116 Gawler Place, Adelaide SA 5000 1800 818 875 [email protected]

Passkeys Are Here: A Simpler, Safer Way to Log In

Jam Cyber Insights

Passkeys Are Here: A Simpler, Safer Way to Log In

Twenty years ago, you had a handful of login passwords. Now there are dozens.

They are impossible to remember and it is tempting to give in to bad password hygiene.

Password managers were built to fix it. LastPass creates a different password for every site, stores them all in your vault and fills them in when you need them. You remember one master password and the vault remembers the rest.

That covers the remembering. But passwords also depend on staying secret.

Limits of even "good" passwords

what a strong password can and cannot protect you from

A secret only works while it stays secret

A password works because only you know it. If someone else learns it, it works for them too.

One of the most common cyber attacks is phishing. An email arrives with a link to a trusted supplier portal like Microsoft. The page looks right, so the details get typed in. But the page is a copy of the real one, and what gets typed there goes to the people who set it up.

A password manager gives you a long random password that is very hard to guess. But typed into a copy of the site, a strong password is still handed straight over.

Password manager 7F$a9kQ2!mT8z#4Lp Long Random Hard to guess
A password manager fixes the remembering, not the handing over.

How passkeys work

signing in without a password, and why a fake page gets nothing

The device proves who you are

Enter passkeys, a way of signing in without a password.

Instead of you typing a secret, your computer or mobile phone proves who you are. It usually does that with the same fingerprint, face scan or PIN that unlocks the device. There is nothing to remember and nothing to type.

The important part is that a passkey is tied to the site it was created for. It only works on that web address. A lookalike page at a slightly different address gets nothing, because it is not the site the passkey belongs to.

The phishing email can still arrive, and there is no password to type into it. Google, Microsoft, Amazon and myGov all offer passkeys today, and the list keeps growing.

0 Passwords to remember or type when signing in
1 Web address a passkey will ever work on
4+ Major services already offering passkeys, and growing

Where a passkey is stored

two common arrangements, and what each one means day to day

A passkey is stored somewhere, and where it is stored affects where you can use it.

Where it lives What that means in practice
Inside one company's system Create a passkey on your iPhone and Apple keeps it, which covers your other Apple devices. On a Windows desktop at the office, that passkey is not available.
Device-bound These stay on the hardware that made them, sitting on a security key or inside one particular laptop. Replace that device and the passkey stays behind, so the site's account recovery process takes over.

A third option is covered in section 4: a passkey held in your password vault.

What this means for your business

The two situations are different. A device-bound passkey stays with its hardware. A passkey held in another company's system is still there, just not on the device in front of you.

For someone moving between a work laptop, a personal phone and more than one browser, where a passkey is stored affects how usable it is.

How LastPass handles passkeys

the same vault, the same prompts, on whichever device you are using

LastPass added general support for passkeys and stores them in the same vault as your passwords.

Passkeys saved in LastPass sync across your devices, browsers and operating systems, no matter which one you created them on. Make a passkey on your iPhone and it is waiting on the Windows desktop. Move to a new laptop and your passkeys arrive with everything else in the vault.

The process is one you already know

1 The site offers A site you use offers you a passkey. The prompt comes from the site itself.
2 You create it You choose to create one, and LastPass saves it to your vault.
3 LastPass fills it Next time you sign in there, LastPass offers to fill it, the same way it fills a password.

Before you start. Passkeys are created, stored and managed through the LastPass browser extension or mobile app, so both need to be up to date.

Businesses enable passkey support through a LastPass admin policy, so availability depends on how the organisation's account is set up.

Why keep passkeys in LastPass

one place for both kinds of login, available wherever you are working

Everything in one vault

Most sites still use passwords, so keeping passkeys in the same vault means both kinds of login sit in one place. The vault keeps track of it all and reports on weak and reused passwords.

It also keeps logins portable. A passkey held in Apple's or Google's system works only inside that ecosystem. A passkey held in LastPass is available on whatever computer, mobile and browser you are on.

The decision is where it gets stored

Passkey support is spreading, so the prompt to create one will come up more often. The decision at that point is where the passkey gets stored.

Saved to LastPass, it sits with the rest of your logins and is available everywhere. Give it a try.

Ready to take the next step?

Let's talk about where your business stands

No jargon, no hard sell. Just a clear, honest picture of your cyber security and IT, and what to do about it.

  • More than 20 years protecting Australian businesses
  • Not a single fully protected client has been breached since 2017
  • Client relationships averaging over 10 years