• itscybernews
  • Posts
  • The password is 65 years old, and the world just started killing it for good — five billion times over. The new lock can't be picked. So the crooks walked around the back.

The password is 65 years old, and the world just started killing it for good — five billion times over. The new lock can't be picked. So the crooks walked around the back.

In partnership with

In 1961, a professor at MIT named Fernando Corbato had a very ordinary problem. His team had built one of the first computers that lots of people could share at once, and everyone wanted their own files kept private. So he invented a simple fix: give each person a secret word they type to prove who they are. The password was born.

It took exactly one year to break. In 1962, a PhD student named Allan Scherr wanted more computer time than his allowance allowed, so he found a way to make the machine print out every password on the system — and quietly helped himself. The world’s first password was followed, twelve months later, by the world’s first password breach.

Sixty-five years later, we’re all still living inside Corbato’s little invention — and still living inside Scherr’s little hack. You have dozens of the things. You reuse them, forget them, and get told off for both. Corbato himself, before he died, called the modern password “a nightmare.” Nearly every big hack you’ve ever read about started with a stolen, guessed, or reused one.

Here’s the good news, and it’s the kind this newsletter doesn’t get to write very often: the password is finally, actually dying. And the thing replacing it is genuinely better. In 2026 it crossed from a geeky option to the default, and it’s spreading at a pace security people find almost hard to believe.

Let’s start with the wonder — because for once, it’s real.

✨ The wonderful part: a lock with no key to steal

The replacement is called a passkey, and the simplest way to understand it is this: instead of a secret you know and type, a passkey is a secret your device holds and unlocks with your face or your fingerprint.

Under the hood, when you make a passkey, your phone or laptop creates a matched pair of digital keys. One — the private one — never leaves your device, locked behind your fingerprint or Face ID. The other — a useless-on-its-own public one — is handed to the website. To log in, the site sends a little puzzle that only your private key can answer, your device answers it after you glance at the camera, and you’re in. You never type anything.

That small change quietly fixes the three biggest problems with passwords at once:

  • There’s nothing to steal in a data breach. When a company gets hacked, the crooks make off with password databases. But the site only ever stored your public key — worthless without the private half sitting safely on your phone. A breach hands the thieves a pile of locks and no keys.

  • It can’t be phished. This is the beautiful part. A passkey is mathematically tied to the real website’s address. If a scammer lures you onto a perfect fake of your bank, your passkey simply refuses to work there — not because you were clever enough to spot the fake, but because the technology won’t let the key turn in the wrong lock. The single most common way people get hacked just… stops working.

  • There’s nothing to forget, reuse, or type. You glance at your phone and you’re in.

And people are noticing. Passkeys log you in successfully about 93% of the time, versus 63% for passwords — Google says passkey sign-ins are roughly four times more successful than typing a password (FIDO Alliance / Deepak Gupta, 2026). Faster and safer is a combination that basically never happens in security. Usually you pay for one with the other.

Here’s the cool part — the scale of how fast this is happening:

  • The FIDO Alliance’s State of Passkeys 2026 report estimates 5 billion passkeys are now in active use, with 90% of consumers aware of them and three in four people having turned one on somewhere.

  • Google reports over 800 million accounts now use passkeys. Amazon says 175 million of its users created one in the first year alone.

  • Microsoft made passkeys the default for new accounts and began switching them on automatically for millions of business users — and saw passkey use jump 120%.

  • 87% of companies across the US and UK have deployed passkeys or are rolling them out, and 69% of ordinary people now have at least one — up from 39% just two years ago.

That’s not a niche gadget. That’s the plumbing of the internet being replaced under our feet, quietly, this year. If you’ve unlocked something lately with your face and thought “huh, it didn’t ask for my password” — that was a passkey. You may already be using them without knowing the name.

So what’s the catch? The catch is a very old lesson: when you make the front door impossible to break, thieves don’t give up. They look for another way in.

🎭 The trapdoor: nobody picks the lock anymore — they knock on the back door

Here’s the twist that the breathless “passwords are dead!” headlines skip over.

The passkey lock really is, for all practical purposes, unpickable. So the criminals did the rational thing: they stopped attacking the lock entirely and went hunting for the back door every account keeps for emergencies — the “I lost my phone, let me back in” recovery flow. Security researchers have watched attackers systematically shift their effort away from the login itself and toward these recovery pipelines instead (Netcraft, 2026).

There are three back doors worth knowing about.

1. The “recovery” back door. Almost every account still lets you get back in the old way if you’re locked out — a code texted to your phone, a reset link to your email, a call to a help desk. Attackers now target those instead. They’ll social-engineer a support agent, hijack your phone number, or break into the email account you’d use to reset everything else. Your fancy passkey is irrelevant if the crook can just click “I can’t use my passkey” and take the scenic route.

2. The downgrade trick. This one is clever. Security firm Proofpoint documented a real attack against Microsoft’s login system where a scammer’s fake page pretends your browser doesn’t support passkeys — so the system politely offers you a weaker option instead, like a text-message code. You think you’re just signing in a slightly different way today. Really, you’ve been quietly nudged off the unpickable lock and onto the pickable one (The Hacker News, 2025). The rule of thumb: any time a login suddenly won’t let you use your passkey and pushes you toward a code or password, be suspicious. That downgrade is the whole attack.

