Sovatun Guide

Passkeys on Public Wi-Fi: What They Change and What a VPN Still Does

Passkeys make iPhone logins phishing-resistant but leave the connection layer untouched. Here's what passkeys on public Wi-Fi do — and what a VPN still does.

Answer First

Passkeys change how you prove who you are on a website, but they do not change the network your iPhone is connected to. The short answer to “do I still need a VPN on public Wi-Fi if I use passkeys?” is yes — for different reasons than you might think.

Definition: A passkey is a passwordless login credential: a cryptographic key pair whose private key stays on your device or in a synced credential manager, unlocked with Face ID, Touch ID, or your passcode. Because the key is bound to the site that created it, a lookalike phishing site can’t sign in with it — there is no password to type, reuse, or steal.

Why: Logging in and sending traffic are two separate layers. Passkeys fix the login layer, making authentication phishing-resistant — which matters on hotel and airport Wi-Fi, where fake portals and lookalike sign-in pages appear. They leave the connection layer untouched: your iPhone still joins the same public access point, your packets still cross that network, and the sites you visit still see your IP address. That layer is a VPN’s job.

Example: You’re on airport Wi-Fi and tap “Sign in with passkey” for your airline account. Face ID approves the login — far more resistant to credential theft than a password. But that exchange travels over the same network as everything else, the airport’s network can still see which sites you’re reaching, and the airline still logs your IP address. The passkey changed none of that.

Key Facts

  • Passkeys are phishing-resistant by design: a credential only authenticates to the site it was created for (FIDO Alliance).
  • A passkey does not encrypt your connection. Transport security still comes from HTTPS, as with a password (FTC).
  • On iPhone, passkeys sync end-to-end encrypted through iCloud Keychain to devices on the same Apple Account; third-party managers (1Password, Dashlane, Bitwarden, Google Password Manager) can also store them (FIDO Alliance).
  • Passkeys on public Wi-Fi don’t hide your IP address, the sites you visit, or your data volume — not from the network operator, and not from the sites themselves.
  • A VPN doesn’t prevent phishing, malware, or account compromise. Neither tool substitutes for the other.
  • Neither passkeys nor a VPN protect you from joining a malicious “evil twin” hotspot that copies a legitimate network name — always confirm the real network (CISA).

Expert Explanation

Two layers, two tools. Think of every online session as two layers. The login layer is the handshake that proves who you are — historically a password, today increasingly a passkey. The connection layer is the pipe your data travels through: your iPhone, the Wi-Fi access point, the internet, and the servers you talk to. Passkeys operate entirely in the first layer; a VPN entirely in the second. Most “passkeys vs VPN” confusion comes from treating them as competitors when they’re different layers of the same stack.

What passkeys actually do. Creating a passkey generates a key pair. The private key stays in the Secure Enclave or your synced vault; the site keeps only the public key. To log in, the site sends a challenge your device signs — proving it holds the private key without ever transmitting it. Because the challenge is tied to the site’s real identity, a phishing page can’t relay or replay it. That’s the property security teams call phishing resistance, and it’s the passkey’s entire reason to exist (Apple).

What still happens on the wire. Here’s the part passkeys don’t touch. On public Wi-Fi, your passkey login — and every request after it — still traverses the shared access point. HTTPS encrypts the content, and because most sites now use encryption, public Wi-Fi is generally safe for ordinary browsing (FTC). But encryption protects the pipe, not the destination: the network operator can still see which domains you connect to, when, and how much data flows, and sites still see your IP. On a hostile network, traffic on unsecured access points can be sniffed and attackers can impersonate a known network name (CISA). Those are connection-layer problems — a VPN’s job.

iPhone specifics: passkeys meet hotel and airport Wi-Fi.

  • iCloud Keychain sync. Passkeys you create on iPhone sync end-to-end encrypted to your other Apple devices. Convenient on trips, but it makes the credential depend on your Apple Account — keep recovery methods current, or losing the account can mean losing passkeys.
  • Third-party password managers. 1Password, Dashlane, Bitwarden, or Google Password Manager can be your passkey provider instead of — or alongside — iCloud Keychain. Either way, the vault is a login-layer store, not a network-layer tool.
  • First passkey login at a hotel or airport. The first sign-in on a device or site may need to reach the site to register the credential — and a new device may need to fetch a synced passkey from iCloud. On a hotel network whose captive portal isn’t completed, that traffic is blocked and the login stalls. If a VPN is already connected, the portal page itself may not load, because traffic is tunneled before the network authorizes internet access. Sequence: join the Wi-Fi, complete the portal, then connect the VPN.

