Passkeys Reshape Account Security
Coverage from PCMag, The New York Times, and others

Passkeys are emerging as a more phishing-resistant alternative to passwords by using device-held cryptographic credentials, while password managers and two-factor authentication remain important during the transition.
Major platforms support passkeys, but adoption is uneven and many services still require passwords. Passkeys reduce the value of stolen password databases but do not prevent account takeover through malware, stolen browser cookies, weak recovery processes, or loss of access to registered devices.
The story is reframed from passkeys broadly replacing passwords to an uneven transition requiring password managers, two-factor authentication, and fallback credentials. The security benefits and remaining session-theft and recovery risks are otherwise reinforced rather than materially changed.
The story has broadened from passkeys as a password alternative into a more explicit account-security transition centered on device-bound authentication, session-cookie abuse, and weaker recovery channels. The updated version also adds new actors and a stronger operational framing, making the risks and tradeoffs more concrete.