3. The cloud back door. Most passkeys “sync” — they back themselves up to your Apple, Google, or Microsoft account so that when you buy a new phone, they follow you over. Lovely for convenience. But it means your passkeys are now only as safe as that one master account. If someone breaks into your Google account (or talks their way through its recovery), they can potentially restore your passkeys onto their own device. The strong new lock is only as strong as the cloud vault holding the spare key.

None of this means passkeys are a con. They genuinely close the front door that most attacks used to walk through. It just means the job isn’t finished at “turn on passkey.” The job is finished when you’ve locked the back doors too — and that part is on you. Good news: it takes about ten minutes.

🛡️ The good news: locking the back door is quick, and mostly common sense

You do not need to be technical for any of this. Passkeys have already done the hard part — they’ve made your everyday logins dramatically safer with zero effort from you. These few habits close the remaining gaps.

  • Set up a backup so you can never be locked out — or locked in a corner. The number-one fear people have (“what if I lose my phone?”) is also a real security setting. Register a passkey on more than one device — say, your phone and your laptop, or a cheap physical security key you keep in a drawer. Now losing one gadget is a minor annoyance, not a crisis, and you’re never forced into a sketchy “emergency recovery” that criminals love to exploit.

  • Guard your email like it’s the master key — because it is. Almost every account on earth can be reset through your email. If your email is protected only by an old password, you’ve fitted a titanium front door to a house with an open kitchen window. Put a passkey on your email account first, before anything else.

  • Clean out the old, weak “get back in” options. In your important accounts, open the recovery and sign-in settings and remove the leftovers you don’t need — especially text-message codes as a fallback, if the account lets you rely on passkeys and an authenticator app instead. Fewer back doors, fewer ways in.

  • Treat any surprise “sign in the old way” as a red flag. This is the single most useful habit. If a site you always breeze into with your face suddenly claims it can’t do passkeys today and asks you to type a password or a texted code, stop. That’s exactly what the downgrade attack looks like. Close the tab, open the app or type the address yourself, and try again.

Protect the cloud account that holds your passkeys. Your Apple, Google, or Microsoft account is now the vault. Give it the strongest protection on offer — its own passkey, a proper authenticator app, and a recovery method only you control.

That’s the whole checklist. Turn on passkeys, keep a spare, guard your email and your cloud account, and get twitchy whenever something tries to walk you backward to a password.

✅ What to actually do

This week, pick the row that’s you:

  1. You just want to be safer with minimal fuss: turn on a passkey for your two most important accounts — email and your bank — next time each one offers (“sign in faster with Face ID or your fingerprint”). Say yes. Then set one up on a second device too, so you’ve got a spare. That’s a bigger security upgrade than any password you’ve ever chosen.

  2. You run a small business or a team: ask whoever handles your tech three questions — Are we offering passkeys for our logins? Have we killed off text-message codes as a fallback where we can? And is our account-recovery process something a smooth talker on the phone can’t just bypass? The lock is solved; the back door is where you’ll actually get robbed.

  3. You’re just here to understand it: the one line to remember is — passkeys make the lock unpickable, so the crooks now attack the “I lost my phone” back door instead. Keep a backup way in, protect your email above all, and never trust a login that suddenly insists on doing things the old-fashioned way.

And zoom out:

Notice that, for once, the safe path is also the easy path. For thirty years, security advice meant more hassle — longer passwords, more codes, more friction. Passkeys are the rare case where the more secure option is genuinely nicer to use. When that happens, take the win. Say yes when your phone offers.

The takeaway

The password had a good run. Sixty-five years, from a shared computer at MIT to the sticky note on your monitor. It was breached one year after it was invented, and it’s been quietly leaking our lives ever since. Watching it finally go is a small cause for celebration.

Its replacement is that rare thing in security: faster and safer, spreading to billions of people this year, and built so that the most common attack on Earth — tricking you into typing your secret onto a fake page — simply cannot work. If you do nothing else after reading this, turn one on for your email.

But don’t let “the lock is unpickable” lull you into thinking the house is sealed. Clever thieves don’t stand at a door they can’t open — they wander around the back and try the windows. The windows here are the emergency ways back into your account. Shut those too, keep a spare key of your own, and you get the whole prize: the end of the password, without swapping it for a nastier surprise.

Log in easy, stay curious.

itscybernews

Know someone who still keeps their passwords in a notebook (or reuses the same one everywhere)? Forward them this — the “put a passkey on your email first” tip is the single best five minutes of security they’ll spend this year. And hit reply to tell us what you’d like us to dig into next: we read every one.

Sources

FIDO Alliance — State of Passkeys 2026: https://fidoalliance.org/

Netcraft — Phishing after passkeys: what attacks to expect: https://www.netcraft.com/blog/phishing-after-passkeys-what-attacks-to-expect

The Hacker News — How attackers bypass synced passkeys (downgrade attack): https://thehackernews.com/2025/10/how-attackers-bypass-synced-passkeys.html

cybernews — The first computer password (1961; Corbato; Scherr, 1962): https://cybernews.com/security/first-computer-password/

Stop making AI decisions in the dark.

Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.

You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.

You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.

CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.