The End of Passwords Is Coming

The End of Passwords Is Coming

(My article, published in Inc. Türkiye)

Passwords are one of the few things that have remained unchanged since the internet entered our lives. First, we chose a simple word. Then we were told that wasn't secure enough and that we needed to use at least eight characters. So we added uppercase letters. Lowercase letters. Numbers. Special characters. Later, we learned that we shouldn't use the same password across different accounts. Eventually, we reached the absurd point where we were expected to remember hundreds of different, long, and complex passwords for hundreds of accounts. Of course, we couldn't.

Then came password managers. We added SMS verification codes on top of our passwords. Next came authenticator apps.

In other words, for nearly 40 years, we've been adding layer after layer to make a fundamentally flawed system more secure. Now, the technology industry finally seems to have agreed on a different solution: eliminating passwords altogether.

Microsoft Has Taken a Major Step

This month, Microsoft introduced a significant change for its enterprise customers. Starting September 1, 2026, passkeys began becoming the default authentication method for organizations using Microsoft Entra ID. More importantly, Microsoft announced that it would largely phase out its own SMS and phone-based authentication services starting February 1, 2027. Microsoft has been quite clear about why: SMS and phone calls are no longer considered secure enough, and the company wants to move users toward methods that are more resistant to phishing. Microsoft's move is, in fact, one of the latest steps in a much broader transformation that has been underway for years.

Google began making passkeys the default option for personal accounts back in 2023. Apple has also integrated passkeys directly into the operating systems of its iPhones, iPads, and Macs. Today, it's possible to sign in to many websites using Face ID or Touch ID without ever entering a password.

In other words, we may already have entered a passwordless world without even realizing it.

So, What Exactly Is a Passkey?

The name may sound a little technical, but using one is remarkably simple. Imagine visiting a website. Today, you would typically enter your username and password. You might then receive a code on your phone, which you would also need to enter.

With a passkey, your phone simply asks: "Would you like to sign in with Face ID?" You look at your phone, and you're in.

No password. No SMS code. Nothing to remember.

Behind the scenes, however, there is a fundamental difference. When you use a password, you and the website share a secret: your password. With a passkey, there is no shared secret. Your device creates two mathematically linked digital keys. One is stored by the website, while the other never leaves your device. When you want to sign in, your phone verifies your identity using your face, fingerprint, or device PIN, then uses the key stored on your device. An image of your face is never sent to Google, Microsoft, or the website you're signing in to. Google, for example, explicitly states that your biometric data remains on your device.

More important than all these technical details is the outcome: there is no longer a password for someone to steal. Fake websites asking you to "enter your password" no longer work in the same way. This is where one of the most important advantages of passkeys becomes clear.

One of the most effective techniques used by cybercriminals today is remarkably simple. You receive an email that appears to come from your bank, Microsoft, or Google. You click the link. A login page appears that looks almost identical to the real one. You enter your username and password. And just like that, you've handed your password directly to an attacker.

Passkeys, however, are tied to the specific website for which they were created. A passkey created for your bank won't work on a fake website impersonating that bank. Apple also points out that this feature makes passkeys inherently resistant to phishing.

Today's security systems rely heavily on users being vigilant.

"Is this link legitimate?"

"Is the domain correct?"

"Did this email really come from my bank?"

With passkeys, a much greater share of the responsibility for security shifts to the technology itself. Perhaps this is exactly what good security technology should do: eliminate the need for users to behave like cybersecurity experts every time they go online.

Five Billion Passkeys in Use

This is why passkeys are no longer simply an experiment in the future of authentication by Apple, Google, and Microsoft. According to research published by the FIDO Alliance in May 2026, approximately 5 billion passkeys are actively being used worldwide. Among consumers surveyed, 75% have enabled a passkey for at least one account. Meanwhile, 68% of large organizations are either already using passkeys for employee authentication or are in the process of rolling them out.

These figures matter. In the technology world, some standards can only succeed when competing companies agree to adopt the same approach. If Apple, Google, and Microsoft had each developed their own incompatible systems, eliminating passwords would have been much more difficult. The most important aspect of the FIDO standard behind passkeys is that technology companies have agreed on a common system.

What Happens If I Lose My Phone?

This is probably one of the first questions that comes to mind. "If all my keys are on my phone, will I lose access to all my accounts if I lose my phone?" Under normal circumstances, no.

Passkeys can be securely synchronized across our devices through systems such as Apple's iCloud Keychain and Google Password Manager. When we get a new phone, we can regain access to our accounts. Apple also supports features that allow passkeys to be transferred securely between different password managers.

Of course, the system isn't perfect.

Account recovery procedures, older devices, enterprise systems, and websites that don't yet support passkeys mean we'll continue living alongside passwords for some time.

And passkeys don't eliminate the problem of cyberattacks entirely. Just last week, Microsoft announced that it had identified attacks in which cybercriminals tricked users by claiming that their "passkey needs to be updated." In these attacks, the criminals aren't breaking the passkey itself. Instead, they're attempting to take over accounts by persuading users to approve a different action.

In other words, as technology evolves, so do the methods used by fraudsters. But one major attack surface is disappearing: the password itself.

Will We Miss Passwords?

In the history of technology, we sometimes only realize how inconvenient certain things were after they've disappeared.

There was a time when memorizing hundreds of phone numbers was perfectly normal.

Studying a map before getting into the car was normal.

Taking photographs and waiting for the film to be developed before seeing how they turned out was normal.

Today, we've become accustomed to remembering dozens of passwords, clicking "Forgot password," and typing six-digit codes sent to our phones into another screen. Perhaps a few years from now, all of this will seem just as outdated.

Passwords probably won't disappear overnight. They'll continue to exist in some legacy systems for years. But the direction is now quite clear. Google is promoting passkeys over passwords. Apple has built them into its operating systems. Microsoft is making passkeys the standard in the enterprise world while moving away from SMS-based authentication. And billions of passkeys are already in use.

For nearly 40 years, we've been doing the same thing whenever we reach the gateway to the internet: Username. Password. Sign in. One of the internet's oldest habits is finally changing. In the future, entering the digital world may no longer require us to remember anything at all. The device we carry with us, together with our face or fingerprint to prove that it really belongs to us, may be all we need.

And I think the best thing about the end of passwords is this:

None of us will ever have to wonder, "What was my password again?"

Mustafa İÇİL

Mustafa İÇİL

Mustafa İÇİL is an accomplished executive with nearly 30 years of experience in senior strategic sales and marketing roles. He has held management positions responsible for sales and marketing strategies at industry-leading companies, including Microsoft, Apple, and Google, from 1994 to 2013. Currently, he serves as a Digital Strategy and Innovation Consultant at his own firm, İÇİL Training and Consulting, which he established in 2013. Mustafa İçil is also recognized as a prominent Keynote Speaker in the field of Digital Transformation and Innovation. In addition to his professional career, he has taught "Digital Strategy" courses at renowned institutions such as Boğaziçi University and the TIAS Business School Executive MBA programs.

https://www.mustafaicil.com
Sonraki
Sonraki

Your Next Customer May Not Be Human