Opinion
View on Substack

Why passwords stuck, and what's finally prising them loose

Written by
Eve Maler
Published on
August 25, 2026
Blog
Technology

In 2012 I didn’t buy the whole “the era of passwords is over” thing. On December 31 of that year, I published a Forrester blog post called “Make A Resolution: Kill Your P@55W0rD Policies” countering Wired’s famous “Kill the P@55W0rD” story.

My argument was that the password is sticky. Why? “[B]oth because it’s handy to be able to synchronize authenticator data between cooperating systems (and people), and because people find using passwords to be less invasive, fiddly, or personally identifying than a lot of other options.”

Subscribe now

None of the reasons are security properties. They’re affordances, and they make the password valuable both to end-users and to whoever has to ship the login box. I’ve long described “something you know” as a macronutrient of authentication: however clearly you can see it working against you, giving up carbs is hard.

Academic research agreed with me. “The Quest to Replace Passwords” in 2012 scored passwords against 35 proposed replacements, and nothing beat passwords on usability, deployability, and security all at once. My follow-on Forrester research scored passwords even worse on security — but still no love for an alternative.

I wasn’t an early believer in the fix, either. In July 2014 I published Forrester research (paywalled) on the work of the FIDO Alliance that put it in a race against time and market innovation — promising, unproven, and by no means obviously the winner. It took the FIDO2 era for the technology to advance sufficiently.

Fourteen years after Wired writer Mat Honan’s password breach, the password is still here — so I was right about the hard part. But little by little, static shared secrets are losing steam, and passkeys and biometrics are why. (Don’t make me assign “protein” and “fat” to them!)

The technology finally caught up, thanks to hard work by an army of specialists. Look at the leap Microsoft is taking: As of September 1, passkeys will become the default sign-in experience in Entra.

Share

And note what they haven’t done: passwords are still there. A default is a signal; eliminating the password would be the signal. I went looking for anyone at the scale of Microsoft Entra who has eliminated passwords outright (retailers excluded because they have special incentives to eliminate password setting from consumer flows). There’s really only one, and it’s firmly future-tense.

In April 2026, LINE Yahoo announced it will end password-only login for Yahoo! JAPAN IDs and consolidate on passkeys, targeting 2027. They’ve been at this longer than almost anyone — FIDO server certification in 2015, more than 30 million monthly active users who have disabled their passwords, a 25% drop in forgotten-ID and password inquiries.

More typical is RSA’s FIDO case study: they “eliminated passwords from all managed endpoints and primary authentication flows” in the enterprise, and then admit that “legacy systems and edge cases exist; RSA documents them and is developing plans to resolve them rather than claiming perfection.” Even with an executive mandate and full control of their own estate, truly killing static shared secrets is hard.

Look, I’ve come around. I believe passkeys have near-magical properties. I made that case in my recent “History of the Login Box” talk, and have been making it since ForgeRock implemented passwordless tech. And FIDO publishes some great UX guidance.

Yet passkey login rants abound — I’ve got a doozy of a rant myself. The rollouts are where things get hung up, and fixing those pains takes decisions that are getting orphaned in the org chart. Authentication and access management may sit in entirely separate teams, and “identity” may not be recognized as a core function at all — let alone as what it actually is, the enterprise’s business model in disguise. That’s where the advice in Mastering Digital Identity comes in.

So while I haven’t changed my mind about where the difficulties lie, I have firmly changed my mind about whether prising passwords out of admins’ and users’ fingers is worth the effort.

The FIDO Alliance’s Authenticate conference in Carlsbad on October 19-21 will be covering passkeys from every conceivable angle, including my own: a keynote on “Why Passkeys Stall: The People and Process Barriers to Adoption.” I’ll share my login rant there, if you’re interested. 😀 I’ll also be signing copies of my book on the 19th, courtesy of BalkanID, with complimentary copies while they last. Registration for non-members is 15% off with my code EVE15.

Leave a comment

Share this post
Technology
Identity
Security
Privacy

Access Irresistible Identity Strategies

Cut through IAM complexity and transform your strategy with Eve Maler's research-backed insights.