Your face is the password

Signing in without passwords: passkeys, Google and 2FA

A cost logbook doesn’t sound like a high-security target, but your Amperlo account holds a year of your movements, your receipts and your billing details — and, more practically, you open it standing at a charger with one hand free. Typing a strong password on a phone keyboard in the rain is exactly the situation passwords are worst at. So Amperlo supports three ways in that are both quicker and safer: passkeys, Google sign-in, and passwords hardened with two-factor authentication.

Passkeys: the short version

A passkey is a cryptographic credential that lives on your device — your phone, your laptop, or a hardware security key — and is unlocked by whatever that device already uses to recognise you: Touch ID, Face ID, Windows Hello, a fingerprint, or the device PIN. When you sign in, the site issues a challenge and your device signs it locally. Nothing secret is ever typed, transmitted or stored on a server.

That design has a property passwords can never have: a passkey is bound to the website it was created for. A phishing page dressed up to look exactly like Amperlo simply cannot use your Amperlo passkey — the browser won’t offer it, because the domain doesn’t match. There’s nothing for you to inspect, no URL to squint at, no judgement call to get wrong at 11pm. The phishing decision is taken away from the human and given to the mathematics, which is precisely where you want it.

There’s also nothing to leak. Amperlo’s servers hold only a public key, which is useless to an attacker on its own. A database breach that would be a disaster for a password-based service yields nothing that can be replayed to sign in as you.

Setting up a passkey, step by step

The whole process takes under a minute:

  • Sign in and go to Settings → Security.
  • In the Passkeys section, choose Add a passkey.
  • Your browser takes over and asks how you want to store it — this device, your phone, or a security key. Confirm with your fingerprint, face or PIN.
  • Give the passkey a name you’ll recognise later — “iPhone”, “Work laptop”, “YubiKey”. Future you, staring at a list wondering which entry belongs to a phone you sold, will be grateful.

From then on, the sign-in page offers the passkey route: choose it, glance at your phone or touch the sensor, and you’re in. No password field, nothing to remember, nothing to mistype one-handed.

Registered passkeys are listed in the same Security section, each removable individually — so when you retire a device, you retire its passkey too, without touching the others. It’s worth registering at least two (say, your phone and a laptop) so that losing one device never locks you out. Amperlo will also give you a gentle nudge to add a passkey after you sign in with a password; you can set one up on the spot or skip it — but it’s the single best minute you can spend on your account.

Passkeys for sensitive actions, not just sign-in

Some operations in Amperlo — the sort you really don’t want a borrowed, unlocked phone to be able to perform — ask you to re-confirm your identity first. If you have a passkey registered, that confirmation can be the passkey itself: a fingerprint or a glance, rather than typing your full password again. It’s the same security property in miniature — proof that you are present, not merely that the session is.

Google sign-in

If your life already runs through a Google account, you can sign in to Amperlo with it — one tap, and Google vouches for you. You get Google’s own protections (their anomaly detection, their 2FA, their device management) applied to your Amperlo access for free.

One safeguard is worth knowing about because it’s deliberately strict. If a Google sign-in arrives for an email address that already has an Amperlo account which has never verified its email, Amperlo refuses to link the two. That closes a well-known account-hijack pattern in which an attacker pre-registers an account with your address and waits for you to “sign in with Google” straight into an account they control. The rule costs a legitimate user thirty seconds of email verification; it costs the attacker the entire technique.

Two-factor authentication for password sign-ins

If you prefer to keep a password — or want defence in depth behind it — turn on two-factor authentication, also under Settings → Security. Scan the QR code with your authenticator app, confirm a code to prove the pairing worked, and from then on a password alone is not enough to get into your account. 2FA protects you when your password leaks; it’s fair to say, though, that codes can still be phished by a convincing fake page in a way passkeys cannot — which is why the passkey remains our first recommendation rather than an optional extra.

A sensible setup, in order

  • Minimum: add one passkey on your phone. Done in a minute, transforms both convenience and safety.
  • Better: add a second passkey on another device, so a lost phone is an inconvenience rather than a lockout.
  • Belt and braces: if you keep a password at all, put 2FA behind it — otherwise the password is a side door that undoes the passkey’s benefits.

Security that adds friction gets switched off; security that removes friction actually gets used. Passkeys are the rare upgrade that is simultaneously the lazy option and the safe one — a combination worth taking every time it’s offered.

If you haven’t yet, sign in at amperlo.com, open Settings → Security, and give yourself a passkey. Your future self, one-handed at a charger in the dark, says thanks.

Avatar photo

Alison Ivers