The password has been declared obsolete at regular intervals for twenty years, and it has outlived every replacement announced with confidence. The current attempt is different in one important respect: it works, it is supported across major platforms and browsers, and the companies that have deployed it report the outcomes they hoped for.

It is also being adopted more slowly than almost anyone involved expected, and the reasons are worth understanding, because they are not technical.

Recovery is the hard problem

A passkey binds authentication to a device and a biometric or PIN. That eliminates the entire category of attacks built on knowing a secret, which is most of them: phishing, credential stuffing, reuse across breached sites. Security teams like it for exactly this reason, and cyber insurers have started asking about it in underwriting, which tends to accelerate adoption faster than any internal argument.

The problem is what happens when the device is gone. A password can be reset by someone who can prove they are the account holder, through a process every organization already operates. A passkey has to be re-enrolled, and the re-enrollment path becomes the weakest link in the entire scheme, because an attacker who can convince support to enroll a new device has defeated the cryptography without touching it.

Organizations that took this seriously built genuine recovery infrastructure: multiple registered devices, verified backup channels, and support procedures with real identity proofing. That is expensive and slow. Organizations that did not have quietly recreated the phishable secret they were trying to eliminate, one help desk call at a time.

The second obstacle is enrollment friction at a moment when nobody wants friction. Adding a passkey requires an interaction during a session the user came to do something else, and every prompt inserted into that session costs conversion. This is the same tension visible in invisible checkout design, where the commercial pressure runs consistently toward removing steps rather than adding them. Product teams measured on completion rates and security teams measured on credential compromise are optimizing different numbers, and the product teams usually own the flow.

Enterprise deployment has its own version. Passkeys assume a device with a secure element and a user with authority over it. Shared workstations, contractor laptops, kiosks and the long tail of manufacturing and healthcare environments do not fit that assumption cleanly, and the fallback for those cases is where the passwords keep living.

There is a procurement dimension that rarely appears in the security discussion. Passkey support has become a checklist item in enterprise software evaluations, which means vendors add it to close deals rather than because customers deploy it, and a surprising share of the support that exists in the market is unused. That is the same gap between purchased and adopted capability visible across sprawling software portfolios.

The realistic forecast is not elimination but stratification. High-value consumer accounts and employee access at security-conscious organizations move first and largely have. The long middle, small business software, legacy internal tools, anything with a login form written a decade ago, will keep a password field for years, because the cost of changing it exceeds the cost of the risk as currently priced. The thing that would change that arithmetic is insurers pricing the risk differently, which is already how a surprising amount of corporate security policy gets set.

Topics technology

Technology Correspondent

Priya Natarajan

Priya Natarajan reports on artificial intelligence, enterprise software and the infrastructure behind the modern internet. Her work focuses on how technical decisions become business decisions.