I’m all for streamlining life and making the whole password process easier! For some reason, I’ve been slow to adopt Passkeys. I’ve written about Passkeys for the past couple of years. The thing I couldn’t get was how Passkeys could “go with you” across devices and when you change devices.
I read articles recently that confirmed my suspicions that I am not alone! Today, I give credit to the author, Oluwademilade Afolabi, for putting into words my hesitation. And share an additional article from MakeUseOf.com

Photo by Miguel Á. Padriñán: https://www.pexels.com/photo/close-up-shot-of-keys-on-a-red-surface-2882654/
Passkeys Feel Invisible Until the Device Changes
When a website offers to create a passkey, your browser or operating system usually suggests where to store it. Where to store it depends on your device, enabled providers, and the website’s policy.
The credential provider is the operating-system service or password manager that stores and, in some cases, synchronizes the passkey. That storage layer becomes much easier to understand when a password manager makes passkeys visible and manageable instead of leaving them buried inside an operating-system prompt.
You then confirm your identity with a fingerprint, Face ID, a PIN, or Windows Hello and sign in without entering a password. Each passkey belongs to one particular website or app account, so it is not a master key that unlocks everything.
Creating a passkey generates a cryptographic key pair. The website stores the public key, while the corresponding private-key material remains under the control of your device or credential provider. A synchronized provider can distribute end-to-end encrypted copies to your other devices, but the website never receives the private key.
The practical distinction is between synchronized and device-bound passkeys. A passkey saved in iCloud Keychain follows you across approved Apple devices, while Google Password Manager synchronizes passkeys across Android and supported Chrome installations.
Device-bound passkeys stay with one authenticator. Microsoft Entra passkey on Windows, currently a preview feature, stores the credential in the local Windows Hello container and requires a separate registration on every PC.
Portability between providers is improving. The FIDO Alliance’s Credential Exchange specifications provide a secure standard for participating apps to transfer credentials, including passkeys. Recent Apple platforms support those transfers, and Google Password Manager now supports importing and exporting passkeys with compatible managers on Android. The awkward part has not vanished, though, because support still depends on current software and both providers participating.
When the passkey is stored on your phone rather than the computer in front of you, cross-device authentication can bridge the gap. The laptop displays a QR code, your phone scans it, and Bluetooth confirms the two devices are physically close before the login is approved. In that situation, your Android phone effectively acts as a security key for the device in front of you.
The actual request travels through an end-to-end encrypted internet connection, and the phone signs a one-time challenge without handing over the passkey itself. If the phone is out of Bluetooth range, offline, unavailable, or back at home, that route disappears with it.
Losing the Phone is Survivable, But Recovery has Two Layers
Dropping a phone into a lake is usually recoverable if your passkeys were synchronized through an end-to-end encrypted provider. Signing in on a replacement device can restore them.
Apple provides protected recovery mechanisms for iCloud Keychain. At the same time, Google may require a Google Password Manager PIN or an existing device’s screen lock before making synchronized passkeys available in a new environment.
There are really two recovery problems. The first is credential recovery, which restores the encrypted vault containing your passkeys. The second is website-account recovery, which gets you back into an individual service when no usable passkey remains.
If you lose access to the Apple, Microsoft, third-party, or Google account handling your synchronized data, credential recovery may become difficult or impossible. The same risk appears when the only passkey lives on a lost device, when you change providers without transferring credentials first, or when a managed work computer blocks the provider you expected to use.
At that point, recovery depends entirely on whatever backup route the service still offers, which may be a password, an email link, recovery codes, another registered passkey, or a support process. That does not make every fallback insecure, but it means the account’s practical resistance to takeover may be determined by its weakest permitted recovery route.
A passkey can resist phishing while an exposed email account still creates another path inside. A hijacked phone number used for SMS authentication can do the same if the service permits it as a recovery route.
New Ways to Transfer Passkeys!
MakeUseOf.com‘s article describes how to transfer passkeys between devices! The author says it well, “This is changing with the introduction of new FIDO Credential Exchange standards, which now allow a safe way to move passkeys between applications.
While adoption is still limited, this can help make passkeys a more convincing option for skeptics. For anyone who’s been holding off on passkeys because they don’t want to be locked into a single ecosystem, this is a development worth paying attention to.”
Click on the highlighted link above to read the whole article to determine IF you’d like to explore transferability of your passkeys.
Passkeys are an Option IF you Know Where They Live
I haven’t decided to take the plunge into passkeys as yet. I’m still evaluating from the lens of whether others understand all of this and access my information if needed. Stay tuned; I’ll keep you posted!
Make sure to know where your passkeys are stored, what they synchronize through, and how you would recover access without your usual device, and you’ll be ready to decide.
Caution: I found an article while writing this warning us that passkeys can be stolen too 🙁 Yikes! It appears that using Google Password Manager for Windows is the culprit. I am linking the article for you HERE, in case you’d like to review the details.

Photo by Miguel Á. Padriñán: https://www.pexels.com/photo/close-up-shot-of-keys-on-a-red-surface-2882654/
Protecting Yourself
We’re living in a world of technology that changes in the blink of an eye, i.e. passkeys. All facets of life change along with technology. Think about it: how we shop, how we bank, how we invest, and how we communicate are all linked to tech!
Simultaneously, there are hackers attempting to get our information. How are you staying informed, safe, and protected?
Join me in The Ready Room if you’d like to plan and organize the admin side of life (document and work on tasks), with a side of having a place to ask questions with me. No cost, one hour, on three Wednesdays: September 16, 23, & 30 at 9 am Pacific Time. Register on Zoom TheReadyRoom.
If you’d like to learn more about my work, check out my website @ The Living Planner. Or feel free to Email me anytime. I love hearing from you!
I’ve written my book for people who would like to consider planning for now and after a loss. The 2026 edition of Living Planner What to Prepare Now While You Are Living © can be purchased HERE.
Quote of the week: “Without labor nothing prospers.” – Sophocles
Happy Labor Day weekend! Lynn
#Can’tPredictCanPrepare #CareForPeopleCareForBusiness

