Passkeys Explained: A Practical Guide for Australians
A four-digit PIN and a text message used to be as good as security got for most Australians online. Passkeys, explained simply, are a sign-in method that swaps out the password, and often the follow-up SMS code too, for the fingerprint or face scan you already use to unlock your phone. myGov, Google, Apple and Microsoft already let you sign in this way, and so does at least one Australian bank, with more on the way.
We’ve spent a fair chunk of this year moving our own logins over, account by account, and the honest answer is that passkeys are both simpler and a little more confusing than the marketing suggests. Here’s what a passkey actually is, which Australian services support one right now, how the syncing works once you own more than one device, and what to do on the bad day your phone goes missing.
What a passkey actually is
A passkey is a credential built on public-key cryptography, the same broad idea that secures your banking traffic, but applied to logging in rather than to the connection itself. When you create one, your device generates two mathematically linked keys. The private key never leaves your phone, laptop or security key. The public key sits on the website’s server and is useless on its own. Signing in means proving you hold the private key, which you do by unlocking your device with a fingerprint, a face scan or a PIN, not by typing anything a scammer could copy off you.
The standard behind all this comes from the FIDO Alliance, the industry body that also built the older physical security-key standards banks and government agencies already use. That matters, because it means passkeys aren’t one company’s idea that everyone else has to copy. Apple, Google, Microsoft, myGov and your bank can all support the same passkey without agreeing on much else, because they’re building to one open standard rather than inventing their own.
How a passkey is different from a password and an SMS code
A password is a shared secret. You know it, and so does the server, which is exactly the problem. Copy that secret onto a fake login page and it works just as well for the scammer as it does for you. Passkeys remove the shared secret entirely. There’s nothing to type on a phishing site, because the private key is tied to the one genuine website it was created for and simply won’t respond to a convincing copy. That’s the part that actually matters, more than the convenience of not remembering another string of characters.
Two-factor codes sent by text message solve a narrower problem, and solve it badly. An SMS code still relies on a password up front, and the code itself can be intercepted, phished through a fake prompt, or bypassed with a SIM swap. We reckon most people vastly overrate how safe an OTP text makes them. It stops the laziest attacks and does very little against a determined one. A passkey isn’t a password plus a second step; it replaces both with a single proof that’s much harder to fake, which is worth remembering given how much of the current wave of phishing and scam activity aimed at Australians depends on tricking someone into handing over exactly what a passkey never produces.
The big accounts that already support passkeys
Google was one of the earliest large platforms to switch passkeys on for personal accounts, and it now nudges people toward creating one instead of typing a password, storing it in Google Password Manager and syncing it to any device signed into the same account. Apple built the same idea into iCloud Keychain from iOS 16 and macOS Ventura onward, so a passkey made on an iPhone turns up automatically on a Mac or iPad logged into the same Apple Account. According to Apple’s own support documentation, that sync is end-to-end encrypted, so even Apple can’t read the keys in transit. Microsoft has rolled passkeys out across personal accounts too, with Windows Hello handling the fingerprint, face or PIN check on a Windows machine.
None of that requires matching hardware. An Android phone can hold the passkey for a Microsoft account, and an iPhone can authenticate a sign-in on a Windows PC by scanning a QR code, a feature the FIDO standard calls cross-device authentication. In our experience that cross-device flow is the single biggest thing that makes passkeys workable for a household running a mix of brands, which is most households we know.
Where myGov and Australian banks stand right now
myGov was among the first government sign-in services anywhere to offer passkeys, and Services Australia’s own passkeys guidance lets you register one through Account Settings using your device’s biometrics, screen lock or a physical security key, with up to three passkeys allowed per account. That matters more than it sounds, because the ATO and the NDIS both require a stronger sign-in method than secret questions. myGov’s help pages warn plainly that removing your last passkey and dropping back to secret questions will unlink both of those services from your account.

