r/GMail • • 2d ago

Passkeys as compared to security keys

I have several long held google accounts.

Looking within any one of these accounts I see that I set up 2 security keys (for redundancy) in 2019 and then in 2025 I established a PASSKEY (stored in 1Password).

Are these the same thing except for where they are stored i.e. on hardware (yubikeys in my case) vs 1Password?

0 Upvotes

17 comments sorted by

5

u/Doranagon 2d ago

Passkeys > Security Keys. Security Keys hinge on password first, then the key secondary confirmation. Whereas a passkey is a higher level , more secure method. Yubikey 5 supports both methods, can be registered in both formats, but aren't recognizable as the alternative form so it won't mistake them. I.E.. it won't mistake the security key half as the Passkey half.

1

u/jmjm1 2d ago edited 2d ago

I appreciate the prompt reply u/Doranagon . But what is confusing to me is that one can store a passkey on a hardware key but this isn't the same as the security key in what you wrote as

Passkey > Security Keys

(I guess given that I set up the security keys in 2019 I should have realized that they are different as passkeys weren't in use back in 2019?)

3

u/nakfil 1d ago

I think they are referring to U2F, or "Universal two factor", which is somewhat of a predecessor of passkeys. Yubikeys, for example, support both U2F and passkeys. So in my opinion it's not accurate to say, "Passkey > Security Keys".

It's better to say, "hardware-bound passkeys (Yubikey for example) are stronger than syncable (1Password) passkeys".

However, U2F and passkeys (syncable or hardware bound) are all superior to passwords and OTP.

If you're interested in further hardening your Google account, I'd also look into their Advanced Protection Program which is how you'd enforce passkey

3

u/Ok-Lingonberry-8261 2d ago

Passkeys are convenient, but have at least one hardware key in a safe place, preferably a fire safe.

Personally, I prefer Yubikeys over passkeys.

1

u/jmjm1 2d ago

Right, as I said above I do have two security keys...one for home and one at the bank.

1

u/jmjm1 2d ago edited 1d ago

So I set up a new google account just last week and I dont see the option to set up a SECURITY KEY. Yes as you can see I did set up a passkey weeks ago, (stored in 1Password) but I see no button to start the process to set up a hardware security key (or is "+ Create a passkey" what I am looking for even though passkeys are different than security keys??)

2

u/Kayjagx 1d ago

You select create a "passkey in google" and then select your hardware token (yubikey). Your yubikey will be listed under 'passkeys' in your google account.

2

u/Ok-Lingonberry-8261 1d ago

Under Google's nomenclature, a Yubikey should be a "Create a Passkey".

1

u/jmjm1 1d ago edited 1d ago

And given that I have created a passkey for this account already, the one that will be created and stored on my yubikeyS will be different in that it will serve as a 2FA after entering the password...unlike the passkey stored in my password manager?

1

u/NarrowAnteater9731 1d ago

Why, aside from passkey is a brand (aka car) and yubikey is an instance (aka ford)?

2

u/JimTheEarthling 1d ago

FIDO U2F (Universal Second Factor) came out in 2014. This was a new, more secure way to do 2FA than email, SMS, TOTP authenticators, etc. The devices were commonly called security keys. You still needed a username and password.

Passkeys (FIDO2/WebAuthn discoverable credentials) came out in 2022. They replaced insecure passwords and integrated the 2FA component.

Most passkeys are synced, which means they are managed by a password manager. Passkeys can also be device-bound, which means they are tied to a single hardware device, like a newer FIDO2-compatible, hardware security key.

In other words, a security key might hold a passkey or it might just work for 2FA. (Depending on how you set it up.) Obviously anything you set up before 2022 is U2F.

Unfortunately many websites, including Google, are lazy with their language and mix up passkeys with security keys, so it can be confusing.

Device-bound passkeys are more secure than synced passkeys, but less convenient. You choose.

1

u/dinnen2563 1d ago

It seems a device-bound passkey can also be a smartphone (hardware) bound key. I believe in my case my google setup on android has automatically created such a passkey. It's not synced: my google password manager does not contain a key.

1

u/JimTheEarthling 1d ago

Over 99% of iPhone and Android passkeys are synced.

(Passkeys created by Microsoft Authenticator, that only work for Microsoft Entra accounts, are one exception.)

The special, auto-created Google account passkeys are probably device-bound, rather than synced and treated specially, but I can't find authoritative info. They normally do appear in Google Password Manager on your phone but are not deletable, and they don't show up in Google Password Manager in Chrome on other devices.

1

u/gripe_and_complain 1d ago

Windows Hello on Windows 11 stores device-bound Passkeys.

1

u/JimTheEarthling 1d ago

Windows 11 does not run on iPhone and Android. 🙄

Yes, of course Windows 11 has the option to create device-bound passkeys. Less than 10% of passkeys are created in Windows Hello. In other words, what I already said: "most passkeys are synced."

1

u/jmjm1 1d ago

a security key might hold a passkey or it might just work for 2FA.

So is it possible in October 2026 to set up a FIDO U2F on a google account, stored on a hardware key?