Of the roughly 15 billion credentials circulating on the dark web, the overwhelming majority are passwords. Reused, weak and phishable passwords remain the primary attack vector for data breaches, accounting for over 80% of hacking-related incidents according to Verizon’s 2024 Data Breach Investigations Report. The technology industry has spent two decades trying to kill the password. In 2025, it may finally be succeeding.

The breakthrough is passkeys. Developed by the FIDO Alliance — a consortium that includes Apple, Google, Microsoft and every major browser vendor — passkeys replace passwords with cryptographic key pairs. When you create a passkey for a website, your device generates a unique private key that never leaves the device, and the website receives a corresponding public key. Authentication occurs when the website sends a challenge that your device signs with the private key and returns for verification. There is no shared secret to steal, no password to phish and no credential database for attackers to breach. The user experience is familiar: unlock with your fingerprint, face or device PIN — the same action you use dozens of times a day.

Who Has Adopted Passkeys

Apple introduced passkey support in iOS 16 and macOS Ventura in 2022. Google followed with Android and Chrome support in 2023. Microsoft added passkey support to Windows 11 and Edge in 2024. As of early 2025, major platforms including Google, Amazon, PayPal, eBay, Best Buy, DocuSign and WhatsApp support passkey authentication. Apple reported at its 2024 Worldwide Developers Conference that over 95% of its active user base has passkeys enabled on their devices. Google’s Password Manager can now store and sync passkeys across Android, ChromeOS, Windows, macOS and Linux, and the company has committed to making passkeys the default sign-in method for Google Accounts.

Enterprise adoption is moving faster than consumer adoption. Okta, the identity management platform used by over 18,000 organisations, added passkey support in 2024 and reported that 40% of its customers enabled the feature within the first six months. Microsoft Entra ID (formerly Azure AD) supports passkeys for passwordless authentication, and the company reported a 71% reduction in password-related support tickets among organisations that adopted passwordless authentication across their workforces. The economic case is compelling: password resets cost large organisations an estimated $70 per incident in IT support time, and the average employee triggers 1-2 resets per month. A 10,000-employee company can save over $1 million annually by eliminating passwords.

Why Passwords Are Not Dead Yet

Despite the momentum, passwords will not disappear overnight. Legacy systems — mainframes, industrial control systems, older enterprise applications — will not support passkeys for years, if ever. Interoperability between different passkey implementations remains imperfect, particularly when moving between ecosystems (Apple to Android, or between different password managers). And user behaviour changes slowly. A 2024 survey by the FIDO Alliance found that while 57% of consumers were aware of passkeys, only 23% had used them — and the most common reason for not adopting them was simply that people did not know how. Passwords are a habit, and habits are hard to break, even when the alternative is objectively better. But the direction is clear. The password — invented by Fernando Corbató at MIT in 1961 to separate users on a shared mainframe — has had an astonishing six-decade run. Its replacement is finally here.

Leave a Reply

Your email address will not be published. Required fields are marked *