Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
Really depends on what you mean by passkey, since it’s actually a fairly vague term for a bundle of technologies.
I don’t really care for password manager passkeys; just use a password, all it really does is save you from needing to enter a username in a login flow.
But I’m a big fan of hardware 2fa using non-resident keys (“passkey” lite); I’ll use a regular login flow with a password manager, then the 2FA step with a hardware token. Basically bulletproof (ditto if you secure your PW manager with hw 2fa) and painless.
android doesn’t allow 3rd party apps to use passkeys nor autofill 2fa consistently. For passkeys, you are forced to use google services for it, or loose access, making it pointless. TOTP codes meanwhile can at least be copied and pasted manually from a password manager.
A password manager is better than passkeys in 2026
Really depends on what you mean by passkey, since it’s actually a fairly vague term for a bundle of technologies.
I don’t really care for password manager passkeys; just use a password, all it really does is save you from needing to enter a username in a login flow.
But I’m a big fan of hardware 2fa using non-resident keys (“passkey” lite); I’ll use a regular login flow with a password manager, then the 2FA step with a hardware token. Basically bulletproof (ditto if you secure your PW manager with hw 2fa) and painless.
Some password managers can sync passkeys for you! Bitwarden can handle it
android doesn’t allow 3rd party apps to use passkeys nor autofill 2fa consistently. For passkeys, you are forced to use google services for it, or loose access, making it pointless. TOTP codes meanwhile can at least be copied and pasted manually from a password manager.