Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

Five Billion Passkeys Later, the Password Is Finally Losing Its Default Status

Passkeys have reached an estimated five billion active credentials, but recovery, portability and inconsistent implementation still decide whether users trust them.

Outspoken Digest Technology Desk

Friday, July 31, 2026/2 min read

A person using biometric authentication on a smartphone
Photo: Intel Free Press via Openverse (CC BY-SA 2.0)

The password has survived decades of predictions about its death because every alternative had a distribution problem. Passkeys are different. The FIDO Alliance estimates that five billion active passkeys now exist worldwide, placing passwordless authentication beyond the experimental stage and into everyday consumer and workplace use.

The Alliance announced the milestone in its State of Passkeys 2026 findings. Passkeys replace a shared secret with cryptographic credentials. The service stores a public key, while the private key remains with the user's device or credential provider and is unlocked through a local gesture such as biometrics or a device PIN.

Why passkeys resist phishing

A password can be typed into a convincing fake website. A properly implemented passkey is bound to the legitimate service's domain, so the credential will not authenticate the impostor. There is also no reusable password database for an attacker to steal and test elsewhere.

This removes several common failure modes at once: weak passwords, password reuse, credential stuffing and many forms of phishing. It also makes login faster when the experience is designed well.

The difficult part is recovery

Users do not experience authentication as cryptography. They experience it when a phone is lost, a laptop breaks or a family member changes ecosystems. If recovery is confusing, people blame the passkey even when the login itself was secure.

Synced passkeys improve convenience by allowing credentials to follow the user across approved devices. Device-bound credentials can offer stronger control in regulated workplaces. Services need to explain which model they use, offer multiple enrolled devices or security keys and avoid falling back to a weak recovery channel that defeats the entire system.

Implementation quality varies

Independent research presented through the USENIX Security 2026 study of passkey deployment finds that adoption and implementation across the web remain uneven. A site can technically support passkeys while hiding the option, requiring a password first or making account recovery dependent on insecure legacy flows.

This is a product design problem as much as a security problem. Users need a clear invitation, understandable device names and simple ways to review or revoke credentials.

What users should do now

  • Create passkeys for high-value accounts such as email, finance and password managers when available.
  • Keep device security, operating systems and recovery information current.
  • Enroll a second trusted device or hardware key where the service allows it.
  • Review passkeys from old devices and revoke those no longer controlled.
  • Remain cautious of fake recovery messages; passkeys reduce phishing but do not remove social engineering.

The finish line is not a number

Five billion credentials prove distribution. They do not prove that every user can recover an account or move between providers without friction. The next phase must improve portability, shared-device scenarios and enterprise administration while preserving phishing resistance.

Passwords will remain as legacy access and recovery for years. The meaningful change is that they no longer have to be the starting point. Passkeys are becoming the default on major platforms because they combine stronger security with less typing. Their success now depends on making the worst day, a lost device or locked account, as carefully designed as the first login.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Technology Desk

Software, hardware, artificial intelligence and what they change for everyone else.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.