What Passkeys Don't Protect | Elacity
Passkeys are Microsoft's default sign-in and five billion are now in use. Passwordless won the login. It never touched the session behind it, or the keys a platform still holds for you.
Microsoft Made Passkeys the Default. What Passkeys Don't Protect Is Everything Behind the Login.
You did the responsible thing. You turned on a passkey, and the phishing email that would have drained your account last year now bounces off a login with no secret to steal. Then someone copies the session that login created, replays it from their own machine, and walks in behind you. Your passkey never fires again.
Passwordless just crossed from campaign to default. Microsoft began making passkeys the default sign-in experience in Entra ID on September 1, 2026, and the FIDO Alliance now counts roughly five billion passkeys in use, with three in four people having turned one on. This is real progress, and it closes a wound that bled for thirty years. It is also the moment to be exact about what passkeys don't protect.
What Passkeys Don't Protect
A passkey secures one event: the instant you prove who you are. It swaps a secret you could hand over for a challenge only your device can answer, so there is nothing left to phish. That is the entire job, and it does it well.
Attackers noticed. Verizon's latest breach report found vulnerability exploitation overtook stolen credentials as the top way into a network, at 31% of breaches, the first time in the report's history that the login was not the softest target. The authors are blunt about the cause: wider passkey and phishing-resistant MFA adoption cut the value of a stolen password, so intruders shifted to the software you are already signed into.
The session is where they went. Once your login succeeds, the system hands your browser a token that means this one is allowed, and a stolen token replays a completed login without ever facing the prompt again. The passkey guarded the door. It has no say over the room.
The Door Was Never the Whole House
Two things live behind that door, and a passkey touches neither.
The first is authority. The second you are inside, every app running as you inherits your reach: your files, your network, your ability to spend. Nothing asked them to justify a single action. This is ambient authority, the quiet assumption that a program acting as you may do anything you may do, and it is why one hijacked session or one poisoned file can move sideways through everything you own.
The second is custody. A passkey proves identity, but it does not hold the keys to the things you actually own: the file, the model, the song, the record. On today's internet those keys sit with a platform, so proving you are you just asks the platform, politely, to act for you. We have written about why a credential that sits still keeps losing and, before that, how you can own something without ever storing the secret that controls it. Passwordless login is the front of that same idea. The back of it is still unbuilt for almost everyone.
Elacity Carries the Passkey Principle Past the Login
The passkey works for one reason: the secret is used, never parked. Elacity takes that single rule, no stored secret, and runs it through the two places a passkey stops. This is the layer we call Social Architecture: identity and authority built so that being you never means handing someone the keys to you. It runs on ElastOS, the open-source runtime where your own machine is the Source of truth and the cloud is a guest.
1. Keys Used, Never Owned
The key that decrypts what you bought, or signs on your behalf, exists in the clear for a fraction of a second, inside a sealed sandbox, welded to one action, then wiped. There is no session secret left in a browser for an infostealer to copy, because there is no standing secret to find. A passkey removes the password. This removes the token behind it.
2. Zero Ambient Authority
Nothing you run, no app, no script, no agent, can touch your files, your network, or your money until you grant a specific, narrow, expiring permission. Revoke it and the action stops mid-flight. Being logged in grants nothing on its own, so a hijacked session inherits no blast radius, because there was never any ambient reach to inherit. The system fails closed.
3. Custody You Hold, Not a Platform That Vouches for You
The key that unlocks what you own is split across an owned quorum of independent machines, a two-of-three threshold where each one re-checks your on-chain rights before releasing its share. No single operator, Elacity included, can rebuild it alone. This is trust-minimised, not magic: a colluding quorum could in principle reconstruct a key, which is exactly why the design spreads the trust rather than asking you to extend it. Your passkey says you are you. The quorum makes you the only party who can open the thing.
The Same Principle, Carried All the Way Down
Passkeys ended the era of the stealable password, and that is worth celebrating. The stealable session, and the platform that still holds your keys, are the next things to end. The rule does not change as you go deeper: never store the secret that controls what is yours.
Get ElastOS and hold your own keys, on a computer that treats the cloud as a guest.