You can already log into many accounts with your face, fingerprint, or a short PIN instead of typing a password. That's a passkey, and it's a big upgrade. Passkeys stop a lot of phishing, the trick where a fake login page fools you into typing your real password. With a passkey there's no password to type, so there's nothing to steal on the fake page. A passkey lives on your device and gets backed up in an app that stores your logins, like the one on your phone, and it never gets reused across sites. FIDO Alliance, the industry group that sets passkey standards, says passkey use has crossed 5 billion accounts, and World Passkey Day 2026 was full of victory laps. Mostly earned.
The problem is not passkeys. The problem is the side door right next to them: how you get back in if you lose your phone. That part is usually still terrible.
What passkeys actually fix
A passkey beats a password the way a deadbolt beats a sticky note on the door. A password is a secret you type, and most people reuse it everywhere, so one leak unlocks a dozen accounts. Typing that kind of secret into login boxes is the most common way people get hacked, and passkeys remove it. Google has pushed passkeys for years, and Microsoft used May 7, 2026 to argue for going passwordless across its own products. More of that would be welcome. Typing passwords into random login boxes is security theater dressed up as responsibility.
Fido Alliance Reports Accelerating Global Passkey, Google Helpful Tools Google Keep Your Accounts, Microsoft World Passkey Day Advancing Passwordless Authentication
Where recovery actually breaks
An account can have a strong front door and a flimsy side door at the same time. Recovery is how a service lets you back in when you can't use your passkey. If it lets you skip the passkey with a text message, an email reset, a weak phone call to support, or an old phone that should have been removed years ago, attackers don't need to beat the passkey at all. They just use the side door.
Check any normal Google or Microsoft account and there's a good chance a recovery email from 2021 is still sitting on it. Old phones, backup emails, open browser logins, app-specific passwords, emergency codes, all of it tends to pile up. Calling something passwordless while a stack of password-era stuff sits underneath it is mostly marketing.
FIDO State of Passkeys 2026, Google Helpful Tools Google Keep Your Accounts
Phishing adapted too
Microsoft's April 6, 2026 writeup on an AI-powered phishing campaign is the kind of thing that should make every passwordless slide deck sweat a little. The attack didn't need a fake password box at all. It pushed victims through a real Microsoft login screen and tried to get them to approve access by typing in a short code the attacker fed them.
Push Security has been tracking the same rough problem in 2026. This trick works because it abuses your trust in normal login pages and normal habits. A tired, rushed person staring at a convincing chat message reads the prompt as routine work stuff, not a neon warning sign.
Microsoft Threat Intelligence, Push Security
What to audit first
Start with the boring checkup. Open your Google, Microsoft, Apple, bank, domain, and password-manager accounts. Remove old devices. Delete stale recovery emails. Print fresh backup codes if the service offers them, then store them somewhere sane. If a phone number is still the master fallback for everything, that's a problem.
For work accounts, admins should treat recovery paths as real security controls, not leftover settings. Logging in with a typed code should be turned off when nobody needs it. Old app permissions, the access you once granted some tool to read your account, should be reviewed and pulled. Support-desk recovery should require more than a warm voice and a sad story. One weak reset path can undo years of careful work. Boring until it becomes the entire incident report.
Passwordless still has homework
Passkeys are still the right move. They're great for normal sign-in, and pretending passwords are secretly fine because recovery is messy would be silly. They're not fine. But the sales pitch needs less sparkle and more honesty about the fallback paths that keep accounts recoverable.
Turn on passkeys. Then do the less fun part. Check the recovery stuff, clean out the old junk, and ask one mean question. If an attacker were trying to steal this account today, would they fight the passkey, or just walk through the forgotten side door?




