top of page

PASSKEYS: The Password Is Ending, and You Will Not Miss It

  • Aug 20
  • 5 min read

You clicked "Not now" at least four times.


Apple asked. Google asked. Your bank asked. Somewhere in the past few months a screen offered to let you sign in without a password, and you declined, because the day was busy and the offer arrived without an explanation attached.


Today's post is the explanation.


The reassuring part comes first. Nothing in this post is a task for you. Passwordless sign-in rests on three foundations: a managed identity platform, a governed credential vault, and recovery procedures that somebody tested. Those foundations are our specialty, and we work through them with each client at the pace our clients set.


What follows is a look at what comes next, and at why this is one of the rare technology changes that makes life easier and safer at the same time.


WHAT A PASSKEY IS

Here it is in plain English.


When you create a passkey, your device generates two mathematically linked keys.


  • One key stays on the device, and your fingerprint, your face, or your PIN protects it. That key never leaves.


  • The other key goes to the website. When you sign in, the website sends a challenge, your device answers with the key it holds, and the door opens.


No secret crosses the internet. There is no string of characters for anyone to steal, guess, reuse, or talk you out of.


That last point carries the most weight. Criminals phish passwords every day. They build a convincing copy of a bank login page, a visitor types credentials into it, and the theft is complete before anyone notices. A passkey refuses to play along. Your device ties the passkey to the genuine web address. Show it a counterfeit and it does nothing at all. No warning. No near miss. Nothing.


THE SCALE OF THE SHIFT

The numbers run larger than most executives expect, so here they are.


The FIDO Alliance, the standards body behind the technology, estimates five billion passkeys in active use worldwide. Ninety percent of people now recognize the term. Three quarters have enabled at least one. Sixty-eight percent of organizations have deployed passkeys for employee sign-in or are deploying them now.


One more figure, and it is the interesting one. Passkey logins succeed roughly 93 percent of the time. Passwords manage roughly 63 percent. The safer method is also the method that works more often. That combination almost never occurs in this field.


WHY THE INDUSTRY MOVED

Firms without a managed identity program (a password manager like Bitwarden, Dashlane, 1Password and Keeper) sit in an uncomfortable position this year. Stolen and reused credentials are still the most common way an intruder walks through the front door of a professional firm. Not brilliant code. Not an exotic vulnerability. A password that an employee also used somewhere else, which a criminal collected in a breach that the employee never heard about, and then tried patiently against a business email account at two in the morning.


Multi-factor authentication helped enormously, and it still helps. It also attracted attention. Attackers now run live phishing sites that relay a one-time code the instant a victim types it, and they run fatigue campaigns that push approval prompts to a phone until somebody taps yes to stop the buzzing.


Passkeys shut both doors. No code exists to relay. No prompt arrives to approve in exhaustion.


"WHAT HAPPENS IF I LOSE MY PHONE?"

Start with what a passkey is not. It is not a single key that lived only inside the phone you left in the taxi.


Your passkeys live in a vault, which is simply a secure application that holds your credentials and keeps an encrypted copy on every device you own. The passkey sits in the vault. The phone was one way to reach it, not the only one. Lose the phone and the passkey stays where it was, the way a file stays in your office after you go home.


The person who finds the phone gets nothing either. A passkey refuses to work without your face, your fingerprint, or your PIN, and none of those left with the taxi.


So, the practical answer is dull, which is rather the point. You sign in from your laptop. You call us. We cut the missing device off, enroll the new one while you are on the line, and your afternoon continues. Every deployment carries written recovery steps, and we walk through them before we call the work finished, because a recovery plan nobody has tested is a theory rather than a plan.


"DOES OUR WHOLE FIRM SWITCH TO PASSKEYS ALL AT ONCE?"

No. That would be a poor idea and we don’t propose it.


We add passkeys to a few accounts for a few people, and we start with the accounts that matter most: email, banking and finance, and the logins your administrators use. Once that first group is comfortable, we move to the next.


Your password still works the whole time. Nothing gets switched off behind you. If a passkey gives someone trouble on a Wednesday morning, they sign in the old way and calls us.


HOW WE HANDLE IT

In March, Bitwarden and Microsoft extended passkeys to the Windows sign-in screen itself, so a passkey held in a managed vault can now unlock the machine and not merely the websites running on it. We follow that work closely, because Microsoft 365 sits at the center of the environments we operate.


We enforce phishing-resistant sign-in on the accounts that carry the most risk. We document the recovery path for every account we enroll. We stage the work so it lands quietly, which is the only way a change of this kind should ever land.


ONE HONEST NOTE BEFORE THE ENTHUSIASM RUNS AWAY WITH ITSELF

Passkeys land smoothly on a governed credential vault and awkwardly without one, which means the vault is the real question for most firms rather than the passkey. Next week's post takes that up properly.


In the meantime, if you are not certain where your firm keeps its credentials today, tell us. We will look, and we will tell you what your own path to passwordless involves. That conversation takes about ten minutes and costs you nothing at all.


And when a question arrives at an inconvenient hour, a person answers it. Roark supports clients in 21 metropolitan areas across seven countries and four continents. Seventeen time zones separate Tokyo from San Francisco.


WHAT THIS MEANS FOR YOUR FIRM

The password is not disappearing because the industry grew tired of it. It is disappearing because something better finally arrived and every major platform agreed on it within the same few years. Agreement of that kind is rare, and the organizations that use it well collect years of quiet benefit.


Firms that make this transition deliberately will spend the coming years signing in faster, resetting less, and removing the single most dependable technique a criminal has. Firms that wait will make the same change later, under pressure, in the days after an incident, which is the most expensive hour anyone could choose for learning something new.


You belong to the first group. You chose that some time ago, and we have been building on the decision ever since.


So, the next time a screen offers you a passkey, accept it. Then tell us, and we will make sure the same option waits for you everywhere else it belongs.


If you know someone whose firm still runs on passwords, a spreadsheet, and good intentions, forward this to them. They will get more out of it than you did.

Independently owned since 1998, with no outside investors and no debt, Roark Tech Services delivers White Glove technology and security services to demanding organizations across multiple time zones.


bottom of page