Account Recovery
Device Loss: Synced Passkeys vs Romanticized MFA
September 8, 2026 · 6 min read

One of the most common objections to passkeys is simple: “If I lose my phone, I lose everything.” It sounds decisive. It also quietly compares a real passkey setup to an idealized version of traditional MFA that few people actually practice.
The UK NCSC comparison of traditional credentials and FIDO2 for personal use walks through the full credential lifecycle—including recovery after device loss—and finds that synced passkeys are at least as available as real-world MFA, while remaining far harder to phish.
The fear: “If I lose my phone, I lose everything”
Phone loss is a real life event: theft, a cracked screen that never boots again, or a device left in a taxi. Because passkeys live on authenticators, people reasonably ask what happens next.
The important question is not “can any credential system survive losing every copy of every secret?” It is “how does this system behave when one device disappears, and how does that compare with the MFA I already use?”
Comparing to idealized MFA that people don’t actually practice
Critics often stack passkeys against a fantasy MFA stack: a long unique password you never reuse, a hardware TOTP token you never lose, perfect SIM hygiene, and a recovery flow you never need. Real users rarely live there.
In practice, many people reuse passwords, store them in the same cloud vault they would use for passkeys, receive SMS or push approvals on the same phone they fear losing, and rely on email “forgot password” when something breaks. That is the fair baseline—not a museum piece of perfect MFA.
Once you compare like with like, the availability story for synced passkeys stops looking uniquely fragile.
How synced passkeys recover after one device is lost
By the NCSC’s definition, a passkey is a FIDO2 credential that synchronises through a vendor sync fabric (Apple, Google, Microsoft, or a compatible password manager). If you already have another enrolled laptop, tablet, or phone in that fabric, losing one device does not erase the credential.
If the lost phone was your only enrolled device, you still recover by signing into the sync fabric on a replacement or temporary device and restoring the vault—the same pattern password-manager users already depend on. You are not permanently locked out simply because one handset is gone.
That is the core availability claim: one lost device is not “everything,” as long as the sync account itself remains reachable and protected.
Single-device passkeys / FIDO tokens: enroll a backup before you need it
Device-bound credentials are different. A single-device passkey or a hardware FIDO security key cannot sync. If that authenticator is the only one registered on an account, losing it means you fall into account recovery for each service—or permanent lockout if recovery is weak.
The practical rule is boring and effective: register a second authenticator while everything still works. That can be another security key, a second device-bound credential, or a synced passkey alongside a hardware key for high-value accounts.
Services that detect a solo device-bound registration should nudge users to add a backup before day-to-day reliance starts. Waiting until the bag is gone is too late.
Availability vs compromise — reused passwords feel recoverable but invite takeover
A reused, memorable password with no second factor is highly “available.” You can usually type it from anywhere. That comfort is expensive: commodity attackers harvest, stuff, and take over those accounts at scale.
Microsoft’s Digital Defense Report 2025 still shows password-centric attacks dominating observed volume. Adding a device to authentication—whether a password manager, traditional MFA, or FIDO2—cuts compromise risk sharply, and in exchange introduces a recovery dependency you must plan for.
Synced passkeys deliberately choose the safer trade: slightly more conscious recovery planning, far less room for phishing and stuffing to quietly empty the account.
Recovery flows are the shared weak link
When every authenticator is gone, passkeys and traditional MFA land in the same place: email links, SMS codes, support tickets, or other “prove you own the account” flows. Those paths are often weaker than the primary login—and attackers already abuse them.
As passkeys spread and primary sign-in becomes harder to phish, recovery will attract more attention. That is not an argument against passkeys; it is an argument for stronger recovery design and for protecting the email and sync accounts that sit behind reset buttons.
Treat your email and sync-fabric accounts as crown jewels: phishing-resistant sign-in where available, unique credentials, and recovery options you understand before you need them.
Checklist before relying on passkeys day-to-day
- Prefer synced passkeys for personal accounts so one lost phone is not a single point of failure.
- Enroll at least two devices (or a device plus a hardware key) on email, banking, cloud, and developer accounts.
- If you use a single-device FIDO token, register a backup authenticator before you need it.
- Protect the sync fabric itself with phishing-resistant authentication and a recovery path you have tested.
- Keep backup codes or documented recovery only where the service still requires them—and store them offline.
- Do not delete password fallbacks until you understand how that service recovers a lost passkey.
- Review registered passkeys periodically and revoke anything you no longer control.
Plan recovery before you need it
Use strong unique passwords where passkeys are not yet available, and open our passkeys overview for how registration and sync actually work day to day.