Banking support is patchier. ubank was the first Australian bank to offer passkeys, launching them in its app in August 2024, and has since expanded the option to online banking as well; the bank’s own numbers, cited in a NAB media release, put adoption at around 90% of its digitally active app users choosing a passkey over a password. ANZ followed with a genuinely password-less option for ANZ Plus web banking, letting customers sign in with a passkey or an in-app approval instead of typing anything at all, as ANZ’s own announcement describes. NAB has flagged a multi-year plan to retire passwords group-wide. CommBank and Westpac, the two biggest banks by customer numbers, hadn’t switched passkeys on for everyday internet banking at the time of writing. We think that gap will start to look odd within a year or two, given the fraud reduction the smaller players are already reporting.
How syncing works across your phone, laptop and password manager
The point of a synced passkey is that it isn’t stuck on one device. Create one on your phone and, provided you’re signed into the same account elsewhere, it should already be available on your laptop or tablet without any extra steps. Apple devices sync through iCloud Keychain, Android and Chrome sync through Google Password Manager, and Windows machines can sync through a Microsoft account or a third-party manager. The catch is that syncing generally happens within one ecosystem, so a passkey created in iCloud Keychain doesn’t automatically show up in Google Password Manager on an Android phone.
That’s where a dedicated password manager earns its keep. Tools such as 1Password and Bitwarden can now store and sync passkeys themselves, independent of any single phone or laptop brand, which is genuinely useful if your household runs a mix of iPhones, Android phones and Windows PCs. If you’re weighing up whether to keep relying on your phone’s built-in option or move to something more portable, we’ve laid out the trade-offs in our own comparison of the major password managers. There’s also a non-synced option, a physical FIDO2 security key that plugs in or taps over NFC. It never leaves that one object, which is more secure against a compromised phone but means losing the key itself is a real problem rather than a minor inconvenience.
What to do if you lose your phone
A synced passkey survives a lost phone. Because the credential lives in your cloud keychain rather than only on the handset, signing into a replacement device with the same Apple, Google or Microsoft account should bring your passkeys back with it, once you’ve verified your identity through that account’s own recovery process. This is one area where we’d argue the marketing undersells the real risk: your passkeys are only as safe as the account they’re synced to, so a weak or reused password on your Apple Account or Google Account becomes the new single point of failure.
A few habits make the bad day less bad:
- Set a strong, unique password and, ideally, a passkey on the cloud account your other passkeys sync through, since that account is now the master key.
- Register more than one passkey where a service allows it, so a lost security key or a broken phone doesn’t lock you out entirely.
- Keep your account recovery details, such as a backup email and phone number, current on myGov, your bank and your major tech accounts.
- If a phone is lost or stolen rather than simply broken, remotely sign it out of your Apple, Google or Microsoft account as soon as you can, the same way you’d cancel a lost card.
If you’ve ever wondered whether your handset shows other warning signs beyond a lost passkey, our guide on spotting a compromised phone covers the symptoms worth acting on quickly.
Should you switch to passkeys now, or wait for your bank to catch up?
For Google, Apple, Microsoft and myGov, we’d say switch now. The setup takes a couple of minutes per account, it’s genuinely faster day to day, and it closes off the phishing tricks that still catch people out. For banking, the answer depends on who you bank with. ubank and ANZ Plus customers already have a real option worth taking. Everyone else is stuck waiting on their bank’s own timeline, and no amount of enthusiasm on our part changes that.
One thing we’d push back on: passkeys get sold as a security fix on their own, but most services still let you fall back to a password when a passkey isn’t available, and that fallback is exactly where the old problems creep back in. Until banks and big platforms are willing to switch the password off entirely, not just offer a passkey alongside it, treat a passkey as a very good upgrade rather than a finished job. Set one up where you can. Just don’t assume the password underneath it has stopped mattering.
Featured image: Photo: Tony Webster, CC BY 2.0.




