DHAKA —
Users have been encouraged to create complex passwords combining upper- and lowercase letters, numbers and special characters, while avoiding the use of the same password across multiple accounts.
But a different approach is now gaining ground: passkeys.
Passkeys are designed to allow users to sign in without typing or remembering a conventional password. As the technology becomes increasingly available across devices and online services, it is raising a broader question about the future of digital authentication: could passkeys eventually reduce the world's dependence on passwords?
Why passwords remain vulnerable
Many of the weaknesses of passwords are linked not only to the technology itself, but also to how people use them.
Users often choose passwords that are easy to remember, sometimes relying on names, birthdays, phone numbers or familiar words. Others reuse the same or similar password across several services.
That creates a chain reaction when credentials are compromised. If a password exposed in a data breach is also used for another account, that second account may become vulnerable as well.
Phishing presents another persistent problem. Attackers can create websites that closely resemble legitimate services and persuade users to enter their passwords. Once submitted, those credentials can be captured by the attacker.
Password managers and multi-factor authentication can reduce some of these risks, but the fundamental weakness remains: a password is a secret that the user must remember, enter and protect.
How passkeys work
Passkeys take a different approach by relying on cryptographic keys rather than a secret password.
When a passkey is created, a pair of cryptographic keys is generally generated: a public key and a private key.
The online service can store the public key, while the private key remains associated with the user's device or a secure credential-management system.
Crucially, the private key is not normally sent to the website in the way a password is submitted during a conventional login.
When the user attempts to sign in, the service can issue a cryptographic challenge. The user's device uses the private key to produce a response, which can then be verified using the corresponding public key held by the service.
From the user's perspective, the process can be remarkably simple. A fingerprint, face recognition, device PIN or screen lock may be all that is required to authorise the login.
Does the website receive your fingerprint?
One important distinction is often misunderstood.
When a passkey is used, the user's fingerprint or facial information is not normally transmitted to the website as a password.
Instead, the device's local security system verifies the user and, after successful verification, permits the relevant cryptographic credential to be used.
This means the website does not need to receive the user's biometric information every time they sign in.
A stronger defence against phishing
One of the most significant potential advantages of passkeys is their resistance to conventional phishing attacks.
With passwords, a user can accidentally enter credentials into a fraudulent website designed to look like the real service.
Passkeys work differently because the cryptographic credential is associated with the legitimate website or service. A fraudulent site cannot simply ask the user to reveal the underlying private key.
This makes passkeys more than a convenient replacement for remembering passwords. They represent a different model of digital authentication, in which cryptographic proof plays a central role.
Are passwords becoming obsolete?
Not yet.
Millions of websites and online services still depend on passwords, while many older devices and systems do not support passkeys.
There may also be situations involving account recovery, backups or alternative authentication methods where additional mechanisms are required.
For the foreseeable future, therefore, passwords and passkeys are likely to coexist.
However, as support for passkeys expands across devices, browsers and online services, dependence on conventional passwords could gradually decline.
The role of password managers
Passkeys are also becoming part of the broader ecosystem of secure credential management.
Modern operating systems and some password-management services can help users store and use passkeys across supported devices.
This introduces practical questions that did not exist in quite the same way with traditional passwords: How is a passkey made available on a new device? How are credentials backed up? What happens if a device is lost or replaced? And how can an account be recovered securely?
Passkeys are therefore not simply a new type of password. They are part of a wider authentication system involving devices, cryptographic credentials and account-recovery mechanisms.
Passkeys do not eliminate every security risk
The arrival of passkeys does not mean that online security concerns disappear.
If an attacker gains control of a user's device, if the device is protected by a weak PIN or if the user is deceived through another form of fraud, security risks can still arise.
Users should therefore continue to protect their devices with strong screen-lock credentials, install software and security updates, and remain cautious about suspicious links, messages and websites.
Good security practices remain important regardless of the authentication technology being used.
The technology industry is moving toward passwordless authentication
The development of standards such as FIDO2 and WebAuthn, supported by the FIDO Alliance, has helped establish a framework for strong, cryptographic authentication as an alternative to traditional passwords.
Major technology companies, including Apple, Google and Microsoft, have also introduced passkey support across various products and platforms.
As interoperability improves, users are gaining more options for creating, storing and using passkeys across supported devices and services.
What could the future login experience look like?
Imagine opening an account on a new website and being asked not to create a complicated password, but to set up a passkey.
You authorise the process using your fingerprint, facial recognition, device PIN or screen lock. The account is created.
When you return, you authenticate through your device again. There is no long password to remember and no secret phrase to type into a website.
That is the basic experience passkeys are designed to deliver: shifting authentication away from something users have to remember and towards cryptographic credentials secured by their devices.
Passkeys vs passwords: What comes next?
Passwords are unlikely to disappear overnight. Their use remains deeply embedded across the internet, and countless services continue to rely on them.
But passkeys are emerging as a significant alternative that could reduce the need for password-based authentication.
Their combination of convenience, phishing resistance and cryptographic security is driving interest among technology companies and online service providers.
The biggest change may ultimately be psychological as much as technical. Instead of asking, “What is my password?”, users may increasingly rely on their devices to prove who they are.
The password era may not be ending immediately, but the shift toward a passwordless digital future has already begun.

No comments:
Post a Comment