Password managers vs passkeys: where we actually are
The "versus" in the title is a trap. Passkeys genuinely fix the worst thing about passwords, which is that they can be phished, and as of October 2026 they are no longer a niche feature. But almost every account you own still has a password behind it, and the place your passkeys live is, in practice, a password manager. Here is where adoption, recovery and portability really stand, and what that means for the setup you should have this year.
What a passkey actually fixes
A password is a shared secret. You know it, the website stores a hash of it, and anyone who gets you to type it into a convincing fake page has it too. A passkey is a cryptographic key pair instead: the private half stays on your device and the website only ever holds the public half. When you sign in, your device signs a challenge, and it will only do that for the domain the key was created for. Apple's security documentation puts it plainly: the private key is never shared with the server, which is what makes passkeys "highly phishing-resistant"[11].
That domain binding is the whole point. NIST's current digital identity guidelines, SP 800-63B revision 4 (published August 2025), define phishing resistance as preventing secrets from being disclosed to an impostor verifier "without relying on the vigilance of the claimant"[2]. A one-time code from an authenticator app relies on your vigilance; you can be talked into typing it into the wrong page. A passkey cannot be, because the browser and the authenticator enforce the domain check below the level where you or a phishing page can interfere.
How much does that matter? Verizon's 2026 Data Breach Investigations Report found that, for the first time in its 19-year history, exploited software vulnerabilities (31% of breaches) overtook stolen credentials as the top way in[3]. Credential abuse as the first step fell to 13%, from 22% the year before, partly because of a reclassification (measured the old way it would have been 16%). Count credentials anywhere in the chain and they are still involved in 39% of breaches[4]. Credentials are losing their crown as the way attackers get in, and keeping it as the way they move around once inside.
Where adoption really is in 2026
The FIDO Alliance's World Passkey Day report, published May 7, 2026, estimates about 5 billion passkeys in use worldwide. Its consumer survey of 11,000 people across ten countries found 90% had heard of passkeys, 75% had enabled one on at least one account, and 49% use them regularly when offered[1]. The honest reading of those three numbers together: most people have tried a passkey, and about half actually reach for it when the option appears.
The platforms are pushing harder than the users. Microsoft made new consumer accounts "passwordless by default" from May 2025, reported roughly a million passkeys registered every day, and quoted a sign-in success rate of about 98% for passkeys against 32% for passwords, with passkey sign-ins around eight times faster than password plus multi-factor[6]. On the workplace side, passkeys became the default authentication method in Microsoft Entra ID on September 1, 2026, and Microsoft will stop offering its own SMS and voice codes on February 1, 2027[5].
Governments are saying it out loud, too. On October 6, 2026, the UK's Report Fraud service launched a campaign telling the public to switch to passkeys, after money stolen through hacked email and social media accounts rose from £1.2m in 2024/25 to £6.3m in 2025/26, with reports up 34% year on year. The same release cited a NordVPN survey of 4,896 UK adults in which 96% could describe a strong password but only 16% knew how to store one safely in a password manager[7]. That gap, between knowing what a good password is and having somewhere sensible to keep it, is the problem passkeys and managers are both trying to solve.
The password isn't going anywhere yet
Here is the part the launch posts skip. Adding a passkey to an account almost never removes the password from it. Google's own help page says that when you create a passkey "you still have the option to use your password to sign in"[12]. Microsoft lets existing users delete their password, but you have to go and do it[6]. Most sites, as of October 2026, keep the password as a permanent fallback and offer no way to turn it off. From an attacker's point of view, that account is exactly as phishable as before. The passkey made your sign-in nicer; it did not close the door. And the long tail of the internet has not added passkeys at all: your utility company, your kid's school portal and the forum you joined in 2011 are still password-only, and will be for years.
So the password manager is not a competitor to passkeys. It is the thing that makes the password era survivable while it winds down, and it is what the standards expect: SP 800-63B-4 says verifiers "SHALL allow the use of password managers and autofill", drops character-composition rules entirely, sets minimum lengths of 15 characters for a password used alone and 8 when paired with a second factor, and requires checking new passwords against breach lists[2]. Long, unique, random, and remembered by software is the official posture now.
If a site still forces a password: generate it rather than invent it. Toolkit's password generator builds long random passwords and passphrases entirely in your browser, nothing leaves the page, so you can paste the result straight into your manager. If you want the reasoning behind "length beats complexity", what makes a password strong walks through the entropy maths.
Synced passkeys move the risk, they don't delete it
Consumer passkeys are synced: Apple copies them between your devices through iCloud Keychain, Google through Google Password Manager, and third-party managers like 1Password, Bitwarden, Dashlane and Proton Pass through their own vaults. That is what makes losing a phone survivable. Apple says the sync is end-to-end encrypted with keys "not known to Apple", and that if you lose every device the escrow copy can be recovered with your iCloud sign-in, a code sent by SMS and your device passcode, with ten attempts before you have to call support[11].
Notice what just happened. The security of the passkey, which was supposed to be unphishable, now depends on an account recovery flow that involves an SMS and a six-digit passcode. A 2025 academic comparison of device-bound and synced passkeys by Büttner and Gruschka concluded that "the security of synced passkeys is mainly concentrated in the passkey provider"[13]. NIST agrees in its own way: syncable authenticators are allowed at its middle assurance level, AAL2, but "SHALL NOT be used at AAL3", because the private key has to be exportable for sync to work at all[2].
