TL;DR: Passkeys reduce phishing and credential theft, but recovery flows remain the weak point when accounts still rely on passwords, SMS codes, or email-based fallback checks, according to 1Kosmos citing Microsoft and Google. Strong identity assurance must extend to recovery, or attackers will route around passwordless controls.
Editorial analysis by NHI Mgmt Group, based on content published by 1Kosmos: “Google and Microsoft Say Passkeys Alone Arenât Enough, Suggest ID & Face Scan”.
Key questions
Q: What breaks when passkeys are used alongside weak fallback authentication?
A: The programme becomes only as strong as the fallback path.
Q: Why do weak recovery flows still matter after passkey adoption?
A: Because account takeover often follows the easiest trusted path, not the strongest one.
Q: How should security teams handle recovery for passkey-protected accounts?
A: They should govern recovery as a separate assurance flow, not a convenience feature.
Practitioner guidance
- Map every account recovery path Inventory password reset, device-loss recovery, help desk verification, and fallback factor flows, then compare each one against the assurance level of primary passkey authentication.
- Remove phishable fallback methods Retire SMS codes, email-only reset links, and knowledge-based checks wherever they remain attached to passkey-enabled accounts, because they reintroduce impersonation risk.
- Raise recovery to identity proofing standard Use government-issued ID verification and biometric re-verification for high-risk recovery events so that reset decisions rely on verified identity evidence, not convenience.
Bottom line: Passkeys improve authentication strength, but they do not remove compromise risk if weaker recovery methods stay in place.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passkey programmes fail at the recovery boundary, not at the cryptographic boundary. The control most organisations think they are buying is phishing resistance, but the actual programme outcome depends on whether recovery is equally governed. If account reset still accepts weaker factors, the passwordless architecture is only partially complete. Practitioners should evaluate the entire identity lifecycle, not just the passkey enrollment and login steps.
A few things that frame the scale:
- eBay's passkey data shows 55-60% of passkey adoption happens on mobile, against around 20% on desktop.
A question worth separating out:
Q: When is a passkey rollout not enough for identity security?
A: It is not enough when the surrounding recovery process still depends on legacy factors or ad hoc help desk decisions. At that point, the organisation has improved sign-in security while leaving account recovery as the easier compromise route.
👉 Read our full editorial: Passkeys alone do not close the account recovery attack path