THREAT BRIEFING · 24.09.2026 DEENFRES

Strategy & Governance

Should We Abandon Passwords? Why the Passkey Hype Ignores Reality

By Tobias Massow · November 20, 2025 · 5 min read

Google, Apple, and Microsoft are promoting a “passwordless future” with passkeys. The promises sound good: more secure, simpler, and phishing-resistant. But reality is more complicated. Vendor lock-in, device dependency, and lack of recovery mechanisms make passkeys a risky solo effort for companies. A sober look beyond the marketing.

TL;DR

What Passkeys Get Right

The criticism first – but let’s start with the praise. Passkeys are based on FIDO2/WebAuthn and are cryptographically solid. Instead of a password that can be transmitted and thus stolen, the user authenticates via a public-key procedure. The private key never leaves the device. Phishing is structurally impossible because there is no secret that could be intercepted.

For consumer applications, this is a real advancement. No password reuse, no credential stuffing, no database leaks with millions of plaintext passwords. So much for the theory.

Where the Hype Obscures Reality

1. Vendor Lock-in: A passkey stored in Apple’s iCloud Keychain works seamlessly on iPhone, iPad, and Mac. But not on the Android corporate phone. Not on the Windows work computer. The “open” technology becomes ecosystem glue through proprietary sync mechanisms. Google and Apple have no interest in portability – passkeys bind users.

2. Device Dependency: Your smartphone is your passkey safe. If it is lost, stolen, or breaks, you face a recovery problem that passwords never had. “Forgot password” is a solved workflow. “Lost passkey” is not.

3. Enterprise Suitability: An IT admin managing access for 500 employees needs: centralized provisioning, revocation upon termination, audit logs, backup mechanisms, device independence. None of these issues are satisfactorily solved today. Passkeys were developed for consumers, not for enterprises.

What Companies Should Do Instead

MFA first, not passkeys first: The biggest security improvement does not come from passkeys, but from consistent multi-factor authentication. Hardware tokens (YubiKey), TOTP apps, and push notifications are mature, device-independent, and enterprise-ready. If you don’t have MFA yet, solve that before thinking about passkeys.

Passkeys as an option, not a mandate: Offer passkeys as an additional authentication method – but don’t enforce them. Users with mixed device ecosystems (private iPhone, corporate Windows) otherwise lose access or resort to insecure workarounds.

Password manager instead of abolition: An enterprise password manager with generated, unique 128-bit passwords plus MFA is currently more secure, portable, and manageable than passkeys. The passwordless future is coming – but it’s not here yet.

Conclusion: Evolution, Not Revolution

Passkeys are the future of authentication – in three to five years, when portability, recovery, and enterprise management are solved. Today, they are a promising consumer feature that creates more problems for companies than it solves. The honest recommendation: roll out MFA widely, use password managers, observe and pilot passkeys – but don’t sell them as a silver bullet.

Key Facts

Passkey Adoption: Less than 5 percent of login processes at major services use passkeys so far – despite aggressive promotion by Apple and Google since 2023.

Recovery Problem: 37 percent of users who try passkeys revert to passwords within 90 days – the most common reason: device change or access loss (FIDO Alliance, 2024).

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Are passwords really less secure than passkeys?

Weak, reused passwords: Yes, significantly. Generated, unique passwords with MFA: The security difference to passkeys is marginal. The problem was never passwords themselves, but human handling of them.

Should I offer passkeys anyway?

Yes – as an optional method alongside MFA. For tech-savvy users in homogeneous ecosystems (e.g., pure Apple environment), passkeys are more comfortable and secure. As the sole method for heterogeneous corporate environments, they are not yet mature.

When will passkeys be enterprise-ready?

When three conditions are met: cross-platform portability (export/import between Apple, Google, Microsoft), centralized MDM management with revocation and audit, and a standardized recovery process in case of device loss. Forecast: 2027/2028.

Related Articles

More from the MBF Media Network

MyBusinessFutureDigital Identity and Authentication on mybusinessfuture.comcloudmagazinCloud Identity and Access Management on cloudmagazin.com

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH