
Andrew Shikiar, Executive Director and CMO at FIDO Alliance asks: why are we still being passive-aggressive about passwords?
We’re all guilty of not addressing irritants and unwanted behaviours in life head-on. The micromanager at work that overexplains. The annoying neighbour that doesn’t get the hint about your fence.
And while we want to tell them how we really feel or reset boundaries, we often don’t, and instead show our frustration in subtle ways like eye-rolls, avoidance and indirect sulks, because taking direct action can be a difficult thing to do.
This kind of passive aggression is how we are collectively responding to the problem of passwords.
We have all known for years passwords are not secure. They’re annoying. We forget them. They need resetting. But instead of taking action to get rid of them or use alternatives, most people still continue to rely on them and make their peace with simply feeling quietly annoyed.
The good news is that recent developments in authentication technology is making it easier to address the problem head-on. There is now a better alternative to passwords, and it’s time for passive aggression to turn to action as the industry and consumers increasingly look to passkeys.
Passkeys are built upon open standards from the FIDO Alliance and W3C WebAuthn communities, addressing both the security flaws and the scalability challenges of legacy authentication solutions – including 2FA solutions like SMS OTPs.
Ultimately, this means giving people and service providers a far greater level of security as well as greater convenience, allowing users to sign-in with the same action (typically a biometric or PIN) they use to unlock their devices dozens of times each day.
The tech industry is backing passkeys too, having played a major role in helping develop the standards. Google recently announced that passkeys are now available for all its users to move away from passwords and two-step verification, as has Apple. Windows 10 and 11 have long supported device-bound passkeys in Windows Hello – and passkeys from iOS or Android devices can also be used to sign into sites in Chrome or Edge on Windows.
There’s also momentum from service providers, including PayPal, Shopify, Hyatt, Mercari and Yahoo! Japan to name a few, who continue to adopt passkeys.
Passwords and legacy forms of two-factor authentication (2FA) are knowledge-based, meaning they can be shared and therefore unwittingly given over to fraudsters or used in scale attacks. It’s this shareable element that is what enables things like social engineering attacks and is used to commit fraud and identity theft.
Fraud has now become so commonplace, though, that it’s become another thing businesses are irritated by but feel it’s too difficult to act on. The cost of fraud is now just considered an annoying cost of doing business, with companies prepared to write off substantial sums as they feel powerless to do anything about it.
And those substantial sums really are huge – UK Finance found over £1.2 billion was stolen through fraud last year, of which £485.2 million came from authorised push payments - where victims were tricked into transferring money to fraudsters. This is rising too.
Giving fraud the cold shoulder and avoiding making real change needs to become a thing of the past for organisations and consumers alike. We’ll never completely eradicate fraud, but there are things that can be done today to address a primary cause of it – passwords – that can save billions globally by making the job of would-be fraudsters far more difficult.
Possession-based authentication mechanisms such as passkeys offer the strength needed to fight fraud head on.
There are several reasons why passwords and knowledge-based authentication have been so hard to beat - most notably that passwords have the advantage of ubiquity and familiarity.
Over the years various strong authentication methods have been brought through with varying degrees of success - but most are band aid layers to help address the fundamental flaws of passwords as the primary factor, and ultimately none of these have had the critical mass to solve the security or usability issues of passwords.
Take SMS OTPs, for example – sure, these add a layer of security, but ultimately this isn’t enough while also sacrificing user convenience. There are some techniques that have come through that offer truly high-grade security, but the need for a physical token has continued to be a hurdle to large scale consumer adoption.
Ultimately, it’s unsurprising that consumers and organisations alike have limped on grumpily with passwords. Until now, no other solution has come through as the ‘silver bullet’ to address security and convenience at scale and motivate action, allowing procrastination to ensue.
Another key element of this story is that getting consumers to adopt any new technology en masse is always slow and challenging.
But with the dawn of passkeys, we are seeing that consumers are up for making the move. A recent FIDO survey of US consumers found that readiness for passkeys is up nearly 20% since Autumn 2022, with over 57% of consumers saying they are interested in using passkeys to sign-in to their accounts.
Demand is even higher among those already preferring and using stronger authentication methods like biometrics. We found that 65% of people who prefer biometrics to authenticate themselves would be interested in using a passkey, while nearly half of those who prefer passwords would be.
This is hugely encouraging. For businesses and service providers that may be considering how they could and should bolster their authentication system, they should take these insights as a battle cry from consumers that they’re ready to finally make a change – and you should be encouraged to, too.
Passkeys differ fundamentally from previous approaches to improve the authentication process because they are a true password replacement that improves the sign-in experience for mainstream users, and we have evidence that people do indeed want them.
For the first time, there is an authentication approach that enables businesses and service providers to improve security and user experience at the same time.
Passkeys are the long-awaited answer to address the password problem head on. With major platform and service provider support, businesses and service providers need to now look seriously at their authentication system, stop procrastinating, and take the opportunity to finally bring in something new.
It’ll better protect them, their employees, their customers online, all while reducing friction to a degree that can have a major impact on their bottom line.
Andrew Shikiar is Executive Director and CMO at FIDO Alliance
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543