A reader writes in, asking:
“You have said, and I have read elsewhere also, that passkeys are ‘phishing resistant.’ I’m ready to believe that, because everybody ‘in the know’ says so, but I haven’t really been able to wrap my head around WHY that’s the case. Is that something you could write about?”
Broadly speaking, phishing happens in either of two ways:
- You somehow end up on a malicious website (one designed to look like your bank, email provider, etc.), and you don’t realize it’s not the real deal. So you enter your login credentials to sign in, and now the bad guy has collected those credentials.
- As part of a communication (e.g., a text or phone call from the bad guy, who convinces you that they work at your bank or some other place where you have an account), you are tricked into sharing your login credentials (e.g., sharing them by text or stating them over the phone).
Passkeys are inherently strong against both of those types of attacks.
Phishing via Malicious Website
Passkeys are domain-bound, which means that when you create a passkey, saved as a part of that passkey is the specific domain that it’s used for. For example, if you bank with Chase, and you create a passkey while signed in on Chase.com, that passkey is specifically bound to the domain Chase.com.
So if you someday unknowingly end up on a malicious website that is designed to look like Chase.com, your passkey simply won’t work. The “accidentally enter your login credentials into a malicious website” scenario simply doesn’t exist with a passkey in the way that it does with a password.
Note, however, that if you have a website for which you can sign in via passkey or via password, then just because you have a passkey doesn’t mean you’re now invulnerable to being tricked into entering your password into a malicious website.
But even still, the passkey provides some useful protection. If you normally sign in with a passkey, and one day that passkey does not load, do not assume that your passkey “isn’t working” and that you should enter your password instead. Rather, treat your passkey not loading as a valuable and critical signal that you might be on the wrong website. Rather than entering your password, it’s probably best to start over: in the location bar of your browser type the known URL of the website you’re intending to visit (or use a bookmark). To be clear, passkeys can sometimes fail to load for benign reasons, but the safe response is the same either way: re-navigate to the website via a known-safe method.
Phishing via Malicious Communication
In normal usage, the user doesn’t actually see the secret part of the passkey (i.e., the private key of the private/public key pair). It’s saved in your password manager (or on a security key such as a YubiKey). And when you click a button to log in with a passkey, all of the magic (i.e., your device accessing your private key, using it to create a digital signature, and sending that digital signature to the website you’re logging into) happens behind the scenes, out of the user’s view. The user doesn’t even have an easy way (or, in some cases, any way) to share the secret part. And if you don’t have a way to share it, you can’t be tricked into sharing it with a bad guy.
Among people who read personal finance books, many save a high percentage of their income through most of their careers. One thing that eventually happens for some such people is that they reach a point at which they realize they have not only saved “enough,” they have saved “more than enough.” Their desired standard of living in retirement is well secured, and it’s likely that a major part of the portfolio is eventually going to be left to loved ones and/or charity. And that realization raises a whole list of new questions and concerns.
This book’s goal is to help you answer those questions.