§ TECH · 2 MIN READ

The Password Is On Its Way Out

The thing replacing it cannot be phished, cannot be reused, and cannot be leaked in a breach, because there is nothing on the server worth stealing.

By Culture

September 14, 2026

The Password Is On Its Way Out

THE SHORT VERSION

A passkey is a login credential stored on your device and unlocked with your face, fingerprint or device PIN, which replaces a typed password. Because the secret half never leaves your device and the site stores only a public half, a passkey cannot be phished, reused across sites, or stolen in a server breach, and it syncs across your devices through your platform account.

A passkey cannot be typed into a fake site, which removes phishing as a category rather than reducing it.
Nothing stealable is stored on the site's server, so a breach there does not expose your login.
Passkeys sync through your Apple, Google or Microsoft account, so a lost phone is not a lost account.
Turn them on where the money is first: bank, email, and the account that resets everything else.

Passwords fail for one structural reason. The secret has to travel. You type it, it goes over the wire, it sits on a server, and every one of those steps is a place it can be taken.

Everything built on top of passwords is an attempt to patch that: complexity rules, rotation, password managers, codes texted to your phone. All of it is compensation for the original design.

Passkeys change the design.

HOW IT ACTUALLY WORKS

When you create a passkey, your device generates two mathematically linked halves. The private half never leaves your device. The public half goes to the site.

To log in, the site sends a challenge. Your device signs it with the private half, after checking it is you by face, fingerprint or PIN. The site verifies the signature with the public half.

The secret never travels. That is the whole thing, and it has three consequences.

Phishing stops working. A fake site can ask you to type a password and you might. It cannot ask your device for a signature, because your device checks which site is asking and will not sign for the wrong one. This is not you being careful. This is the protocol refusing.

Breaches stop mattering for login. The site holds only public halves, which are worthless alone. A stolen database of them is a stolen list of padlocks with no keys.

Reuse stops existing. Every site gets its own pair, automatically. The single most common cause of account takeover, one password used in five places, simply cannot occur.

THE QUESTION EVERYONE ASKS

What happens if you lose the phone.

Passkeys sync, encrypted, through your Apple account, Google account or password manager. New phone, sign in, the passkeys come back. It behaves like your photos.

This is also the honest limitation: your platform account becomes the master key. Protect that one seriously, with a strong unique password and a recovery method you control, because everything else now hangs from it.

WHERE TO TURN THEM ON FIRST

Order matters. Do these:

Your email. Not because the email is precious, but because it is the reset address for every other account you own. Whoever holds the email holds everything.

Your bank and anything holding money.

The platform account itself, Apple or Google or Microsoft, which now guards the rest.

Everything else can happen whenever you next log in and the site offers.

WHAT NOT TO DO

Do not delete your passwords yet. Most sites keep the password as a fallback, so it still exists whether you remember it or not. Leave it in a password manager, long and random, and stop typing it.

And do not treat a code sent by text as equivalent. Text codes can be intercepted and, far more commonly, talked out of you by somebody on the phone. A passkey cannot be talked out of you.

“A password is something you can be tricked into giving away. A passkey is not.”
THE REST OF THE SURFACE

The login is one door. The profile that strangers buy about you is another, and it is what makes a scam call sound legitimate.

Tell the people who will actually be targeted, too. The call goes to your grandmother, not to you.

§ QUESTIONS PEOPLE ASK
What is a passkey?
A login credential stored on your device and unlocked with your face, fingerprint or PIN. Your device keeps a private half that never leaves it and the site stores only a public half, so there is nothing stealable on the server.
What happens to my passkeys if I lose my phone?
They sync in encrypted form through your Apple, Google or Microsoft account or your password manager. Signing in on a new device restores them, which is why that platform account now needs the strongest protection you have.
Are passkeys better than a code sent by text?
Yes. A text code can be intercepted or talked out of you over the phone. A passkey requires a signature from your device, which checks which site is asking and refuses to sign for an impostor.
§ TAKE IT FURTHER