The Prophets Were Wrong (Mostly) All articles
Tech & Internet Culture

Just Remember Your Password: How Fifty Years of Silicon Valley Prophets Kept Promising You'd Never Have To

The Prophets Were Wrong (Mostly)
Just Remember Your Password: How Fifty Years of Silicon Valley Prophets Kept Promising You'd Never Have To

Somewhere right now, a person is locked out of their own bank account. They are staring at a screen that is asking them to confirm which of their fourteen email addresses they used when they signed up in 2011. They are doing this because they have forgotten their password, which was itself a replacement for a password they also forgot, which was itself created after a data breach forced them to make something with at least one uppercase letter, one number, one symbol, and apparently the blood of a firstborn child.

This person should have been liberated decades ago. Multiple generations of technologists promised it. They were, with respect, completely wrong.

The Fingerprint Utopia of the 1970s

The dream of killing the password is older than most people realize. In the early 1970s, researchers at institutions like Stanford and MIT were already floating the idea that biometric authentication—fingerprints, voice recognition, retinal scans—would render memorized credentials obsolete within a generation. The pitch was clean and logical: your body is a key that you cannot lose, forget, or accidentally leave in your other pants.

Popular Science ran variations of this vision throughout the decade. Fingerprint readers, the articles assured readers, would be standard on home terminals by the 1990s. The technology existed in rudimentary form. The future was basically here. All that remained was scaling.

What actually scaled, of course, was the password. The internet arrived, then e-commerce, then online banking, then social media, and each new platform cheerfully issued you another set of credentials to misplace. By the time fingerprint readers actually appeared on consumer devices in the early 2000s—mostly on laptops that nobody used the feature on—the average American had accumulated more passwords than they had houseplants, and was watering neither.

The 1990s: When Passwords Were Going to Get Smart

The dot-com boom brought a fresh wave of prophecy. Passwords weren't going to disappear so much as evolve into something called "smart authentication." Single sign-on systems, digital certificates, and cryptographic keys were going to create a seamless, secure experience where one verified identity would travel with you across the entire internet like a well-behaved golden retriever.

Microsoft and Sun Microsystems both made serious plays at unified identity platforms. Wired magazine published breathless pieces about the coming death of the login screen. Security experts—who at this point were still allowed to make confident predictions without immediately being laughed out of the room—assured the public that by 2005, typing a password into a website would feel as archaic as sending a telegram.

What actually happened by 2005: people started writing passwords on Post-it notes and sticking them to their monitors. This is documented. It happened in offices across America. The IT departments of the nation wept quietly and updated their security policies, which nobody read.

The Biometric Renaissance (Attempt Two)

Apple's introduction of Touch ID on the iPhone 5S in 2013 felt, briefly, like the moment the prophets had been right all along. Here was fingerprint authentication that actually worked, on a device that 100 million people used every day. The obituaries for the password were filed with genuine enthusiasm. "The Password Is Dead" announced a chorus of tech journalists who had also announced this in 1998, 2003, and 2008, but who felt much more confident about it this time.

Then came the hacks. The elaborate workarounds. The discovery that a determined adversary could lift a fingerprint from a drinking glass and replicate it in gelatin. The revelation that facial recognition in its early consumer form could be defeated by a photograph. The dawning realization that biometrics, unlike passwords, cannot be changed after a data breach—a problem that is, when you think about it for more than eleven seconds, fairly significant.

Passwords did not die. They multiplied. Password managers became a booming industry, which is the tech sector's charming way of solving a problem it created by selling you a slightly more organized version of the problem.

The Passwordless Promise of the 2020s

Enter the FIDO Alliance, passkeys, and a new generation of passwordless authentication standards that are, genuinely, technically impressive. Apple, Google, and Microsoft all committed to passkey support in 2022. The headlines were familiar in their optimism: "Passwords Are Finally Dead." "Say Goodbye to the Password Forever." "The Password's Last Days."

And here is the thing—passkeys are actually pretty good. The underlying technology is sound. The security model is legitimate. This time, the prophets might even be right, mostly, eventually, for a significant portion of users, on platforms that have implemented the standard correctly, assuming their devices support it, and provided they haven't lost access to the device that holds the passkey, in which case there is a recovery flow that involves, and you will enjoy this, a password.

The Ledger

Fifty years of predictions. Fingerprints, retinal scans, voice recognition, smart cards, digital certificates, single sign-on, two-factor authentication, biometric fusion, behavioral analytics, and passkeys. Each one was supposed to be the thing that finally freed humanity from the tyranny of "MyDog2024!" (which, for the record, is not a secure password, but it is an extremely common one, and if your dog is named something other than Max or Bella you're at least beating the statistical average).

The password endures. It endures because switching costs are enormous, because legacy systems are immortal, because humans are resistant to change, and because every new authentication system eventually requires a fallback that is, at its core, a password.

The prophets were not stupid. The technology they described was real. What they consistently underestimated was the extraordinary tenacity of the thing they wanted to replace—and the equally extraordinary human capacity to choose convenience over security and then blame the technology when things go wrong.

Somewhere, a researcher is currently developing an authentication system that reads your gait, your typing rhythm, and the unique electromagnetic signature of your brain. It will work. It will be secure. It will require a backup password.

We'll see you in 2045.

All articles

Related Articles

Gather 'Round the Extinct Water Cooler: Forty Years of Predictions That Humans Would Stop Chatting at Work

Gather 'Round the Extinct Water Cooler: Forty Years of Predictions That Humans Would Stop Chatting at Work

Backpack Full of Broken Promises: Half a Century of Predictions That Textbooks Were Toast

Backpack Full of Broken Promises: Half a Century of Predictions That Textbooks Were Toast

Chalk One Up for the Skeptics: Six Decades of EdTech Prophets Who Couldn't Kill the Pencil

Chalk One Up for the Skeptics: Six Decades of EdTech Prophets Who Couldn't Kill the Pencil