{"id":499526,"date":"2026-06-14T17:18:09","date_gmt":"2026-06-14T17:18:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/499526\/"},"modified":"2026-06-14T17:18:09","modified_gmt":"2026-06-14T17:18:09","slug":"readers-reply-experts-say-we-should-use-passkeys-but-can-a-smartphone-pin-really-be-safer-than-a-password-life-and-style","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/499526\/","title":{"rendered":"Readers reply: Experts say we should use passkeys, but can a smartphone pin really be safer than a password? | Life and style"},"content":{"rendered":"<p class=\"dcr-130mj7b\">I\u2019ve been struggling to get my head around the idea that a passkey, which can be a pin on your phone, or facial recognition, can be safer than using a complicated password and two-factor authentication.<\/p>\n<p class=\"dcr-130mj7b\">I get that having something unique to your device, not stored on a company\u2019s server, is unphishable and less hackable by cybercrims, but what if your phone is nicked and someone guesses the password? And what if you lose your phone?<\/p>\n<p class=\"dcr-130mj7b\">Sorry if that sounds simplistic, but I am genuinely stumped to understand why the <a href=\"https:\/\/www.theguardian.com\/technology\/2026\/apr\/24\/what-is-a-passkey-how-does-it-work-and-why-is-it-better-than-a-password\" data-link-name=\"in body link\" rel=\"nofollow noopener\" target=\"_blank\">UK\u2019s National Cyber Security Centre<\/a> and others who know about these things are so sold on passkeys. Can anyone who\u2019s used them enlighten me? Martin Avis, Chester<\/p>\n<p class=\"dcr-130mj7b\">Send new questions to <a href=\"https:\/\/www.theguardian.com\/lifeandstyle\/2026\/jun\/14\/mailto:nq@theguardian.com\" data-link-name=\"in body link \" https:=\"\" rel=\"nofollow noopener\" target=\"_blank\">nq@theguardian.com<\/a>.<\/p>\n<p>Readers reply<\/p>\n<p class=\"dcr-130mj7b\">The question is legit and deserves a proper answer. First, passkeys are safer than passwords simply because login using a password is vulnerable to a hacker anywhere in the entire world, while a physical passkey is vulnerable only to a hacker who can steal your phone (as the crypto used by a passkey is out of reach of hacking by anyone but state actors \u2013 and they don\u2019t need to hack your bank account). Second, when someone steals your phone, you tend to notice very quickly and can cancel (revoke) your passkey on your accounts; if your password login is hacked, you may not notice for a long time. No security system is perfect, but passkeys are still a good step up compared to a password. wyldfam<\/p>\n<p class=\"dcr-130mj7b\">Passkeys are good, strong protection \u2013 much better than passwords. Create a 10-digit pin on your phone from random numbers and remember it so it\u2019s second nature. On an iPhone, turn on \u201cStolen Device Protection\u201d. [On Android, it\u2019s Identity Check.] And if you\u2019re really serious about security, enable iOS\u2019s \u201cLockdown Mode\u201d [or Android\u2019s \u201cAdvanced Protection Mode\u201d]. That\u2019s my opinion. TechGirl<\/p>\n<p class=\"dcr-130mj7b\">Passwords are built on an inherent weakness known as a \u201cshared secret\u201d. That is, your password must be \u201cshared\u201d between you and the website you\u2019re accessing. This is so your password can be sent to the website and verified when you login. The problem with this is that if a server is hacked and your data is stolen, your password can be lifted from the hacked data and reused by the hacker without your knowledge.<\/p>\n<p class=\"dcr-130mj7b\">Passkeys don\u2019t have this weakness. A passkey is (very simply) a really complex value that\u2019s used as a start for a mathematical calculation, the result of which is sent to the website. This mathematical result is then verified to have come from only your passkey using a totally different complex value. The beauty is that your passkey is never sent to the website (only the result is), so if the website is hacked, your passkey can\u2019t be stolen and can\u2019t be reused. Passkeys are stored in your phone, laptop or password manager and unlocked using a simple pin or biometrics, so they\u2019re super easy to use, while still maintaining that highly secure underlying technology. There are more benefits to using passkeys, though being easy to use and \u201cunphishable\u201d are the most obvious ones. If given the choice, pick passkey every time. gh05ted<\/p>\n<p class=\"dcr-130mj7b\">I really can\u2019t understand these answers. I tend not to use things I don\u2019t understand. My passwords are partly written on a piece of paper. The accounts they refer to are on a separate piece in a different place written in a way only I could make much sense of. I do use two-factor authentication where required or available. I don\u2019t use a password manager. Good luck if you can hack that. I\u2019m very suspicious of all this. I suspect it is software companies trying to self stuff we don\u2019t need and making things more complicated than they need to be. dannytheclown<\/p>\n<p class=\"dcr-130mj7b\">The whole subject seems very confusing. My initial understanding of passkeys, after Microsoft suggested their use on my PC, was that they were simply supposed to be a convenience, because they were easier to enter then passwords. Recent publicity now indicates that they should be more secure because they are tied to hardware and cannot be used remotely by hackers. On the other hand, you may be able to sync them between devices, which seems to introduce possible vulnerabilities.