Hacking News All articles
Opinion

Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?

Hacking News
Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?

Photo: MFischer (WMF), CC0, via Wikimedia Commons

Somewhere around 2012, the security community reached what felt like a consensus: passwords were a failed experiment. Too short, too reused, too easily phished, too expensive to manage. The math was brutal — over 80% of breaches involved compromised credentials, and no amount of complexity requirements or forced rotations was going to fix that.

Fast forward to today. FIDO2 is mature. WebAuthn is a W3C standard. Apple, Google, and Microsoft have all thrown their weight behind passkeys. The infrastructure exists. The spec is solid. And yet, the average American worker is still grinding through a login screen with a password they've used since the Obama administration.

Something went wrong. Or rather, a lot of things went wrong — and the gap between "technically ready" and "actually deployed" has turned into one of the more frustrating stories in enterprise security.

The Standard That Everyone Agrees On and Nobody Uses

Let's be clear about what FIDO2 and WebAuthn actually are, because the marketing fog around "passkeys" has gotten genuinely thick.

FIDO2 is an authentication framework developed by the FIDO Alliance that eliminates shared secrets entirely. Instead of sending a password to a server — where it can be stolen, leaked, or cracked — the user's device holds a private cryptographic key that never leaves the hardware. The server only ever sees a public key and a signed challenge. There's nothing to phish. There's nothing to breach. Credential stuffing attacks become mathematically irrelevant.

WebAuthn is the browser API that makes this work on the web. It's supported in Chrome, Firefox, Safari, and Edge. It's been supported for years.

So why does your company's VPN still prompt you for a password every Monday morning?

The Friction Nobody Wants to Talk About

The honest answer is that passwordless authentication is genuinely hard to roll out at scale, and the industry hasn't been great about admitting that.

Start with device dependency. Passkeys live on your device — your phone, your laptop, your hardware security key. That's the whole point. But it immediately creates a support nightmare: What happens when an employee loses their phone? What happens on day one for a new hire who hasn't enrolled yet? What happens when someone needs to log in from a shared terminal at a hospital or a factory floor?

Legacy password systems had a simple (if terrible) answer to all of those questions: reset the password. The helpdesk understood it. Users understood it. It was bad security, but it was operationally familiar.

Passkey recovery flows, by contrast, are still a mess. Every vendor has a different approach. Some rely on cloud backups, which reintroduces the centralized attack surface FIDO2 was supposed to eliminate. Some require backup hardware keys, which most organizations haven't budgeted for. Some just... don't have a great answer yet.

Vendor Lock-In and the Ecosystem Problem

Then there's the ecosystem fragmentation issue, which doesn't get nearly enough attention.

Apple's passkey implementation syncs beautifully across Apple devices via iCloud Keychain. Google's syncs across Android and Chrome. Microsoft's ties into Windows Hello and the Microsoft Authenticator ecosystem. Each works well within its own garden. Cross-platform? That's where things get awkward.

If you're a security engineer at a mid-sized company with a mix of Windows machines, personal iPhones, and a few Android holdouts, you're not deploying one passkey solution — you're managing three, plus a fallback mechanism for the edge cases. That's not simplification. That's complexity with better PR.

Enterprise identity providers like Okta, Duo, and Azure AD have all added passkey support, but integration depth varies wildly. Plenty of internal applications — especially anything built more than five years ago — aren't WebAuthn-compatible and would require significant redevelopment to get there. Most IT departments are already underwater. A multi-year authentication modernization project doesn't make the roadmap.

The Real Cost of Staying Stuck

Here's where the frustration tips into genuine alarm. The cost of inaction isn't abstract.

Credential-based attacks aren't slowing down while the industry figures out its passkey rollout strategy. Adversary-in-the-middle phishing toolkits like Evilginx can bypass SMS-based MFA in real time. Infostealer malware vacuums up session tokens and saved passwords at industrial scale. The threat landscape has evolved significantly faster than enterprise authentication infrastructure, and that gap is where breaches happen.

Meanwhile, the organizations most vulnerable — mid-market companies, local government agencies, healthcare networks — are exactly the ones with the least capacity to absorb a complex authentication overhaul. They're still on Active Directory setups from 2015. Their security teams are one or two people stretched thin. The elegant cryptographic solution exists; the path to deploying it does not.

What Security Pros Should Actually Do Right Now

None of this means you should give up on passwordless. It means you should be realistic about the transition.

If you're a security professional navigating this, a few things are worth keeping in mind:

Start with phishing-resistant MFA, not full passkeys. FIDO2 hardware keys like YubiKeys are mature, well-supported, and dramatically reduce phishing risk even without going fully passwordless. Deploy them for privileged accounts and remote access first. That's where your exposure is highest.

Audit your application portfolio before you commit to a timeline. Find out which of your internal apps actually support WebAuthn today. The answer will probably be depressing, but better to know now than to promise a board-level rollout you can't deliver.

Push your identity provider on recovery flows. Don't accept vague answers about what happens when a user loses their authenticator device. That scenario will happen. You need a tested, documented process before you go live.

Watch the passkey sync standards space. The FIDO Alliance is actively working on cross-platform credential exchange standards. The ecosystem fragmentation problem is being worked on — it's just not solved yet.

The post-password era is real. The technology works. But the transition is going to be messy, longer than the vendors' press releases suggest, and full of edge cases that no conference talk quite prepares you for. The worst move is to treat passwordless as an all-or-nothing leap and do nothing while you wait for the perfect solution.

Passwords are dying. They're just taking longer to die than anyone wanted — and in the meantime, attackers are having a field day.

All Articles

Related Articles

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?

Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry

Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry