The industry crossed five billion passkeys this year, but "we deployed passkeys" and "we killed the password" are different sentences.
A passkey is bound to the real site's domain, so on a phishing clone at paypa1-secure.com the browser sees the wrong origin and the key never fires: there is no secret to type. Genuine, not hype. The catch is the back door: 57 percent of organizations that deployed passkeys still keep a phishable fallback behind them, and a passwordless front door with a phishable back door is still phishable.
Close your own back door:
- Turn on a passkey for one account you care about, email first
- Delete the SMS code and the security questions
- Kill the backup you set up in 2014 and forgot
The front door was never really the problem.






