{"id":9929,"date":"2026-08-24T15:00:16","date_gmt":"2026-08-24T12:00:16","guid":{"rendered":"https:\/\/handoli.com\/index.php\/2026\/08\/24\/why-do-passkeys-prevent-phishing\/"},"modified":"2026-08-24T15:00:16","modified_gmt":"2026-08-24T12:00:16","slug":"why-do-passkeys-prevent-phishing","status":"publish","type":"post","link":"https:\/\/handoli.com\/index.php\/2026\/08\/24\/why-do-passkeys-prevent-phishing\/","title":{"rendered":"Why Do Passkeys Prevent Phishing?"},"content":{"rendered":"<p>A reader writes in, asking:<\/p>\n<blockquote>\n<p>\u201cYou have said, and I have read elsewhere also, that passkeys are \u2018phishing resistant.\u2019 I\u2019m ready to believe that, because everybody \u2018in the know\u2019 says so, but I haven\u2019t really been able to wrap my head around WHY that\u2019s the case. Is that something you could write about?\u201d<\/p>\n<\/blockquote>\n<p>Broadly speaking, phishing happens in either of two ways:<\/p>\n<ol>\n<li>You somehow end up on a malicious website (one designed to <em>look like<\/em> your bank, email provider, etc.), and you don\u2019t realize it\u2019s not the real deal. So you enter your login credentials to sign in, and now the bad guy has collected those credentials.<\/li>\n<li>As part of a communication (e.g., a text or phone call from the bad guy, who convinces you that they work at your bank or some other place where you have an account), you are tricked into sharing your login credentials (e.g., sharing them by text or stating them over the phone).<\/li>\n<\/ol>\n<p>Passkeys are inherently strong against both of those types of attacks.<\/p>\n<h3>Phishing via Malicious Website<\/h3>\n<p>Passkeys are <strong>domain-bound<\/strong>, which means that when you create a passkey, saved as a part of that passkey is the specific domain that it\u2019s used for. For example, if you bank with Chase, and you create a passkey while signed in on Chase.com, that passkey is specifically bound to the domain Chase.com.<\/p>\n<p>So if you someday unknowingly end up on a malicious website that is designed to <em>look<\/em> like Chase.com, your passkey simply won\u2019t work. The \u201caccidentally enter your login credentials into a malicious website\u201d scenario simply doesn\u2019t exist with a passkey in the way that it does with a password.<\/p>\n<p>Note, however, that if you have a website for which you can sign in via passkey\u00a0<em>or<\/em> via password, then just because you\u00a0<em>have<\/em> a passkey doesn\u2019t mean you\u2019re now invulnerable to being tricked into entering your password into a malicious website.<\/p>\n<p>But even still, the passkey provides some useful protection. If you normally sign in with a passkey, and one day that passkey does not load, do not assume that your passkey \u201cisn\u2019t working\u201d and that you should enter your password instead. Rather, treat your passkey not loading as a <em>valuable and critical signal<\/em> that you might be on the wrong website. Rather than entering your password, it\u2019s probably best to start over: in the location bar of your browser type the known URL of the website you\u2019re intending to visit (or use a bookmark). To be clear, passkeys <em>can<\/em> sometimes fail to load for benign reasons, but the safe response is the same either way: re-navigate to the website via a known-safe method.<\/p>\n<h3>Phishing via Malicious Communication<\/h3>\n<p>In normal usage, the user doesn\u2019t actually <em>see<\/em> the secret part of the passkey (i.e., the private key of the private\/public key pair). It\u2019s saved in your password manager (or on a security key such as a YubiKey). And when you click a button to log in with a passkey, all of the magic (i.e., your device accessing your private key, using it to create a digital signature, and sending that digital signature to the website you\u2019re logging into) happens behind the scenes, out of the user\u2019s view. The user doesn\u2019t even\u00a0<em>have<\/em> an easy way (or, in some cases, <em>any<\/em> way) to share the secret part. And if you don\u2019t have a way to share it, you can\u2019t be tricked into sharing it with a bad guy.<\/p>\n<h3>What is the Best Age to Claim Social Security?<\/h3>\n<p>Read the answers to this question and several other Social Security questions in my latest book:<\/p>\n<table border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col span=\"2\" width=\"75\"\/><\/colgroup>\n<tbody>\n<tr>\n<td width=\"158\"><a href=\"http:\/\/www.amazon.com\/dp\/1950967190\/\"><img decoding=\"async\" class=\"alignleft size-full wp-image-6696\" title=\"Book8FrontCovertilted150x200\" alt=\"\" src=\"https:\/\/www.obliviousinvestor.com\/wp-content\/uploads\/2014\/04\/NewBook8CoverTiltedScaled2.png\" width=\"158\" height=\"211\"\/><\/a><\/td>\n<td width=\"350\"><em><strong>Social Security Made Simple: Social Security Retirement Benefits and Related Planning Topics Explained in 100 Pages or Less<\/strong><\/em>\n<ul>\n<li><a href=\"http:\/\/www.amazon.com\/dp\/1950967190\/\" target=\"_blank\">Click here to see it on Amazon<\/a>.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>Disclaimer:<\/b>Your subscription to this blog does not create a CPA-client or other professional services relationship between you and Michael Piper or between you and Simple Subjects, LLC. By subscribing, you explicitly agree not to hold Michael Piper or Simple Subjects, LLC liable in any way for damages arising from decisions you make based on the information available herein. Neither Michael Piper nor Simple Subjects, LLC makes any warranty as to the accuracy of any information contained in this communication. The information contained herein is for informational and entertainment purposes only and does not constitute financial advice. On financial matters for which assistance is needed, I strongly urge you to meet with a professional advisor who (unlike me) has a professional relationship with you and who (again, unlike me) knows the relevant details of your situation.<\/p>\n<p>You may unsubscribe at any time by clicking the link at the bottom of this email (or by removing this RSS feed from your feed reader if you have subscribed via a feed reader).<\/p>","protected":false},"excerpt":{"rendered":"<p>A reader writes in, asking: \u201cYou have said, and I have read elsewhere also, that passkeys are \u2018phishing resistant.\u2019 I\u2019m ready to believe that, because everybody \u2018in the know\u2019 says so, but I haven\u2019t really been able to wrap my head around WHY that\u2019s the case. Is that something you could write about?\u201d Broadly speaking, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9930,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[1],"tags":[],"class_list":["post-9929","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-explore"],"_links":{"self":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts\/9929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/comments?post=9929"}],"version-history":[{"count":0,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/posts\/9929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/media\/9930"}],"wp:attachment":[{"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/media?parent=9929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/categories?post=9929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/handoli.com\/index.php\/wp-json\/wp\/v2\/tags?post=9929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}