Introduction
In a digital world constantly chasing convenience, “passkeys” are being promoted as the next big leap beyond passwords. Tech giants promise us a future without forgotten passwords, phishing attacks, or clunky login forms. It sounds incredible. Yet, when you look a little closer, the picture becomes much more complicated.
After recently migrating my digital life from 1Password to Proton Pass, I found myself questioning whether passkeys are truly the upgrade they seem to be. In this article, I want to share why, despite the hype, passwords combined with 2FA (Two-Factor Authentication) remain the most reliable and resilient option for 2025.
The Promise of Passkeys
Passkeys use biometrics (Face ID, fingerprints) and device authentication to let you log into services without typing anything. Built on standards like FIDO2 and WebAuthn, they promise to eliminate password theft and phishing.
In theory, passkeys are:
- Safer (no password to steal)
- Faster (one-click authentication)
- Smarter (resistant to phishing sites)
Tech companies like Apple, Google, and Microsoft are rushing to integrate them across devices. Some password managers, like 1Password, are aggressively building passkey vaults.
The Hidden Risks
But what few talk about is the cost of that convenience:
- Cloud Dependency Most passkeys are stored in your iCloud, Google Account, or a third-party cloud service. If you lose access to that account, you might lose all your passkeys—with no easy recovery.
- Platform Lock-in Switching from iPhone to Android? Or from Windows to Linux? Your passkeys might not transfer easily. You could become tied to a platform longer than you want.
- Lack of Exportability In many cases today, you can’t export your passkeys easily. This creates a dangerous dependency where you don’t fully “own” your credentials.
- Immature Ecosystem Not every service supports passkeys yet. Many only offer basic password + 2FA security models. The “passkey world” is far from universal.
- Overconfidence Risk Because passkeys seem “more secure,” users might become less careful about backups, multi-device access, and account recovery options.
Why Password + 2FA Still Wins
Right now, a strong password + 2FA remains:
- Fully under your control (with vaults like Proton Pass, Bitwarden)
- Cross-platform (works on any device, any OS)
- Recoverable (with recovery codes and backup options)
- Auditable (you can see and manage your credentials manually)
It may not feel as “invisible” as a Face ID login, but it offers independence, resilience, and real ownership over your digital identity.
A Practical Approach for 2025
Here’s the strategy I’m personally using and recommending:
- Passwords + 2FA for all important services (email, bank, government, cloud storage)
- Passkeys only for low-risk accounts or where it’s impossible to avoid
- Backup everything (passwords and 2FA recovery codes)
- Choose open ecosystems that respect user independence (Proton, Bitwarden, etc.)
Technology evolves—and passkeys might eventually become safer and more portable. But until then, controlling your own credentials is not old-fashioned: it’s smart survival.
Closing Thought
In a world rushing to eliminate passwords, keeping control of your own authentication might just be the new superpower.
Would you trust your entire digital life to one cloud login?
For now, I’m keeping my keys—and my backups—in my own hands.
(To be continued…)
I’m Felipe Aguilera. I help brands and professionals improve their communication, design, and digital systems. Explore more at faguilera.com.