Passkeys: the new, safe and secure way to sign in

Learn more about passkeys as a new authentication method, why we’re introducing them and how they can keep you safe.

Keep your account secure with a passkey, the phishing-resistant multi-factor authentication tool.

At UniSuper we’re always looking for ways to keep you and your money safe. That’s why we’re beginning to offer passkeys to some members as a login method for your online account—with a view to progressively offering these to all members. It’s the more secure and convenient way to sign in.

What’s a passkey?

Chances are you might have already used a type of passkey before, like a fingerprint, Face ID, or PIN on a device that you possess. Your passkey is based on you and your characteristics – or biometrics – making them phishing-resistant. You’re the only one that has access to it and it can’t be shared or guessed, unlike an email address or password.

Your passkey stays on your device and with UniSuper, and can’t be used elsewhere. Think of your passkey as having two parts:

  • there’s the ‘private’ key, which is held on your device, based on your biometrics and never shared with us
  • then there’s the ‘public’ key, which is held by UniSuper.

A passkey proves that you hold the private key, which we then confirm against your public key.

Logging in to your account with a passkey is also quick and easy—no more hitting that ‘forgot password’ button.

FAQs

We know you might have some questions about passkeys, and how to enrol one.

Can I use a passkey on more than one device?

UniSuper passkeys are currently limited to one device. However, we’ll be looking to address this so that your passkey can be used on more than one device.

In the meantime, we recommend taking one of the following actions:

1. Use a password manager, which will sync across all your devices.
2. Enrol a passkey on your mobile device.
3. Enrol a passkey on your most used device.

Can I have a password and a passkey for my UniSuper online account?

Yes. Even if you enrol a passkey, your current login credentials like your email address and password will still be associated with your online account—so you can still use them, as well as SMS PIN. However, you’ll only need to use one login method.

Is it mandatory to enrol a passkey for my UniSuper online account?

No. Although we recommend enrolling a passkey because of its resistance to phishing, you don’t need to enrol one.

What makes passkeys phishing-resistant?

Passkeys are phishing-resistant by design. They’re based on your characteristics, or biometrics, like your facial features, so they can’t be shared and used by anyone else—that includes malicious actors.

Will my biometrics be safe when enrolling a passkey?

Yes. Your biometrics are never sent to any remote servers or even stored on the device you possess. Any server used will simply check that your login attempt using your passkey was successful.

More like this

You might also be interested in:

Do casual employees get paid super?
Working casually? Under 18? Not sure if you’re eligible for super? Whether it’s one or all, we’ll explain the rules—from first job jitters to full-time careers—and how to secure that super bag.
Is super paid on long service leave?
Learn more about whether super is paid on long service leave and what impact it could have on your superannuation.
Is super paid on overtime?
Learn about the relationship between your super and overtime payments, and how you could boost your retirement savings with those payments.
X
Cookies help us improve your website experience.
By using our website, you agree to our use of cookies.
Confirm