On the phone or computer you will use, make sure a screen lock is on.
- On a phone, prefer a passcode of at least six digits that nobody could work out from details about you, such as a date of birth.
- If anyone else can unlock this device, choose another one.
Step 2 — Add a passkey to your main email
- Sign in to your main email account and open its security settings.
- Look for an option such as “Passkeys”, “Passkeys and security keys” or “Sign in without a password”. Not every service offers one yet.
- Follow the prompts and confirm with your face, fingerprint or PIN.
Step 3 — Sign in with it once
- Sign out of the account, then sign back in, choosing the passkey.
Step 4 — Check your way back in
- In the same security settings, confirm that your recovery email and phone number are current.
- If the service offers recovery codes, make sure you have saved a set somewhere you can reach without your phone.
- Keep your password in your password manager: many services keep it as another way in, and you may need it on a device where the passkey is not available.
Once this works on your email, repeat step 2 for the next account that matters to you, whenever it offers a passkey.
E. Videos, articles and further resources
Platform documentation first, then the standards body and the UK’s national guidance. All in English.
Platform documentation
Apple Support — About the security of passkeys
How the key pair works, how passkeys sync through iCloud Keychain, and how they can be recovered.
https://support.apple.com/en-us/102195
Google Account Help — Sign in with a passkey instead of a password
Which devices and browsers support passkeys, how to use your phone on another computer, and what to do if a device is lost.
https://support.google.com/accounts/answer/13548313?hl=en
Microsoft Support — Create and save a passkey
How to create a passkey for your Microsoft account with Windows Hello, with your phone through a QR code, or in a password manager.
https://support.microsoft.com/en-us/accounts-billing/security/create-save-passkey
Standards and national guidance
FIDO Alliance — Passkeys
What passkeys are, synced and device-bound passkeys, and signing in across devices, from the body that writes the standards.
https://fidoalliance.org/passkeys/
NCSC (UK) — Passkeys are more secure than traditional ways to log in
Why passkeys resist phishing, and why 2-step verification remains the choice wherever passkeys are not yet offered. Published April 2026.
https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in
Links checked in October 2026. If an address changes, searching for the title on the organisation’s site usually finds it.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Skills pillar at level FL2. It follows the lessons on second factors and introduces the sign-in method that makes phishing much harder.
Skills
- Creating a passkey on a service that offers one.
- Signing in with a passkey, including on another computer through the phone.
- Checking recovery options before relying on a new way of signing in.
Awareness
- Understanding that a site holds only the public half of a passkey, which is useless on its own.
- Knowing that a passkey is bound to one site, so a fake page gets nothing.
- Recognising that the screen lock and the syncing account now guard the secret.
Secure Behavior
- Creating passkeys only on devices you own and that only you can unlock.
- Always keeping a working way back in: recovery details, recovery codes and your password manager.
G. Questions to sit with
- If your main email offered you a passkey today, which device would you create it on? Who else can unlock that device?
- Which account syncs your passkeys, and how well is that account protected?
- If you lost your phone tomorrow, which way back in would you use to reach your email?
H. What to do now
The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply most directly here.
1. Guarding the lock
- R5 — Set a passcode of at least six digits on your phone. It now opens your passkeys as well as your phone.
- R7 — Keep the screen lock timeout short, so an unattended device locks itself.
- MS4 — Where you can, use an alphanumeric passcode of eight characters or more.
Minimum commitment: make sure the device that will hold your first passkey has a screen lock only you know.
2. Keeping a way back in
- R2 — Keep your passwords in a reliable password manager. You will still need them for every site that does not offer passkeys yet.
- R4 — Keep a second factor on your accounts, and save the recovery codes somewhere you can reach without your phone.
- R8 — Turn on login alerts, so you hear about it if someone tries to use your recovery options.
Minimum commitment: add one passkey to your main email, and check its recovery details the same day.
In short
- A passkey is a key pair. The site keeps only the public half, which is useless on its own; the private half stays with you.
- It is bound to one site, so a fake page gets nothing from it.
- It is as safe as the screen lock that opens it: create passkeys only on devices you own and that only you can unlock.
- Keep a way back in: recovery details, recovery codes and your password manager.
Related resources in this course
- Two-Factor Authentication Methods: Why They Are Not Equal
- Device Lock: The Barrier Everything Else Sits Behind
- Password Managers: Many Strong Passwords, One to Remember
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.








Leave a Reply