
Consumers are moving from passwords to passkeys, but the new method still requires careful protection. Improper handling can expose accounts to the same risks that plagued traditional passwords. Understanding how to secure each storage option is essential.
Securing Cloud-Stored Passkeys
When a passkey is saved to a smartphone, a password manager, or a browser linked to a Microsoft or Google account, it resides in the cloud. Cloud storage enables use across multiple devices, but it also ties the passkey’s safety to the underlying account.
To defend that account, set a long, random password that is unique to the service. Enable two-factor authentication to add a second verification step. Both measures reduce the chance that an attacker can steal stored passkeys.
Select a reputable cloud-based password manager. Independent managers tend to attract fewer attacks than large platforms such as Chrome, which have already seen successful exploitation of stored passkeys. Reducing exposure starts with the choice of service.
Protecting Device-Bound Passkeys
Saving a passkey directly to a Windows PC keeps it off the cloud. Windows requires Windows Hello to lock the credential, typically using a PIN or biometric factor. A PIN of at least six digits is recommended for reasonable security.
Hardware keys such as the YubiKey or Google Titan Security Key store passkeys offline. When configuring a YubiKey, the manufacturer advises a PIN that meets the minimum length requirement. Business-grade YubiKeys may enforce this length automatically.
YubiKey devices also wipe themselves after eight incorrect PIN attempts, preventing repeated brute-force guessing. This automatic reset adds a layer of protection that software-only solutions cannot provide.
Unlike passwords, which can be reused across sites, passkeys are tied to specific services, limiting the damage of a single breach. The shift mirrors earlier moves from reusable tokens to device-specific certificates, showing a pattern of tightening authentication scopes.
Backing Up Passkeys
Having a single passkey is risky; loss of the device can lock a user out with no reset option. Creating backup copies mitigates that danger.
For cloud-based passkeys, generate an additional credential on a separate PC or on a hardware security key. Security keys are priced between $30 and $35 and can be purchased at major retailers.
