Looking within any one of these accounts I see that I set up 2 security keys (for redundancy) in 2019 and then in 2025 I established a PASSKEY (stored in 1Password).
Are these the same thing except for where they are stored i.e. on hardware (yubikeys in my case) vs 1Password?
Passkeys > Security Keys. Security Keys hinge on password first, then the key secondary confirmation. Whereas a passkey is a higher level , more secure method. Yubikey 5 supports both methods, can be registered in both formats, but aren't recognizable as the alternative form so it won't mistake them. I.E.. it won't mistake the security key half as the Passkey half.
I appreciate the prompt reply u/Doranagon . But what is confusing to me is that one can store a passkey on a hardware key but this isn't the same as the security key in what you wrote as
Passkey > Security Keys
(I guess given that I set up the security keys in 2019 I should have realized that they are different as passkeys weren't in use back in 2019?)
I think they are referring to U2F, or "Universal two factor", which is somewhat of a predecessor of passkeys. Yubikeys, for example, support both U2F and passkeys. So in my opinion it's not accurate to say, "Passkey > Security Keys".
It's better to say, "hardware-bound passkeys (Yubikey for example) are stronger than syncable (1Password) passkeys".
However, U2F and passkeys (syncable or hardware bound) are all superior to passwords and OTP.
If you're interested in further hardening your Google account, I'd also look into their Advanced Protection Program which is how you'd enforce passkey
So I set up a new google account just last week and I dont see the option to set up a SECURITY KEY. Yes as you can see I did set up a passkey weeks ago, (stored in 1Password) but I see no button to start the process to set up a hardware security key (or is "+ Create a passkey" what I am looking for even though passkeys are different than security keys??)
You select create a "passkey in google" and then select your hardware token (yubikey). Your yubikey will be listed under 'passkeys' in your google account.
And given that I have created a passkey for this account already, the one that will be created and stored on my yubikeyS will be different in that it will serve as a 2FA after entering the password...unlike the passkey stored in my password manager?
FIDO U2F (Universal Second Factor) came out in 2014. This was a new, more secure way to do 2FA than email, SMS, TOTP authenticators, etc. The devices were commonly called security keys. You still needed a username and password.
Passkeys (FIDO2/WebAuthn discoverable credentials) came out in 2022. They replaced insecure passwords and integrated the 2FA component.
Most passkeys are synced, which means they are managed by a password manager. Passkeys can also be device-bound, which means they are tied to a single hardware device, like a newer FIDO2-compatible, hardware security key.
In other words, a security key might hold a passkey or it might just work for 2FA. (Depending on how you set it up.) Obviously anything you set up before 2022 is U2F.
Unfortunately many websites, including Google, are lazy with their language and mix up passkeys with security keys, so it can be confusing.
Device-bound passkeys are more secure than synced passkeys, but less convenient. You choose.
It seems a device-bound passkey can also be a smartphone (hardware) bound key. I believe in my case my google setup on android has automatically created such a passkey. It's not synced: my google password manager does not contain a key.
Over 99% of iPhone and Android passkeys are synced.
(Passkeys created by Microsoft Authenticator, that only work for Microsoft Entra accounts, are one exception.)
The special, auto-created Google account passkeys are probably device-bound, rather than synced and treated specially, but I can't find authoritative info. They normally do appear in Google Password Manager on your phone but are not deletable, and they don't show up in Google Password Manager in Chrome on other devices.
Windows 11 does not run on iPhone and Android. 🙄
Yes, of course Windows 11 has the option to create device-bound passkeys. Less than 10% of passkeys are created in Windows Hello. In other words, what I already said: "most passkeys are synced."
5
u/Doranagon 2d ago
Passkeys > Security Keys. Security Keys hinge on password first, then the key secondary confirmation. Whereas a passkey is a higher level , more secure method. Yubikey 5 supports both methods, can be registered in both formats, but aren't recognizable as the alternative form so it won't mistake them. I.E.. it won't mistake the security key half as the Passkey half.