Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.
But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.
I broke down how passkeys work, their strengths, and what’s still missing



if it undermines or circumvents my fifth amendment right not to testify against myself, then I’m not interested in ending the use of passwords.
You can set a pin on most passkey devices so that it doesn’t serve the authentication without it.