tech

Readers reply: Experts say we should use passkeys, but can a smartphone pin really be safer than a password?

The long-running series in which readers answer other readers’ questions on subjects ranging from trivial flights of fancy to profound scientific and philosophical concepts

Readers reply: Experts say we should use passkeys, but can a smartphone pin really be safer than a password?

TL;DR

  • Passkeys are considered safer than passwords because they are not vulnerable to phishing and are not stored on company servers.
  • Unlike passwords, which are shared secrets vulnerable to server hacks, passkeys use complex calculations where the key itself is never transmitted.
  • Concerns exist about phone theft and loss, but proponents argue that users notice phone theft quickly and can revoke passkeys, while password breaches may go unnoticed for longer.
  • Some users express skepticism, preferring traditional methods like coded notes and password managers, and suspecting a push for unnecessary complexity by software companies.
  • The shift in security recommendations from password complexity to password length is noted, with passphrases also suggested as a better alternative to passwords.