Journal / Technology

Technology

Passkeys, and the Recovery Problem Nobody Advertises

The industry numbers for passwordless login are genuinely good and they come from parties who sell authentication. The part they leave out is where every passkey deployment actually breaks.

10 min readResolution

Passwordless login stopped being a proposal and became a default. The FIDO Alliance reported an estimated five billion passkeys in use worldwide, with 75% of surveyed people having enabled one on at least one account and 68% of organisations deploying or actively deploying them for employee sign-in.1

The performance figures are good. In FIDO's Passkey Index, built from production sign-in data at nine large companies, passkey sign-ins succeeded 93% of the time against 63% for other methods, took 8.5 seconds against 31.2, and were associated with an 81% reduction in login-related help desk tickets.2

Before using any of that: the FIDO Alliance is an industry body whose members sell authentication. These are self-reported, aggregated numbers, not independently audited ones. They are directionally useful and they are not neutral.

reported sign-in success 93% passkey 63% other methods reported time to sign in 8.5s 31.2s figures self-reported by an industry body
fig. 01 — the industry figures, and who produced them

Why it is worth doing anyway

The argument does not rest on those numbers. It rests on what a passkey removes.

A password can be phished, reused, guessed and typed into the wrong page. A passkey cannot be phished in the ordinary sense, because the credential is bound to the domain — a lookalike site cannot elicit it. For a small company, where credentials are the entry point in most incidents and where nobody has time to run phishing training every quarter, that is a structural fix rather than a behavioural one.

Verizon's 2025 breach report puts the context plainly: ransomware appeared in 88% of breaches at small businesses against 39% at large organisations, and a non-malicious human element featured in 68% of breaches overall.3 Small companies are not targeted less. They are protected less.

The part nobody puts in the marketing

Account recovery is the weak link, and it has not been solved.

A passkey protects the front door. Every account also has a back door: what happens when the device is lost, replaced, or the employee leaves. That back door is almost always still an email link or an SMS code — the exact mechanisms passkeys were meant to replace.

Anna Pobletts, who leads passwordless work at 1Password, has put it directly: account recovery is the weak link, and right now it is mostly whatever already existed with passwords.

An account is only as strong as its weakest door, and the recovery door is usually the old one.

the account passkey: phishing-resistant recovery: email or SMS code the account is only as strong as its weakest door
fig. 02 — a strong front door and an old back door

The practical failures follow from that. Lose the only device holding the passkey and recovery may be difficult. Share a device between staff and you have shared the credential. Push a passkey requirement onto customers with a weak fallback and you generate lockouts — something large consumer platforms have already produced at scale.

What changed recently and actually matters

Two standards developments are worth knowing because they remove real objections:

  • NIST SP 800-63-4, finalised in July 2025, treats synced passkeys as meeting AAL2. If you have a compliance conversation, that is the reference.
  • Credential Exchange Format reached Proposed Standard status in August 2025, which addresses portability — the fear that adopting passkeys locks you into one password manager or platform.

A rollout for a company with no IT department

  1. Start with your own admin accounts, not with customers. The accounts that would end the company if compromised — domain registrar, hosting, banking, email admin — are the ones to convert first, and they belong to two or three people.
  2. Fix recovery before you fix login. For each account, write down what happens if the device is lost. If the answer is an email code, you have moved the problem rather than solved it. Recovery codes stored offline are unglamorous and they work.
  3. Never one device. Two enrolled devices per person, or a synced passkey through a manager the company controls. A single point of failure with better cryptography is still a single point of failure.
  4. Leave customer-facing login for last, and always as an option rather than a requirement. Forcing it produces support load you are not staffed for.
  5. Write down the offboarding step. When someone leaves, their enrolled device leaves with them. That step belongs in the same checklist as the laptop and the keys.

The honest summary

Passkeys are a real improvement and the strongest available answer to phishing. They are not the end of credential management — they move the hard part from "how do people log in" to "how do people get back in", and that second problem has fewer good answers and much less marketing behind it.

Adopt them. Just do the recovery design first, because that is where your incident will come from.

Further reading

Books that shaped this article, including the ones we disagree with. Where a work is popular rather than peer-reviewed, we say so.

Bruce Schneier — 2018
Security as a problem of incentives rather than of technology. Explains why the recovery path stays weak long after the login path is fixed.
Andy Greenberg — 2019
Reported rather than theoretical. Useful for understanding how credential compromise becomes everything else.

Resolution is a participant in the Amazon Services LLC Associates Program. As an Amazon Associate we earn from qualifying purchases — at no additional cost to you. Affiliate links never determine what appears on these lists: several of these books are here specifically because we think they are wrong in an instructive way.

References & notes

  1. FIDO Alliance, State of Passkeys 2026, published 7 May 2026. Underlying surveys by Sapio Research, April 2026: 11,000 consumers and 1,400 business decision-makers across ten countries. Industry-body data.
  2. FIDO Alliance, Passkey Index, launched 14 October 2025 with Liminal, built on production sign-in data from nine member companies. Self-reported and aggregated; not independently audited.
  3. Verizon, 2025 Data Breach Investigations Report — 22,052 incidents and 12,195 confirmed breaches analysed.
  4. NIST SP 800-63-4, finalised July 2025; FIDO Credential Exchange Format, Proposed Standard status, August 2025.
  5. Remarks on account recovery attributed to Anna Pobletts of 1Password in trade press coverage; a practitioner position, not a research finding.

Corrections are published inline and dated. Write to us if something here is wrong.

// weekly dispatch

One email. Every Tuesday.

The week's analysis, one tool we actually tested, and one behavioural pattern worth practising. Unsubscribe in one click.

// no spam · no resale · ~4 emails a month