Why passkeys are hard to phish
A passkey replaces your password with a secret that lives on your phone or laptop and is tied to one exact website. When you sign in, your device checks the real web address before it does anything. Land on a look-alike scam page and the passkey simply refuses to work — there is no code or password for the scammer to grab and reuse.
That protection is real, and it is why passkeys are worth using. The catch is not the passkey. It is everything else your account still lets you sign in with.
The weak spot: your backup logins
When you set up a passkey, the older sign-in methods usually stay switched on — a password, a text-message code, an app code, or an email reset link. They sit there as a “just in case,” so you are not locked out if you lose your device.
Scammers know this. Instead of fighting the passkey, they steer you toward one of those weaker backups, because a code you can read or type is something you can be tricked into handing over. The passkey did its job; the scam just went around it.
The trick, in plain terms
The “downgrade” push: a fake login page quietly hides the passkey option and only offers “sign in with a code” or “use your password instead.” You follow along and enter the code — which the scammer types into the real site at the same moment.
The fake “security upgrade”: a message or pop-up says you must “re-register” or “add a new passkey.” Following it actually registers the scammer’s device on your account. And the help-desk call: someone posing as support asks you to read out a recovery code “to verify your identity.” In every case the passkey held — you were simply guided around it.
How to protect yourself
Be suspicious of any login that skips your passkey. If a page suddenly asks for a code or password when your passkey normally just works, stop, and open the site yourself from a bookmark or its app. Never read a code or recovery phrase to anyone — real support will not ask. And ignore “add a new passkey” prompts you did not start; only add passkeys from inside an app’s own settings.
Where a service allows it, turn off the weakest backups: drop text-message codes in favour of an app code or a second passkey. And keep your most sensitive files out of the login picture entirely — stored in encrypted storage on your own device, so even a hijacked online account exposes nothing.
Where Sealby fits in
Sealby keeps your private photos, notes, and files in a vault encrypted with AES-256 on your iPhone, unlocked only by you. It is not a login service and cannot manage your passkeys — and it does not claim to.
What it shares with good passkey habits is one idea: a lock is only as strong as its spare key. Keep what matters most behind a lock only you control, and treat any request to switch to a “backup” way in as a reason to slow down.
This is general education, not security advice. Scam tactics and account settings change over time and differ by service and device — check current, reputable sources and treat any unexpected sign-in step with caution.