For sixty years, the password has guarded our digital lives. It was invented for a 1960s time-sharing computer, and it shows. The average person now juggles around a hundred accounts, reuses the same handful of passwords, and gets phished anyway. That era is ending, not with a bang, but with a fingerprint.

The shift went mainstream this year. On September 1, 2026, Microsoft made passkeys the default authentication method for Entra ID, pushing millions of enterprise users away from SMS codes and toward cryptographic login. The UK's National Cyber Security Centre told the public to ditch passwords wherever passkeys are available, declaring that passwords no longer offer sufficient protection against modern cyber threats. According to the FIDO Alliance, 15 billion accounts can now authenticate with passkeys.

How passkeys actually work

A passkey is a pair of cryptographic keys. Your device generates them, keeps the private key locked on your phone or laptop, and hands the public key to the website. When you log in, the site sends a challenge, your device signs it with the private key, and you are in. Nothing reusable ever travels across the network, so there is nothing for a hacker to steal and nothing for you to accidentally type into a fake login page.

Your fingerprint or face never leaves the device. Biometrics just unlock the private key locally. And because the browser enforces origin binding automatically, a passkey created for your bank simply will not work on a lookalike phishing site. The security does not depend on your vigilance. It is built into the architecture.

A password is a secret you have to protect. A passkey is not a secret at all, and there is nothing to leak, guess, or phish.

Why 2026 became the tipping point

Enjoying this story?

Get the five most important stories in tech, every morning. Free.

Three forces converged. First, phishing got industrialized. AI-generated lures, SIM-swapping, and credential stuffing made even careful users vulnerable, and SMS-based two-factor codes became a liability rather than a shield. Microsoft explicitly cited AI-powered phishing as the reason for its September move.

Second, the platforms aligned. Apple made passkeys the default for new iCloud accounts. Google reports over a billion passkey sign-ins per month, with account compromise rates 99.9 percent lower than passwords. GitHub, Amazon, and others followed. When the biggest gatekeepers on the internet all push the same direction, developers follow.

Third, passkeys are simply nicer to use. Login success rates with passkeys beat passwords, because there is nothing to mistype, forget, or reset. Better security that also means less friction is a rare combination, and it is why adoption keeps accelerating.

What is still standing in the way

Passkeys by the Numbers

Adoption milestones for passwordless login.

Accounts supporting passkeys
15B
Google passkey sign-ins / month
1B+
Lower compromise rate vs passwords
99.9%
Microsoft Entra default
Sep 2026

Note: Figures from FIDO Alliance, Google, and Microsoft announcements.

The honest answer: passwords will not vanish overnight. Most of the web still runs both systems side by side, and the remaining obstacles are organizational, not technical. Legacy systems need rewrites. Account recovery, what happens when you lose every device, is still the hardest design problem in the space. Cross-platform sync has improved, with password managers carrying passkeys across devices, but rough edges remain.

Expect a hybrid decade, not a sudden shutoff. Passwords will linger in corners of the internet the way fax machines lingered in offices. But the direction is unmistakable, and it runs one way.

What you should do now

Fingerprint scanner
The password's days are numbered. (Photo: i.blogs.es)

Start accepting passkeys wherever a service offers them. Keep them in a cross-platform password manager so they survive a lost phone. And keep the password manager for everything else, because the long tail of the password era will be with us for years.

The password is not dying because it stopped working entirely. It is dying because something fundamentally better arrived, and enough of the internet's biggest gatekeepers decided it was worth the effort to switch.