Passkeys, which major tech companies including Google and Microsoft actively promote as replacements for passwords, offer genuine security advantages but remain poorly suited for individual users, according to Hawksley, a developer who analyzed the technology’s current limitations.

Passkeys are cryptographically bound to the specific websites where they are created, making them resistant to phishing attacks and data breaches. Unlike passwords, they use asymmetric encryption and cannot be recovered from compromised servers. These properties make them ideal for corporate environments, but the calculus differs for personal security.
For individuals, the greatest risks are not phishing attacks but account lockout, automated bans, and device loss—scenarios where passkeys create vulnerability rather than protection. While passkeys eliminate phishing through standard login flows, account recovery still depends on secondary methods like SMS, email links, or security questions. If these aren’t properly configured, users face permanent account lockout with no recourse.
Hardware keys present additional friction. Passkeys stored on hardware keys cannot be backed up or moved; they can only be added or deleted. Users must purchase multiple keys and enroll each one for every site. Hardware keys also have storage limits—typically 25 to 100 discoverable credentials per key, with premium keys reaching 300. Beyond that threshold, users must either delete accounts or purchase additional keys.
Synced passkeys through Apple and Google create dependency on corporate account systems. If automated moderation systems ban a user’s account, they irreversibly lose all passkeys across third-party services. Third-party password managers like Bitwarden and KeePassXC offer alternatives but face fragmentation and inconsistent autofill support outside browsers and in native applications.
Passkeys also complicate access on shared or borrowed devices. While hardware keys, sign-in via synced accounts, and Hybrid Transport (QR code scanning with Bluetooth) offer solutions, each involves trade-offs: keys may not have compatible ports, synced sign-in risks exposing all passkeys, and Hybrid Transport suffers from unreliable connections and limited Bluetooth support.
Hawksley concludes that while enterprise users benefit from passkey adoption, the ecosystem remains immature for individual use. A combination of randomly generated passwords stored in a third-party password manager plus a separate TOTP authentication app provides better control and flexibility for most people than current passkey implementations.
Key facts
- Passkeys eliminate phishing vulnerability but remain dependent on recovery methods like SMS and email
- Hardware keys cannot backup passkeys and have storage limits of 25-300 accounts per key
- Account bans from Apple or Google systems result in irreversible loss of all synced passkeys
- Third-party passkey managers lack consistent autofill support outside browsers
- Passkeys present inconvenience when accessing accounts on shared or borrowed devices
