Inside the Quiet Death of the Password
The password, that most unloved and ubiquitous artifact of digital life, is dying. Not suddenly, and not without resistance, but with a quiet inevitability that has accelerated sharply over the past eighteen months. The technology that is replacing it — a cryptographic system known as passkeys — has now been adopted by every major platform vendor, is supported on more than four billion devices worldwide, and is being rolled out by a growing roster of banks, retailers, and enterprise software companies. For the first time in the password's three-decade reign, its successor is not merely theoretical. It is here, it works, and it is spreading fast.
The case against passwords is so familiar it barely needs restating. People choose weak ones, reuse them across sites, forget them constantly, and fall for phishing attacks that trick them into handing them over. Despite decades of advice — use a different password for every site, make it long and complex, change it regularly — the most commonly used passwords in the world remain variations of "123456" and "password." The cybersecurity industry has built an entire ecosystem of band-aids around this fundamental fragility: password managers, two-factor authentication, security questions, biometric overlays. None of them address the core problem, which is that a password is a shared secret — a piece of information that exists in both the user's mind and the service's database — and shared secrets can be stolen.
Passkeys work differently, and the difference is fundamental. When a user creates a passkey for a website, their device generates a pair of cryptographic keys: a private key, which stays on the device and is never transmitted, and a public key, which is shared with the website. To log in, the user authenticates locally — with a fingerprint, a face scan, or a device PIN — and the device uses the private key to sign a cryptographic challenge from the server. The server verifies the signature using the public key. At no point is a secret transmitted over the network. There is nothing to phish, nothing to steal from a database breach, and nothing for the user to remember.
"Phishing is eliminated," said Roland Kuiper, a security engineer at one of the companies implementing passkeys across its consumer products. "Not reduced. Eliminated. You cannot phish a key that never leaves the device. You cannot stuff credentials that don't exist. You cannot intercept a secret that is never sent. That is not an incremental improvement. It is a category change."
The adoption curve, after years of false starts, has steepened dramatically. Apple, Google, and Microsoft have all built passkey support into their operating systems, making it available by default to virtually every smartphone and computer user in the developed world. Major consumer platforms — including several large banks, e-commerce companies, and social networks — have begun offering passkey login as an option, and a smaller but growing number have made it the default. Industry estimates suggest that more than 800 million passkeys have been created worldwide, a number that is roughly doubling every six months.
The transition is not without friction. Older users who are accustomed to passwords find the new system unfamiliar and, in some cases, unsettling. The idea of logging in without typing anything feels wrong to people who have spent decades equating security with secrecy. Cross-device recovery — what happens when you lose your phone and your passkeys are stored on it — remains a source of anxiety, despite the cloud-sync mechanisms that Apple, Google, and Microsoft have built to address it. And the experience is not yet seamless across platforms: a passkey created on an iPhone works effortlessly on other Apple devices but requires an extra step to use on a Windows laptop, a friction point that undermines the promise of universal simplicity.
Enterprise adoption presents its own challenges. Large organizations with thousands of employees, legacy systems, and complex identity-management infrastructure cannot flip a switch and move to passkeys overnight. The transition requires changes to authentication servers, directory services, and the dozens of internal and third-party applications that employees log into daily. IT departments are cautious by nature and averse to deploying technologies that could lock employees out of critical systems if something goes wrong. "The technology is ready," said Kuiper. "The organizational change management is the hard part."
The password will not vanish overnight. It will linger in legacy systems, in the long tail of smaller websites that lack the resources to implement passkeys, and in the habits of users who resist change. But the direction is unmistakable. The infrastructure is in place, the incentives are aligned — fewer breaches, lower support costs, better user experience — and the momentum is building with a speed that has surprised even the technology's advocates.
For an industry that has spent thirty years trying and failing to fix the password, the arrival of a replacement that is simultaneously more secure and more convenient is something close to a miracle. The password was never a good idea. It was simply the best bad idea available at the time. That time, at last, appears to be ending.
Listen as a Podcast
Pick two voices and we'll generate an AI podcast — two hosts discussing this article in a natural, conversational style. Powered by Workers AI.