What a VPN still does — and doesn’t. A VPN encrypts everything between your iPhone and a VPN server, so the local network sees one encrypted tunnel instead of a stream of site connections, and sites see the VPN server’s IP rather than yours. iPhone supports VPN natively over IKEv2/IPsec and other protocols (Apple). On public Wi-Fi that’s a real, distinct job: IP exposure and same-network snooping are exactly what a passkey leaves in place. What a VPN can’t do is make you immune to phishing, malware, or account takeover — and it shifts trust to the provider, so not all VPN apps deserve it: some are data collectors in disguise, and Apple has pushed VPN apps off the App Store over data practices.

Practical limits. Passkeys aren’t everywhere yet — many sites still fall back to passwords and one-time codes, and there public Wi-Fi risk looks the way it always did. A passkey doesn’t protect you on a compromised device, and it doesn’t hide activity from sites, your carrier, or (without a VPN) the network you’re on. A VPN doesn’t hide everything either: it changes what the network and sites see, not what the provider sees — and it doesn’t change how your iPhone handles local network access for nearby devices. No single tool closes all gaps.

Decision Framework

Concern on public Wi-FiPasskeyVPN
Phishing site steals your loginStrongly reduces riskNo effect
Password reuse or credential stuffingStrongly reduces riskNo effect
Site or network sees your IP addressNo effectHides your IP from sites
Network operator sees which sites you visitNo effectMasks it behind the VPN tunnel
Same-network sniffing of unencrypted trafficNo effectEncrypts the connection
Evil-twin hotspot interceptionNo effectNo effect — confirm the real network
Malware or a compromised deviceNo effectNo effect

When to still use a VPN on public Wi-Fi: airport and hotel networks you don’t control; work or financial accounts over an unfamiliar hotspot; anywhere you’d rather the local network not see which sites you visit; and as a general default for everyday connection privacy on iPhone — the use case SovaTun is built for. You can skip it on your own trusted home or cellular connection, where passkeys plus HTTPS is already a strong setup.

Key Takeaways

  • Passkeys fix the login layer with phishing-resistant credentials; they do nothing to the connection layer.
  • On public Wi-Fi, a passkey still travels over the same network — your IP, destinations, and traffic volume stay visible without a VPN.
  • iCloud Keychain syncs passkeys end-to-end encrypted, and third-party managers work too; keep Apple Account recovery options current.
  • First passkey logins at hotels and airports can fail behind captive portals — complete portal sign-in before connecting a VPN.
  • A VPN isn’t a security shield: it doesn’t stop phishing, malware, or account compromise, and it’s only as trustworthy as its provider.

FAQ

Q: Are passkeys safe to use on public Wi-Fi?

A: Yes — passkeys are phishing-resistant and never transmit a reusable secret, so using one on hotel or airport Wi-Fi is safer than typing a password. They protect the login itself. What they don’t protect is the connection: your IP and site traffic remain visible to the network unless you also use a VPN.

Q: Do passkeys replace the need for a VPN?

A: No, because they work at different layers. A passkey makes your login phishing-resistant; a VPN encrypts your connection and hides your IP from sites and the local network. Passkeys solve the credential problem, not the network problem — on public Wi-Fi you typically want both.

Q: Can someone steal my passkey on hotel Wi-Fi?

A: Not by sniffing the network. The private key never leaves your device, and the authentication challenge is bound to the real site, so a lookalike page can’t use it. The realistic risks a passkey doesn’t address: your IP being visible, traffic patterns being observed, and joining an evil-twin hotspot that copies the hotel’s network name.

Q: Why did my first passkey login fail at a hotel?

A: The usual culprit is the captive portal. Until you complete the hotel’s sign-in page, the network blocks internet traffic, so your iPhone can’t reach the site to register the passkey — or fetch a synced passkey from iCloud. If a VPN is already connected, the portal page itself may not load. Disconnect the VPN, complete the portal, then reconnect.

Sources