For the highest protection level (like ChatGPT Advanced Protection, with device-bound passkeys), you need backup passkey authenticators (security keys, Windows platforms with TPM, etc.) — if you lose all your keys, you lose the accounts. Add keys that support different platforms/USB ports. Higher security comes with inconvenience and a price.What happens if the device the passkeys are on, borks, due to a hardware issue. If you have to get a new device, laptop, how are you able to login to sites from the new PC? Do you need to use some kind of backup manager to sync from?
Most default setups today keep passwords and 2FA while offering passkeys as an alternative (for example, MT itself), so logging in from a new device isn't a problem. Using passkeys while retaining passwords and 2FA is primarily convenient (fast and reassuringly safe). The anti‑phishing protection is stronger than password managers because it can't be overridden, so it's safer too.
Password manager sync is meant for convenience. Passkey is like a very strong password (anti‑phishing with no override, no leaks from the service side), but they mostly authenticate without an additional 2FA, so if your password managers leak, there is no second line of defense. OTH, if you password managers leak because of a malware on your system, your authentication tokens on the machine are most likely leaked too.
Last edited:




