Technology
The Password Is Dying, Very Slowly
Passkeys and biometrics are clearly winning, but the long tail of legacy logins shows how hard it is to kill a standard
Updated

The password has been declared dead so many times that its persistence has become a kind of running joke among security professionals. And yet this time feels different. The major technology platforms have aligned around passkeys, a method that lets a device prove who you are using cryptography and biometrics like fingerprints or facial recognition, with no secret string to remember, steal, or reuse. This replacement is genuinely better. But the question isn't whether it wins; it's how long the funeral takes.
The password is a flawed idea wearing the costume of a sensible one. It asks human beings to invent and recall many long, unique, random secrets, precisely what human memory is worst at. The predictable result? Reuse. And reuse turns a single breach at one careless service into a skeleton key for a person's entire digital life. Decades of advice about complexity and rotation mostly produced friction rather than safety because the underlying model fought against how people actually behave.
Passkeys move the secret off the human and into the device. Instead of typing something a thief could capture or guess, you authorize a cryptographic exchange that never sends a reusable secret across the network. There is nothing to phish, no password to hand over to a convincing fake login page. This single property closes off one of the most common and damaging categories of attack. For the user, the experience is simply unlocking a phone or laptop, a rare case of better security that's also less work.
But standards do not die on the schedule their successors deserve. The internet is built on a vast accumulation of older systems: corporate tools commissioned years ago, government portals, small services maintained by no one in particular, and countless accounts that predate the new method and will never be upgraded. Each of these represents a login that still depends on the old secret, and a system is only as strong as its weakest link. As long as a password remains an accepted fallback anywhere, attackers will simply aim for the fallback.
There's also the awkward matter of recovery. When the secret lived in a person's head, losing access meant resetting a password. But when it lives in a device, losing that device raises harder questions about how to prove who you are without reintroducing exactly the vulnerable backdoor the new method was meant to abolish. The industry's answers here are improving but still uneven, and this unevenness slows trust.
The deeper lesson is about how hard it is to retire infrastructure that works well enough. A standard survives not because it's good but because it's everywhere, and everywhere is expensive to change. Migration demands that every service, device, and habit move roughly together, which they never do. So the password won't vanish on an announced date; it will fade unevenly, surviving longest in the corners no one has the budget or incentive to modernize.
That slow fade is itself the story. The future of authentication isn't in doubt, but the present is a long, overlapping transition where the strong new method and weak old one coexist, with the weak one keeping the door ajar. Killing a password is easy; killing the institution of it is the work of a decade, and that decade has only begun.
The daily digest
One email each morning, all the day’s reporting.