<\/p>\n<p class=\"dcr-130mj7b\">Between fingerprints, pins, passwords, passkeys, password managers, two-factor authentication via apps or text messages \u2013 not to mention Google, Apple or Windows offering to save and enter your passwords (and passkeys?) automatically \u2013 getting security right is a minefield for Joe (or Joanna) Bloggs. Getting access to your system again if it crashes and you have forgotten key passwords after years of letting it log on itself is also a severe risk. GordonLiv<\/p>\n<p class=\"dcr-130mj7b\">I\u2019ve resisted using a passkey because it is tied to a single device. What happens if I want to access my bank account and I\u2019m away from my desktop? Then I need to have passkeys on my laptop and maybe on my phone as well. In the latter case, my security only becomes as secure as my phone (which can easily end up in the hands of others). What happens if I have lost access to all of my devices and need to get money urgently? So I am continuing to use a password. Every high-value site has its own very different password, which is not stored in a password manager, but in my memory. And on a bit of paper, which I can take with me when travelling \u2013 but that has the information in an incomplete, coded form, so would be useless to anyone else. It\u2019s not as strong as a passkey tied to a single device \u2013 but it\u2019s unlikely to leave me stranded. Jiminoz<\/p>\n<p class=\"dcr-130mj7b\">Ugh. I think back to my childhood and younger adult life when your \u201cpassword\u201d was your signature. We didn\u2019t ask for this complicated world \u2013 we were told life would be so much easier when we logged on to do this or that. We had no choice in any of it and now look where we are. The burden for protecting ourselves from the life we didn\u2019t ask for falls directly on to us. And of course, it\u2019s our fault when we get hacked. To that end, I\u2019ll stick with my password manager. ElleWoods<\/p>\n<p class=\"dcr-130mj7b\"><a href=\"https:\/\/cybersecuritynews.com\/nist-rules-password-security\/\" data-link-name=\"in body link\" rel=\"nofollow noopener\" target=\"_blank\">Since September 2024<\/a>, the US National Institute of Standards and Technology has stopped recommending \u201cenforcing arbitrary password complexity requirements such as mixing uppercase and lowercase letters, numbers and special characters. Instead, the focus has shifted to password length as the primary factor in password strength\u201d. <a href=\"https:\/\/xkcd.com\/936\/?correct=horse&amp;battery=staple\" data-link-name=\"in body link\" rel=\"nofollow noopener\" target=\"_blank\">The web comic XKCD<\/a> explains why passphrases are better than passwords. mu5epen7ra<\/p>\n<p class=\"dcr-130mj7b\">When I die, how do I ensure that my executor can access my passkey to control my accounts? BarnerCobblewood<\/p>\n<p class=\"dcr-130mj7b\">In reply: Use a password manager and store the \u201croot of trust\u201d on a physical piece of paper and store it in a safe place. Storing a \u201croot of trust\u201d for your password manager means storing sufficient information to regain access to your password manager account, even if you lose all your devices. Typically, it includes long and random recovery codes. For example, <a href=\"https:\/\/www.theguardian.com\/technology\/2022\/mar\/19\/not-using-password-manager-why-you-should-online-security\" data-link-name=\"in body link\" rel=\"nofollow noopener\" target=\"_blank\">1Password generates an \u201cemergency kit\u201d<\/a> as part of the initial setup. This is a pdf you physically print out for exactly this purpose. A relative or executor can use the emergency kit to re-establish access to your password manager and all its data. jmsgwd<\/p>\n<p class=\"dcr-130mj7b\">I was going to tell you all how I use passwords, but now that I\u2019ve read all the comments I\u2019m scared to reveal anything. Goldgreen<\/p>\n","protected":false},"excerpt":{"rendered":"I\u2019ve been struggling to get my head around the idea that a passkey, which can be a pin&hellip;\n","protected":false},"author":2,"featured_media":499527,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[61,60,202,80],"class_list":["post-499526","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-ie","tag-ireland","tag-mobile","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/499526","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=499526"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/499526\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/499527"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=499526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=499526"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=499526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}