Updated October 12, 2026. Google highlighted passkeys for Cybersecurity Awareness Month on October 8, 2026. Learn setup steps, phishing resistance and recovery tips.
Why Google is promoting passkeys now
On October 8, 2026, Google used Cybersecurity Awareness Month to encourage more people to sign in with passkeys. A passkey lets you authenticate through your device’s familiar unlock method, such as a fingerprint, face recognition or PIN, rather than typing an account password. Google’s announcement highlights both convenience and resistance to common phishing attacks. Passkeys are especially relevant because scammers can copy login-page designs, but a passkey is tied cryptographically to the genuine website or application.
How passkeys work behind the scenes
Unlike a traditional password shared with a service, a passkey uses public-key cryptography. A device securely holds private key material while a service uses the corresponding public key to verify authentication. When you sign in, the device proves possession of the private key after local authorization. The website does not need to receive your fingerprint or face scan. This design makes phishing-resistant authentication possible and also limits the harm from many forms of credential theft.
How to create a Google Account passkey
Start by visiting Google’s official passkey setup page at g.co/passkeys, then sign in to your own account. Follow the on-screen steps to create a passkey on a trusted device. You may be asked to verify ownership using your existing account settings. Before changing your sign-in routine, review account recovery information and keep your devices protected with a strong screen lock. Avoid clicking passkey setup links from unsolicited emails; open the official Google account security page yourself.
Benefits and practical limitations
Passkeys avoid the need to remember another complex secret and can reduce exposure to fake sign-in forms. However, security still depends on how devices are protected, how recovery is configured and what alternative login methods remain enabled. Sharing a device with someone who knows its unlock PIN can create risks. Support varies between websites and operating systems, and some people may still need a password during migration or account recovery.
A safer account checklist
Enable passkeys where supported, update your recovery email and phone details, turn on device encryption and keep software current. Review connected devices and active sessions periodically. For services that do not support passkeys, use a password manager and unique passwords with multifactor authentication. Organizations should update employee training to explain how modern sign-in flows differ from one-time codes and why account recovery remains part of the security strategy.
Frequently asked questions
Does Google receive my fingerprint? Google says biometric information stays on the device.
Can I use passkeys on multiple devices? Availability depends on your platform, account and passkey storage method.
Do passkeys eliminate every cyberattack? No. Malware, device compromise and social engineering still matter.
Source and further reading
Read the source announcement or report. This SenseCentral article includes original analysis and explains the limits of the available evidence.
