Every few months a keynote buries the password. Passkeys have won, the slide says, and passwordless is one project away. It's a good story. It also skips the part that costs money.
Passkeys deserve the enthusiasm, up to a point. They're phishing-resistant, they leave no reusable secret lying around to be lifted, and they are genuinely where identity should be heading. The direction isn't in doubt.
What's oversold is the switch. "Passwordless" in the announcement is a finished product. In your estate it's a migration with a long and awkward tail: the legacy application that only speaks passwords, the VPN that predates the idea, the shared shop-floor login, the service accounts, the third party who hasn't heard of any of this. You run both worlds side by side for years, not weeks.
There's a subtler trap underneath. Take the password away and account recovery becomes the real front door. Lose a phone, break a laptop, and something has to let you back in. If that something quietly falls back to a code by email or SMS, you've reintroduced the very weakness you thought you'd removed, now sitting behind a more expensive rollout. A half-finished passwordless programme with a sloppy recovery path can be weaker than the password estate it replaced.
So the questions worth asking aren't about the demo. They're about the tail:
- What is the recovery path, and is it as strong as the passkey it restores?
- How much of the estate genuinely can't do this yet, and who owns that list?
- Are we running both worlds deliberately, or by accident?
The password dies the day the last system that needs one is switched off, not the day a vendor says so. Until then, the recovery path is the perimeter.