SecurityQ&A
Are Passkeys More Private, or Just More Secure?
Passkeys stop phishing and breaches, but does that make them more private? Here's what a site learns, how synced passkeys work, and the tradeoffs.
Passkeys are replacing passwords on sites from Google to your bank, and the pitch is always the same: faster, safer sign-ins. Are passkeys more private than passwords, or just more secure? The two questions have different answers, and the difference matters if you're deciding how much to trust the technology with your identity.
Are passkeys more private than passwords, or just more secure?
Security and privacy are separate properties here, and the W3C WebAuthn specification, the technical standard behind passkeys, treats them that way on purpose, with distinct sections for each. Security is whether your credential can be stolen or phished. Privacy is what leaks to a website, a platform, or other sites watching you move around the internet.
Passkeys are unambiguously more secure: there's no password to type, guess, or steal. FIDO Alliance defines a passkey as a credential "based on FIDO standards, that allows a user to sign in to apps and websites with the same process that they use to unlock their device (biometrics, PIN, or pattern)." With passkeys, "users no longer need to enter usernames and passwords or additional factors." That kills phishing and password-reuse attacks in one move. Privacy is more of a mixed bag, laid out below.
What does a website actually learn when you sign in with a passkey?
A passkey is a public/private key pair. Your device keeps the private key; the website only ever gets the public key. Google's developer documentation puts it plainly: "Only the public key is stored by the site, but this alone is useless to an attacker." Apple describes the same design in its passkey security documentation: "No shared secret is transmitted, and the server does not need to protect the public key." A breach at the website no longer hands attackers anything reusable elsewhere. For more on what encryption does and doesn't hide from a service provider, see our explainer on what end-to-end encryption actually protects.
How do synced passkeys work, and who can see them?
Many passkeys today are "synced," copying private keys across a person's own devices through a phone or laptop maker's account system. The WebAuthn spec describes this: "a consumer-centric Relying Party can leverage the authenticator built-in to a user's devices to provide phishing-resistant sign in using multi-device credentials (commonly referred to as synced passkeys)." Apple syncs through iCloud Keychain, and its support page describes that sync as end-to-end encrypted, using strong cryptographic keys Apple itself does not have, and recoverable even if someone loses every device. So your keys do leave the device — but in Apple's case only inside an end-to-end encrypted channel Apple itself cannot read. Google and Microsoft sync passkeys through their own account systems, and each publishes its own security documentation; don't assume an identical design without checking it.
Not every passkey syncs this way. The UK's National Cyber Security Centre defines a single-device passkey as one that is unable to leave the device it was created on — it cannot be exported, shared, or synchronized — and separately defines a synced one as "A FIDO2 credential on a commodity device (phone, tablet, laptop) that is also synchronised through a sync fabric." A hardware security key is the single-device kind; many phone and browser passkeys are the synced kind.
Do passkeys stop websites from tracking you across sites?
Yes, and this is the clearest privacy win. The WebAuthn spec requires that "Relying Parties are not able to detect any properties, or even the existence, of credentials scoped to other Relying Parties." A credential made for one site cannot be read by another. Google's developer documentation says: "The same passkey is never used with more than one site." Microsoft's Windows passkey documentation makes the same point about FIDO protocols generally, saying they "prioritize user privacy, as they're designed to prevent online services from sharing information or tracking users across different services." That doesn't stop other tracking methods, like the browser and device fingerprinting covered in how sites track you even without cookies — passkeys just aren't one of them.
Can your biometric data leak through a passkey?
No. A fingerprint or face scan never leaves the device and never reaches the website; it only unlocks the device's stored private key locally. Google's developer documentation states "the user's biometric information is never revealed to the website or the app" and "biometric material never leaves the user's personal device." Microsoft's Windows documentation says the same about its own unlock factor: "any biometric information used in the authentication process remains on the user's device and isn't transmitted across the network or to the service." The site never sees biometric data — only proof that a device's private key was unlocked.
What are the privacy tradeoffs of passkeys?
The tradeoffs sit less in the sign-in itself and more in what surrounds it. Syncing a passkey means trusting one company's account ecosystem to store and recover private keys, as is the case with Apple's iCloud Keychain, which Apple itself cannot read. The NCSC still advises users of synced passkeys to keep their sync fabric account protected against phishing and to set up a secure recovery option, because a compromised Apple, Google, or Microsoft account could expose every synced credential behind it. Choosing a hardware security key avoids that dependency, but the same guidance places the burden of keeping backups of a single-device credential on the user, since nothing copies automatically if the key is lost. Microsoft's documentation also notes that Windows now asks people to approve access app by app, so no application can reach stored passkeys without an explicit prompt. Passkeys fix the parts of a login that a stolen password used to expose, without touching the separate question of how much a phone or laptop maker already knows about its owner.
Sources
- W3C WebAuthn specification w3.org
- FIDO Alliance fidoalliance.org
- developer documentation developers.google.com
- passkey security documentation support.apple.com
- National Cyber Security Centre ncsc.gov.uk
- Windows passkey documentation learn.microsoft.com