Twenty years ago, you had a handful of login passwords. Now there are dozens.
They are impossible to remember and it is tempting to give in to bad password hygiene.
Password managers were built to fix it. LastPass creates a different password for every site, stores them all in your vault and fills them in when you need them. You remember one master password and the vault remembers the rest.
That covers the remembering. But passwords also depend on staying secret.
what a strong password can and cannot protect you from
A secret only works while it stays secret
A password works because only you know it. If someone else learns it, it works for them too.
One of the most common cyber attacks is phishing. An email arrives with a link to a trusted supplier portal like Microsoft. The page looks right, so the details get typed in. But the page is a copy of the real one, and what gets typed there goes to the people who set it up.
A password manager gives you a long random password that is very hard to guess. But typed into a copy of the site, a strong password is still handed straight over.
A password manager fixes the remembering, not the handing over.
How passkeys work
signing in without a password, and why a fake page gets nothing
The device proves who you are
Enter passkeys, a way of signing in without a password.
Instead of you typing a secret, your computer or mobile phone proves who you are. It usually does that with the same fingerprint, face scan or PIN that unlocks the device. There is nothing to remember and nothing to type.
The important part is that a passkey is tied to the site it was created for. It only works on that web address. A lookalike page at a slightly different address gets nothing, because it is not the site the passkey belongs to.
The phishing email can still arrive, and there is no password to type into it. Google, Microsoft, Amazon and myGov all offer passkeys today, and the list keeps growing.
0Passwords to remember or type when signing in
1Web address a passkey will ever work on
4+Major services already offering passkeys, and growing
Where a passkey is stored
two common arrangements, and what each one means day to day
A passkey is stored somewhere, and where it is stored affects where you can use it.
Where it lives
What that means in practice
Inside one company's system
Create a passkey on your iPhone and Apple keeps it, which covers your other Apple devices. On a Windows desktop at the office, that passkey is not available.
Device-bound
These stay on the hardware that made them, sitting on a security key or inside one particular laptop. Replace that device and the passkey stays behind, so the site's account recovery process takes over.
A third option is covered in section 4: a passkey held in your password vault.
What this means for your business
The two situations are different. A device-bound passkey stays with its hardware. A passkey held in another company's system is still there, just not on the device in front of you.
For someone moving between a work laptop, a personal phone and more than one browser, where a passkey is stored affects how usable it is.
How LastPass handles passkeys
the same vault, the same prompts, on whichever device you are using
LastPass added general support for passkeys and stores them in the same vault as your passwords.
Passkeys saved in LastPass sync across your devices, browsers and operating systems, no matter which one you created them on. Make a passkey on your iPhone and it is waiting on the Windows desktop. Move to a new laptop and your passkeys arrive with everything else in the vault.
The process is one you already know
1
The site offers
A site you use offers you a passkey. The prompt comes from the site itself.
2
You create it
You choose to create one, and LastPass saves it to your vault.
3
LastPass fills it
Next time you sign in there, LastPass offers to fill it, the same way it fills a password.
Before you start. Passkeys are created, stored and managed through the LastPass browser extension or mobile app, so both need to be up to date.
Businesses enable passkey support through a LastPass admin policy, so availability depends on how the organisation's account is set up.
Why keep passkeys in LastPass
one place for both kinds of login, available wherever you are working
Everything in one vault
Most sites still use passwords, so keeping passkeys in the same vault means both kinds of login sit in one place. The vault keeps track of it all and reports on weak and reused passwords.
It also keeps logins portable. A passkey held in Apple's or Google's system works only inside that ecosystem. A passkey held in LastPass is available on whatever computer, mobile and browser you are on.
The decision is where it gets stored
Passkey support is spreading, so the prompt to create one will come up more often. The decision at that point is where the passkey gets stored.
Saved to LastPass, it sits with the rest of your logins and is available everywhere. Give it a try.
Ready to take the next step?
Let's talk about where your business stands
No jargon, no hard sell. Just a clear, honest picture of your cyber security and IT, and what to do about it.
More than 20 years protecting Australian businesses
Not a single fully protected client has been breached since 2017
Jam Cyber Insights
Passkeys Are Here: A Simpler, Safer Way to Log In
Twenty years ago, you had a handful of login passwords. Now there are dozens.
They are impossible to remember and it is tempting to give in to bad password hygiene.
Password managers were built to fix it. LastPass creates a different password for every site, stores them all in your vault and fills them in when you need them. You remember one master password and the vault remembers the rest.
That covers the remembering. But passwords also depend on staying secret.
In this guide
Limits of even "good" passwords
what a strong password can and cannot protect you from
A secret only works while it stays secret
A password works because only you know it. If someone else learns it, it works for them too.
One of the most common cyber attacks is phishing. An email arrives with a link to a trusted supplier portal like Microsoft. The page looks right, so the details get typed in. But the page is a copy of the real one, and what gets typed there goes to the people who set it up.
A password manager gives you a long random password that is very hard to guess. But typed into a copy of the site, a strong password is still handed straight over.
How passkeys work
signing in without a password, and why a fake page gets nothing
The device proves who you are
Enter passkeys, a way of signing in without a password.
Instead of you typing a secret, your computer or mobile phone proves who you are. It usually does that with the same fingerprint, face scan or PIN that unlocks the device. There is nothing to remember and nothing to type.
The important part is that a passkey is tied to the site it was created for. It only works on that web address. A lookalike page at a slightly different address gets nothing, because it is not the site the passkey belongs to.
The phishing email can still arrive, and there is no password to type into it. Google, Microsoft, Amazon and myGov all offer passkeys today, and the list keeps growing.
Where a passkey is stored
two common arrangements, and what each one means day to day
A passkey is stored somewhere, and where it is stored affects where you can use it.
A third option is covered in section 4: a passkey held in your password vault.
What this means for your business
The two situations are different. A device-bound passkey stays with its hardware. A passkey held in another company's system is still there, just not on the device in front of you.
For someone moving between a work laptop, a personal phone and more than one browser, where a passkey is stored affects how usable it is.
How LastPass handles passkeys
the same vault, the same prompts, on whichever device you are using
LastPass added general support for passkeys and stores them in the same vault as your passwords.
Passkeys saved in LastPass sync across your devices, browsers and operating systems, no matter which one you created them on. Make a passkey on your iPhone and it is waiting on the Windows desktop. Move to a new laptop and your passkeys arrive with everything else in the vault.
The process is one you already know
Before you start. Passkeys are created, stored and managed through the LastPass browser extension or mobile app, so both need to be up to date.
Businesses enable passkey support through a LastPass admin policy, so availability depends on how the organisation's account is set up.
Why keep passkeys in LastPass
one place for both kinds of login, available wherever you are working
Everything in one vault
Most sites still use passwords, so keeping passkeys in the same vault means both kinds of login sit in one place. The vault keeps track of it all and reports on weak and reused passwords.
It also keeps logins portable. A passkey held in Apple's or Google's system works only inside that ecosystem. A passkey held in LastPass is available on whatever computer, mobile and browser you are on.
The decision is where it gets stored
Passkey support is spreading, so the prompt to create one will come up more often. The decision at that point is where the passkey gets stored.
Saved to LastPass, it sits with the rest of your logins and is available everywhere. Give it a try.
Ready to take the next step?
Let's talk about where your business stands
No jargon, no hard sell. Just a clear, honest picture of your cyber security and IT, and what to do about it.
Jam Cyber · Cyber Insights: Passkeys Are Here · [email protected] · jamcyber.com
Recent Posts
Categories