Provider risk is not hypothetical. In late 2022 an attacker stole LastPass's backups of customer vaults. The sensitive fields were encrypted with AES-256 under a key derived from each user's master password, so what the attacker got was ciphertext plus, in the clear, the website URLs for every entry[14]. Users with a long master password were fine. Users with a short one were, in effect, handed to an offline cracking rig. A vault of passkeys would have been protected the same way, and only as well as that one passphrase.
The practical conclusion is not "avoid syncing". For nearly everyone, a synced passkey that survives a dropped phone beats a device-bound one that doesn't. It is that the master password or platform account protecting the sync is now the most important secret you have, and deserves a passphrase and a hardware second factor more than any individual account does.
Portability: the lock-in problem is half solved
Until recently the strongest argument against going all-in on passkeys was that you could not take them with you. A passkey created in iCloud Keychain stayed in iCloud Keychain; switching managers meant re-registering every account. That changed this year. The Credential Exchange Protocol, a FIDO Alliance standard built by Apple, Google, Microsoft, 1Password, Bitwarden and others, lets a manager hand your passkeys directly to another app without ever writing them to a plain-text file. As of July 2026 it is live on iOS 26 and on Android 14 and later with current Google Play services[8].
The catch is in that sentence: mobile. 1Password's export documentation is blunt about it: "You can only export passkeys in 1Password for iOS and Android at this time", and on a desktop the only option is to create new passkeys on each site and save them elsewhere[9]. The wider platform picture is uneven too. The device support matrix at passkeys.dev, updated September 21, 2026, lists native synced passkeys on Windows as "Planned", with third-party managers only supported natively from Windows 11 25H2, and Linux limited to whatever the browser provides[10]. If your life is split between a Windows desktop and an Android phone, your passkeys will mostly live in the phone and in a browser extension, not in the operating system.
What to actually do this week
None of this argues for waiting. It argues for a specific order, because each step protects the one after it.
- Pick one password manager and commit. Built-in (Apple Passwords, Google Password Manager) if you live inside one ecosystem; a cross-platform one if you don't. The major ones all store passkeys and all speak the exchange protocol on mobile[8], so this is no longer a one-way door.
- Make the master secret the strongest thing you own. A long passphrase you can type from memory, never reused, plus a hardware security key or at least an authenticator app on the manager account itself. This is the secret the LastPass lesson is about[14].
- Add passkeys to the accounts that can take down the others. Primary email first, because it is the recovery address for everything else; then Apple, Google or Microsoft; then banking and anything with a card on file.
- Register a second passkey for the accounts you cannot afford to lose. A hardware key in a drawer, or a passkey in a second manager, so recovery never depends on one provider's SMS flow[11].
- Where a site lets you remove the password, remove it. Microsoft accounts allow this today[6]. Everywhere else, replace the password with a long random one from your manager so the fallback is at least not guessable.
- Know the lost-phone drill before you need it. On Google, you sign in from another device and remove the passkey registered to the lost one[12]. Check that you actually have another device signed in. If you don't, that is the gap to fix.
When not to follow this
If you share one device with family and no one has their own profile, a passkey tied to the device's face or fingerprint unlock is a passkey tied to whoever can unlock the device. Sort out separate user accounts first.
If you are in a high-risk role, a journalist, an activist, an admin for systems other people depend on, synced passkeys are the convenient option, not the strongest one. NIST reserves its top assurance level for keys that cannot be exported[2]; that means hardware security keys, with a spare, and the recovery flow written down and tested.
If your main computer runs Linux or an older Windows build, expect the browser extension experience rather than the operating-system one, and expect some sites' passkey prompts to assume a phone is nearby[10]. Worth knowing before you delete a password you can't get back.
Where we actually are, then: passkeys have crossed from promise to default on the big platforms, they solve phishing in a way nothing else does, and they have inherited the recovery and portability problems passwords always had, with half of those now fixed. The right setup in October 2026 is not passkeys instead of a manager. It is a manager you trust, protected like it is the only secret you have, with passkeys in it wherever a site will let you.
Sources
- FIDO Alliance — Five billion passkeys: FIDO Alliance reports mainstream global usage on World Passkey Day 2026, May 7, 2026, accessed October 2026
- NIST — SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management, August 2025, accessed October 2026
- Verizon — 2026 Data Breach Investigations Report (overview), accessed October 2026
- Descope — Verizon DBIR 2026: credential abuse is down, but not out (summary of the report's credential figures), accessed October 2026
- Microsoft Security Blog — Microsoft Entra ID security updates: passkeys are the default authentication method in Entra ID, July 13, 2026, accessed October 2026
- Microsoft Security Blog — Pushing passkeys forward: Microsoft's latest updates for simpler, safer sign-ins, May 1, 2025, accessed October 2026
- Infosecurity Magazine — Police urge passkey use after surge in cybercrime profits (UK Report Fraud campaign), October 6, 2026, accessed October 2026
- Bitwarden — July 2026 spotlight: your passkeys can now move freely (Credential Exchange Protocol on iOS 26 and Android), July 2026, accessed October 2026
- 1Password Support — How to export your data from the 1Password apps, accessed October 2026
- passkeys.dev — Device support matrix, updated September 21, 2026, accessed October 2026
- Apple Support — About the security of passkeys, accessed October 2026
- Google Account Help — Sign in with a passkey instead of a password, accessed October 2026
- Büttner & Gruschka — Device-bound vs. synced credentials: a comparative evaluation of passkey authentication (arXiv, ICISSP 2025), January 2025, accessed October 2026
- LastPass — Notice of recent security incident, December 22, 2022, accessed October 2026
Related: What makes a password strong? Entropy, length and passphrases · How to share a password or secret safely · Backing up your digital life properly: the 3-2-1 rule in practice