Passkeys at GMX and web.de: Security Win or a Door for Big Tech?
GMX and web.de are rolling out Passkeys. Sounds great. But who really benefits when millions of users hand their login to Apple, Google, or Microsoft?

Passkeys at GMX and web.de: Security Win or a Door for Big Tech?
GMX and web.de have introduced Passkeys. The story came via Heise, the tone was predictable: more security, more convenience, no more passwords. Everything sounds good. And technically speaking, Passkeys are indeed a sensible development.
But I have a problem with this. Not with the standard. With what happens behind it.
What Passkeys actually are
Short version for anyone who doesn't know yet: A Passkey works with a cryptographic key pair. The private key stays on the device, the public key sits with the service. Sign-in only needs a fingerprint, the camera, or the device PIN. No password is typed, no password can be stolen.
That is clearly more phishing-resistant than a classic password. And better than many SMS-based two-factor methods that can be attacked via SIM swap. So far, so good.
The real problem: Who holds the key?
This is where thinking starts. When a typical GMX user sets up a Passkey, this usually happens: The key ends up in iCloud, Google's password manager, or with Microsoft. Why? Because those are the built-in solutions on smartphones and browsers that get offered automatically.
And that is the crux: The Passkey standard itself is open and secure. But the infrastructure that runs it for billions of users belongs to Apple, Google, and Microsoft.
In concrete terms:
- Whoever creates a Passkey via Apple syncs their login through iCloud
- Whoever creates it via Google stores it in Google's infrastructure
- Whoever switches devices needs the ecosystem of the original provider
From a security angle: no problem. From a privacy angle: worth asking.
Millions of users do not understand this
And that is my real critique. Not the tech. The people.
GMX and web.de together have around 40 million active users in Germany. Those are not 40 million IT specialists. That is retiree Else, who has never heard of iCloud sync. That is the tradesperson who is just glad their email works. That is the teenager who simply taps whatever the phone suggests.
These people are now shown a feature sold as a convenience win. And while they click "Continue," they lay the foundation for their email login to run through a US corporation. They do not know that. Nobody explains it to them.
The ecosystem trap
"Lock-in" sounds abstract, but the principle is simple: If your GMX Passkey lives in iCloud, you will think twice about switching to Android. If everything is in Google, you stay in Google. That is not a bug of these systems — from a corporate view, that is a feature.
And the coupling goes further: If your login runs through Google's infrastructure, Google has metadata about when you sign in where, with which device, from which country. That is not the same as "Google reads your emails." But it is also not nothing.
Are there better alternatives?
Yes. The Passkey standard forces nobody into Apple or Google. There are local options:
- Hardware security keys such as a YubiKey: The private key never leaves the device, no ecosystem needed, no sync into US clouds
- KeePassXC: Local Passkey management, open source, runs on your own machine
- Vaultwarden: Self-hosted password and Passkey manager, European infrastructure possible
The Heise guide "Using Passkeys with open-source tools" shows exactly that. Technically doable. For average users, though, the barrier is still too high.
What GMX and web.de should do better
When a provider with 40 million users rolls out a feature like this, it carries responsibility. This would be desirable:
Clear explanation: Which provider syncs my key? What happens to the metadata? Can I also use a hardware key?
A European option: Offer your own GDPR-compliant sync infrastructure instead of automatically sending users to Apple/Google.
Opt-in instead of opt-out: Passkeys should be set up as a conscious decision, not as a default click path that funnels the masses into Big Tech ecosystems.
My conclusion
Passkeys are good technology. I do not dispute that. But good technology, poorly implemented, creates new dependencies. And if 40 million people de facto deposit the login key for their German email provider with a US corporation without knowing or understanding it, that is not progress. That is the next stage of digital disempowerment.
The question is not: Passkey yes or no? The question is: Who controls the key? And who even asks the user?
If you want to use Passkeys without Big Tech dependency, the Heise guide and KeePassXC are solid starting points for local solutions.
Image credits
- Photo: panumas nikhomkhai via Pexels