Security
Passkeys on Android: Replacing Passwords Safely
Passkeys are finally usable on Android. Here's how to set them up and where the rough edges still are.

By Adrián Vega
Published 5 November 2025 · Updated 24 June 2026 · 7 min read
Most of us spend all our time worrying about the "front door" of our security—our passwords. But the "back door"—the account recovery process—is often much weaker. I’ve seen people with 20-character passwords lose their entire digital lives because they used an old, insecure recovery email that got hacked. When you lose access to your Android phone or your Google account, you enter a high-stakes game. If your recovery options are set up correctly, it’s a minor 10-minute annoyance. If they are wrong, you might lose your photos, contacts, and emails forever. I spent an afternoon auditing my own recovery path and found three major vulnerabilities I hadn't even thought of.
How recovery attacks work
Hackers love "What was your high school mascot?" questions. These are called security questions, and they are terrible. Most of that info is public on your Facebook or LinkedIn. A "recovery attack" happens when someone tries to reset your password by exploiting these secondary channels. The most common one is the "SMS reset." If a hacker swaps your SIM card, they can just click "Forgot Password" on Google, get a code sent to your number, and they're in. They don't need your password at all. This is why we need to move away from using our phone numbers as the primary way to get back into our accounts. It’s the weakest link in the chain.
Recovery phone choices
Google will constantly nag you to add a phone number for recovery. While it's better than nothing, I’ve actually removed my phone number from some of my most sensitive accounts to prevent SIM swapping. If you choose to keep a recovery phone, make sure your mobile carrier has a "Port-Out Pin" or "SIM Lock" enabled. I called my carrier and added a verbal password that must be given before any changes can be made to my account. It took five minutes and adds a huge layer of physical security. On your Android device, check this by going to Settings > Google > Manage your Google Account > Security > Recovery phone. If it’s there, make sure it’s a number you actually still have access to.
Recovery email choices
Your recovery email is a powerful tool, but it can be a circular trap. I once saw a friend use Email A as the recovery for Email B, and Email B as the recovery for Email A. When he lost the password to both, he was stuck in a loop with no way out. Your recovery email should ideally be more secure than your primary email. I use a separate, encrypted email service (like Proton) for my recovery address, and I have a physical security key protecting it. To update yours, go to the Security tab in your Google Account settings. Make sure that the recovery email is an address you check at least once a month; otherwise, you might miss "security alert" emails if someone else tries to change your password.
Backup codes done right
This is the one thing everyone ignores until it’s too late. Google provides a set of 10 "Backup Codes" for 2-step verification. These are your "break glass in case of emergency" keys. If your phone is stolen and you can’t get your 2FA code, these are the ONLY way back in. Go to 2-Step Verification in your Google settings and find Backup codes. Generate them, but—and this is the key—don't just save them on your phone. If your phone is stolen, you won't have the codes. I printed mine out, put them in a small envelope, and hid them in my physical filing cabinet. I also have a digital copy saved in an encrypted vault that isn't tied to my Google account. It feels old-school, but it has saved my skin exactly once, and once was enough.
Trusted devices list
Your Android phone itself is often a "trusted device." If you try to log in on a new computer, Google will send a prompt to your phone. But what happens if you sell your old phone? I checked my "Your devices" list last month and found an old Samsung S10 I sold three years ago was still listed as an "Active Session." That’s a massive security hole. Go to Settings > Google > Manage your Google Account > Security > Your devices. Review every single one. If you see a phone you don't own anymore, tap it and select Sign out. This revokes that device's "trusted" status instantly. It's a satisfying way to clean up your digital footprint and ensure only you have the keys to your kingdom.
Quarterly review
The biggest mistake you can make is assuming your recovery options are fine because they were fine in 2021. Links break, carriers change settings, and old emails get deactivated. I put a recurring event on my calendar for every three months called "The Security Audit." It takes 15 minutes. I check my recovery phone, my recovery email, and I make sure I still know where my physical backup codes are. Last time I did this, I realized my recovery email was an old university address that was about to be deleted. Catching that early saved me weeks of potential headache. Security isn't a wall you build once; it’s a garden you have to keep weeding.
Key takeaways
- What passkeys actually are is where you start — it's the fastest win.
- Setting up your first passkey: don't skip this — it's where most users leave settings at risky defaults.
- How sync works across devices: don't skip this — it's where most users leave settings at risky defaults.
- Third-party password managers: don't skip this — it's where most users leave settings at risky defaults.
- Recheck these settings quarterly; OEM updates can reset toggles.
Frequently asked questions
- Does changing these settings break apps?
- Almost never. Modern Android apps must handle a denied permission or restricted access gracefully — they either skip the feature or prompt again when needed.
- Will this drain my battery?
- No. If anything, restricting background access and disabling tracking pipelines reduces battery and data usage.
- Do these steps apply to Android 13, 14 and 15?
- Yes. The menu paths shift slightly between versions and OEM skins (Pixel/stock, Samsung One UI, Xiaomi HyperOS), but the underlying controls behave the same.
References & further reading
Continue reading
Related guides
Secure Your Google Account on Android: 2FA, Passkeys, and Recovery
Your Google account is the master key to everything on your Android phone. Here's the four-step lockdown.
7 min read · Updated 24 Jun 2026
Setting a Strong Screen Lock on Android (PIN, Pattern, Biometrics)
The lock screen is your phone's last line of defence. Most people get it wrong.
6 min read · Updated 24 Jun 2026
Set Up Find My Device on Android the Right Way
The new Find My Device network works offline using nearby Android phones. Here's how to enable everything.
7 min read · Updated 24 Jun 2026