Ok, who’s still a bit confused about passkeys? 
Written by @samraven

Ok, who’s still a bit confused about passkeys? 

You hear they’re safer than passwords, but why? Will adopting one cause problems logging in? Are they a right hassle? And if you start using passkeys, can you then turn off 2FA? All these questions and more will be answered in this informative little article. Grab a cuppa and sit your pass down. This is how it works.  

Meet The Keys 

When a passkey is created, a public-private key pair is generated.  

If your encryption subscription has lapsed, a ‘public-private key pair’ is a concept rooted in asymmetric encryption. When a key pair is generated, they are, unlike most of us, literally (and mathematically) designed to be together. Meet The Keys: Mrs. Public and Mr. Private. They’re the right pair.  

The public part of the key pair, Mrs Public, has one job: to encrypt data. Anyone can have access to this key (the clues in the name) which only encrypts but can’t unlock anything at all. A public key is like the post-box on your front door. You can post it into it, but you can’t take anything out.  

The introvert of the relationship is Mr. Private Key. Also generated during the generation of the public-private key pair, he prefers to stay home, get takeaway and binge-watch TV shows. When needed, he decrypts the data his partner Mrs. Public locked up. Unlike the public key, he’s never shared with others – for only he can unlock her post-box.  

The reason that this special pair of keys are more secure than a password is that even if someone intercepts Mrs. Public Key, without Mr. Private, no one can decrypt a thing! 

When a public-private key pair is created, the public key is copied to the website’s servers and the private lives on your smartphone (or trusted device), in your password manager/vault (i.e. 1Password). This means unlike a password; you never have to worry about forgetting it.   

Passkey Problems? 

Using a passkey shouldn’t cause any problems logging in. It should simplify the whole process. Even when you’re trying to sign into a passkey-protected account using a device without access to your password manager, you can sign in from a device that does have your passkey, i.e. your smartphone.  

Should you turn off 2FA when using passkeys? Probably. With that said, it depends on your risk tolerance. If you’re comfortable using two-factor authentication on top of a passkey, then keep it up, but for most intents and purposes, using a passkey alone is secure enough.  

Ease in Keys  

Let’s break the process down with a real-world example.  

You visit a website selling let’s say doughnuts, and they have an option when creating your account to secure it, with passkeys. With the thoughts of jam-filled, custard-coated munchies goading you on, you dive in. And by ‘dive in’ I mean you blankly click on ‘secure with passkey’.  

Behind the scenes, donuts.com is incredibly busy. Its server is sharing information about the website with your device. It’ll then prompt you to confirm the hardware that your private key will be stored on. This is known as ‘The Authenticator’, who I imagine looks a bit like The Terminator if he wasn’t a cyborg and instead worked in a library and wore a pullover his gran knitted for Christmas in the early 1970s. The Authenticator could be your phone, tablet, PC or if you want to go full-on risk-geek, a hardware security key.  

Then the magic happens.  

A new passkey pair has been created! What makes this step even more special is that the pair of generated keys are created for a specific website or application. In other words, they’re a one-off. The key generation happens on your device, locally. But the public part of the key meanwhile, is immediately climbing aboard her private jet, sipping an iced Bloody Mary, and cruising to the destination server, for storage. The private key stays chilling on your device, or authenticator. And all this magic happens in the blink of an eye.  

Key-p It Simple 

From your side, you simply choose your authenticator and then see confirmation your account has been successfully created. With no password to memorise or save, you are free to order as many doughnuts as you desire. Which for me personally, is always a bank-busting, insulin-spiking, near-fatal amount.  

Next time you sign in for more, i.e. later that afternoon, you don’t have to enter a password. Oh no. That’s all in the past. Like your stupid diet. All you need now do is authenticate with biometrics (Face or TouchID, Windows Hello, etc.) and you will automatically have access to your account. NB. Face ID might not work if you’re coated in sugar/jam.  

Your Authenticator just needs to check if it’s you before giving up the private key– so it can authenticate your identity with the copy of your public key, on the website’s server. If biometrics aren’t available on your device, the system will simply request the PIN or password you normally use to unlock your device.  

Lowering Risk 

The beauty of all this is even if an adversary did manage to exfiltrate Mrs Public Key from donuts.com, there would still be zero risk to your account without Mr Private Key (which remember, never leaves your device). This removes the worry from your end – donuts.com could be storing your public key, un-hashed and in clear text, printed on each doughnut - and it would not affect security one bit.  

Should you move over to passkeys? Consider this: you would never have to reset your password ever again.  

Also, passkeys are quick – once your device has authenticated you via biometrics (or pin) you’re in. No more typing in usernames and passwords.  

Passwords like that one you’ve been alternating, modifying and re-using, since you left university. That’s a huge security risk, best left in the back of your cupboard, along with your zany hat, stolen traffic cone and tie-dye.  

Just like those dodgy tie-dye garments, each generated passkey is unique - linked to a single specific application or website, further increasing security. Finally, passkeys are resistant to phishing attempts: as the private key never leaves your device, and you can’t be manipulated into sharing it or entering it into a dummy website. What’s not to love? 

To passkey or not to passkey? That’s not even a question. Get your pass in gear, key-p it real and join the revolution. Make passwords a thing of the past.

Now, where did I leave that doughnut? 

To view or add a comment, sign in

More articles by Risk Crew

Others also viewed

Explore content categories