Text size:
Tuesday Tidbit #1

Passwords vs. passkeys: what's actually safer

The sign-in that can't be phished — and the one catch worth knowing before you turn it on.

August 20, 2026

Welcome to the first Tuesday Tidbit — one short, plain-English tech tip, most weeks, about something worth knowing. No jargon, nothing to install.

This week: passwords vs. passkeys.

The problem with passwords

You already know it. You’ve got dozens of them, they all want a capital letter and a symbol, and the only way to keep them straight is to reuse one or write it down. That’s not you being bad at this — that’s the system asking people to do something people are bad at.

Worse, a password is a secret you can be talked out of. Someone calls, sounds official, says there’s a problem with your account, and asks you to confirm it. Every year, a lot of careful people lose money exactly that way.

What a passkey is

A passkey replaces the password with something your device already does — your fingerprint, your face, or the PIN you use to unlock your phone.

Think of it this way. A password is a key you have to describe out loud to prove it’s yours. A passkey is more like the lock recognizing your thumb. There’s nothing to type, nothing to remember, and nothing to repeat to a stranger on the phone.

Two things follow from that:

  1. It can’t be phished. A passkey only works on the real website. If a fake one asks for it, there’s simply nothing for you to hand over. This isn’t marketing — the U.S. cyber agency calls this kind of sign-in the only widely available phishing-resistant one there is.
  2. It can’t leak in a breach. The company never has your passkey — the secret half never leaves your device.

The honest catch

Passkeys live on your device, so if you lose the phone and haven’t set up a backup, you can lock yourself out. Set the recovery option when you turn one on. And not every site offers them yet — banks are slower than the big tech companies. So keep the notebook for now. Passkeys are something you add, one account at a time, not a switch you flip.

(If you haven’t set up a password notebook yet, here’s how.)

One thing to try this week

Pick one account — your email is the best place to start, since it's the master key to everything else. Sign in, look in the settings for “Passkeys” or “Sign in without a password,” and turn it on. It takes about two minutes.

Where this comes from

Got a thought on this issue? Tell us what you think — takes about 30 seconds.

Want help putting this into practice?

If you'd rather walk through it with a person than a page, just call — no rush, no judgment.