Home The Blog Passwords, padlocks, and passkeys: a plain-English guide to logging in better

Passwords, padlocks, and passkeys: a plain-English guide to logging in better

You’ve probably started seeing the word “passkey” popping up on websites and apps recently. Maybe your phone offered to create one and you tapped “Not now” because it sounded complicated. Don’t worry — you’re not alone. But it’s worth understanding what they are, because passkeys are genuinely one of the better things to happen to online security in years.

Let’s start with an analogy. Stick with me — it’ll all make sense.

The password problem: shouting your secret across the room

When you log in with a traditional password, here’s roughly what happens: you type your secret word, and it gets sent across the internet to the website, which checks it matches what they’ve got stored. Simple enough.

The problem? You’re transmitting the secret itself. It’s like standing in a crowded room and shouting your PIN number to your bank. Even if nobody’s listening right now, you’re taking a risk every single time. And if the website gets hacked and their list of passwords leaks — well, there goes your account. Possibly several accounts, if you’re a “same password everywhere” person (no judgement, we’ve all been there).

Encryption: the locked box upgrade

Modern websites don’t actually transmit passwords in plain text anymore — they use encryption. Think of it like this: instead of shouting your secret across the room, you put it in a locked box, and both you and the website have a copy of the key to open it.

Better! But there’s still a weak point: at some stage, the key had to be shared. And the website still holds something sensitive. If their systems get breached, attackers might still find a way to unlock things.

Passkeys: the padlock you never hand over

Here’s where passkeys do something clever. Imagine you have a padlock that only you can close, and a key that never leaves your possession. When you sign up to a website, you give them a copy of your padlock — but not your key. They keep the padlock on file. That’s it.

When you want to log in, the website sends you an empty box and says: “Lock this.” You lock it with your padlock. The website receives the locked box, checks it with the padlock they have on file, and — because only your padlock could have closed it — they know it’s really you. You’re in.

Notice what just happened: nothing secret was ever transmitted. No password crossed the wire. The website never had your key. Even if they get hacked, the attacker walks away with a pile of padlocks — completely useless without the keys to match.

“But where does my key actually live?” — On your device. Your phone, laptop, or tablet stores it securely, usually protected by your fingerprint or face ID. You never see it, and it never goes anywhere.

What this means in practice

When a site supports passkeys, logging in looks something like this: you visit the site, tap “sign in with passkey,” your phone asks you to confirm with your fingerprint or face, and that’s it. No password to remember. No password to forget. No password to have stolen.

Phishing attacks — where a fake website tricks you into handing over your password — also stop working. Your device will only use the passkey with the real website it was created for. A convincing fake doesn’t get a look in.

The short version

Password

Your secret crosses the internet every time

Encryption

Secret travels in a box, but a key still had to be shared

Passkey

No secret ever leaves your device. The website gets a padlock, not a key

Passkeys aren’t perfect — support is still rolling out across the web, and you’ll need your devices to cooperate. But next time a site offers you one, it’s genuinely worth saying yes.

Your future self, who won’t have to click “forgot password” ever again, will thank you.

Leave a Comment

Leave a Comment