Passkeys: Are They Really Safe? Google and Microsoft Warn of Security Risks (2026)

Passkeys are the future of online security, right? Wrong, according to Google and Microsoft. These tech giants are warning that passkeys alone are not enough to protect your accounts from hackers. The issue lies in the recovery methods still attached to accounts, which can become a new attack surface even after passkeys are deployed.

Passkeys are supposed to replace passwords and stop phishing attacks. But as Microsoft says, "Each account is only as secure as its weakest credential." Passkeys are an improvement, but they don't eliminate the risk of phishing and other attacks. In fact, attackers are now targeting recovery flows and fallback credentials instead of passkeys.

Google and Microsoft are urging users to use two-step verification (2SV) in addition to passkeys. This includes Google Prompts and Authenticator apps, which provide an additional layer of security. SMS one-time codes should be avoided, as they are weaker and more susceptible to phishing.

The key takeaway is that passkeys are not a silver bullet. They must be complemented with strong recovery methods and user awareness. As Microsoft warns, "Eliminate phishable credentials entirely" to ensure your accounts remain secure. This is especially important as attackers shift their focus to recovery flows and fallback authentication methods.

In my opinion, the widespread adoption of passkeys is a step in the right direction, but it's not enough. We need to educate users about the importance of strong recovery methods and the risks associated with SMS codes. Only then can we truly move towards a safer online environment.

Passkeys: Are They Really Safe? Google and Microsoft Warn of Security Risks (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Aracelis Kilback

Last Updated:

Views: 6162

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Aracelis Kilback

Birthday: 1994-11-22

Address: Apt. 895 30151 Green Plain, Lake Mariela, RI 98141

Phone: +5992291857476

Job: Legal Officer

Hobby: LARPing, role-playing games, Slacklining, Reading, Inline skating, Brazilian jiu-jitsu, Dance

Introduction: My name is Aracelis Kilback, I am a nice, gentle, agreeable, joyous, attractive, combative, gifted person who loves writing and wants to share my knowledge and understanding with you.