Summary

I stopped using passwords and switched to passkeys as a safer and faster alternative. Since then, the numbers have only grown, now standing at five billion passkeys, as reported by the FIDO Alliance. But the growth hides a coverage gap: passkeys are still a first-class option layered on top of passwords right now, not a complete replacement for them. Why passkeys haven’t fully replaced passwords yet Adoption is growing, but the gap hasn’t closed The numbers say passkeys are winning. About 48% of the top 100 websites now support them, and over two-thirds of consumers have turned one on somewhere. When passkeys work, FIDO’s 2025 data puts the login success rate at 93%, against 63% for other methods, with logins landing roughly 73% faster. But passwords are still the most common way of logging in for most people. Why? The biggest reason passkeys haven’t fully replaced passwords isn’t the cryptography; it’s what happens the moment you step outside the one device everything was set up on. Face ID on my iPhone feels effortless, but hop onto a work laptop or a shared family computer, and that smoothness disappears fast. I’ve had to scan a QR code, approve a prompt on another screen, or just guess which vault, iCloud or Google Password Manager, holds the passkey I need. I noticed this most clearly the week I set up a phone. My Google and Microsoft passkeys, created on my laptop, simply weren’t there. I had to fall back on my password just to get logged in far enough to register a fresh passkey for the new machine, which can feel like a step backward for a system that’s supposed to be more convenient than what it replaced. That’s the gap the FIDO Alliance is trying to close with its new Credential Exchange standards, which finally let you move passkeys between password managers instead of being stuck wherever you first created them. It’s a real fix, but it’s still rolling out one platform at a time, and until it reaches all of them, passwords remain the one login method that works everywhere, every time, with zero setup. Why people who have passkeys still fall back on passwords The comfort of a login routine you already know Even after setting up passkeys everywhere I could, I still catch myself typing a password out of habit. It’s not that the passkey failed; it’s that the old routine is simply faster to trust. A forgotten password has a fix everyone already knows by heart: click forgot password, check your email, reset it, done. Passkeys don’t have that same muscle memory built up yet, so the first question most people ask is “what happens if I lose my phone?” This skepticism isn’t entirely irrational. The NCSC flags recovery as a genuine risk with passkeys, since attackers can simply target the recovery path instead of trying to steal the credential itself. I ran into a version of this myself while researching this piece: the biggest catch with passkeys was never the everyday sign-in; it’s the machinery underneath- the sync account, the recovery method, the device ecosystem- that you only think about once your phone dies or you switch platforms. There’s also the matter of trust built one bad experience at a time. One app nails the passkey flow in a single tap. The next throws up a QR code or an unfamiliar step, and suddenly the whole idea feels less predictable than it should. That unevenness teaches people to distrust the new way, even though passkeys succeed more often than passwords when they do work. It’s not that passkeys fail technically. It’s that the moment something feels uncertain, people default to the login method they’ve trusted for twenty years. Why even “passkey-ready” sites still ask for a password Eligible isn’t the same as enrolled FIDO’s 2025 data shows 93% of user accounts are technically eligible for a passkey, but only 36% have one set up, and just 26% of sign-ins use one. A site can call itself passkey-ready because the infrastructure technically supports it, while most of its real users still don’t have a passkey enrolled, which means a password prompt is the only option that works for them. Sites also keep passwords around on purpose, as a safety net. Because account recovery matters even more once passkeys are in the mix, since attackers may target that fallback route instead, most services hedge their bets by leaving password sign-in alive rather than fully retiring it. Nothing about the current rollout forces anyone to remove passwords once passkeys get added; the two are layered on top of each other, and the site gets to call itself modern either way. So a site can proudly support passkeys while a password field remains the universal fallback for the roughly three-quarters of sign-ins that aren’t happening through one yet. Until passkeys feel as boring and predictable as typing a password, sites have every incentive to keep that door open. Passkeys are the future, even if they’re still a little way off Five billion passkeys in, I don’t think this is a distant technology anymore. It’s a present, practical replacement, and one that happens to be better for my security and better for the provider’s liability at the same time. Passwords just haven’t finished their exit yet.

By Tashreef Shareef

Original Article