tech
Readers reply: Experts say we should use passkeys, but can a smartphone pin really be safer than a password?
The long-running series in which readers answer other readers’ questions on subjects ranging from trivial flights of fancy to profound scientific and philosophical concepts

TL;DR
- Passkeys are considered safer than passwords because they are not vulnerable to phishing and are not stored on company servers.
- Unlike passwords, which are shared secrets vulnerable to server hacks, passkeys use complex calculations where the key itself is never transmitted.
- Concerns exist about phone theft and loss, but proponents argue that users notice phone theft quickly and can revoke passkeys, while password breaches may go unnoticed for longer.
- Some users express skepticism, preferring traditional methods like coded notes and password managers, and suspecting a push for unnecessary complexity by software companies.
- The shift in security recommendations from password complexity to password length is noted, with passphrases also suggested as a better alternative to passwords.