Keep your account secure with a passkey, the phishing-resistant multi-factor authentication tool.
At UniSuper we’re always looking for ways to keep you and your money safe. That’s why we’re beginning to offer passkeys to some members as a login method for your online account—with a view to progressively offering these to all members. It’s the more secure and convenient way to sign in.
What’s a passkey?
Chances are you might have already used a type of passkey before, like a fingerprint, Face ID, or PIN on a device that you possess. Your passkey is based on you and your characteristics – or biometrics – making them phishing-resistant. You’re the only one that has access to it and it can’t be shared or guessed, unlike an email address or password.
Your passkey stays on your device and with UniSuper, and can’t be used elsewhere. Think of your passkey as having two parts:
- there’s the ‘private’ key, which is held on your device, based on your biometrics and never shared with us
- then there’s the ‘public’ key, which is held by UniSuper.
A passkey proves that you hold the private key, which we then confirm against your public key.
Logging in to your account with a passkey is also quick and easy—no more hitting that ‘forgot password’ button.
FAQs
We know you might have some questions about passkeys, and how to enrol one.
Can I use a passkey on more than one device?
UniSuper passkeys are currently limited to one device. However, we’ll be looking to address this so that your passkey can be used on more than one device.
In the meantime, we recommend taking one of the following actions:
1. Use a password manager, which will sync across all your devices.
2. Enrol a passkey on your mobile device.
3. Enrol a passkey on your most used device.
Can I have a password and a passkey for my UniSuper online account?
Yes. Even if you enrol a passkey, your current login credentials like your email address and password will still be associated with your online account—so you can still use them, as well as SMS PIN. However, you’ll only need to use one login method.
Is it mandatory to enrol a passkey for my UniSuper online account?
No. Although we recommend enrolling a passkey because of its resistance to phishing, you don’t need to enrol one.
What makes passkeys phishing-resistant?
Passkeys are phishing-resistant by design. They’re based on your characteristics, or biometrics, like your facial features, so they can’t be shared and used by anyone else—that includes malicious actors.
Will my biometrics be safe when enrolling a passkey?
Yes. Your biometrics are never sent to any remote servers or even stored on the device you possess. Any server used will simply check that your login attempt using your passkey was successful.