avalw news
Noah MitchellNoah MitchellVIEW PROFILE →

The Slow Death of the Password: Passkeys Hit 5 Billion but Struggle to Finish the Job

tech2026-08-31 · 3 min read · 0 reads

The FIDO Alliance estimates 5 billion passkeys are now in use, and 68 percent of organisations are deploying them. Passkeys log in successfully 93 percent of the time versus 63 for passwords, yet most services still keep passwords, and platform lock-in slows a truly passwordless future.

The humble password has been the weakest link in online security for decades. In 2026, its long awaited replacement is finally arriving at scale, as passkeys spread across the internet, though the transition is proving far messier than its champions had hoped.

Billions of passkeys, already

The scale of the shift is now hard to dismiss. The FIDO Alliance, the industry body behind the technology, estimates that around 5 billion passkeys are already in use worldwide, a remarkable figure for a standard still relatively early in its life.

Businesses are moving quickly too. According to a 2026 industry report, some 68 per cent of organisations are already deep into deployment, whether they are piloting, rolling out or fully integrating passkeys across their workforce.

What a passkey actually is

A passkey replaces the typed password with a cryptographic key unlocked by a fingerprint, face scan or PIN.
A passkey replaces the typed password with a cryptographic key unlocked by a fingerprint, face scan or PIN.

For the uninitiated, a passkey replaces the familiar typed password with something far harder to steal. Instead of a string of characters, it relies on a cryptographic key stored on a device and unlocked with a fingerprint, a face scan or a PIN.

That design closes off a whole class of attacks. Because there is no password to phish, to guess or to leak in a data breach, passkeys strip away the single most common route that criminals use to break into online accounts.

Consumers are warming up

Ordinary users are increasingly on board. Some 69 per cent of consumers now have passkeys enabled on at least a few of their accounts, a sign of how quickly the technology has moved from novelty toward something like normality.

Uptake varies sharply by country, however. Enablement rates reach 88 per cent in China and India, 77 per cent in the United Kingdom, 70 per cent in Germany and 64 per cent in France, reflecting different habits and different device platforms.

Turning that on is not the same as using it. Only about 49 per cent of consumers actually use passkeys whenever possible or most of the time, exposing a real gap between having the option enabled and genuinely relying on it day to day.

The numbers make the case

Where passkeys are used, the results are striking. They log people in successfully about 93 per cent of the time, compared with roughly 63 per cent for traditional passwords, which are so often forgotten, mistyped or reset by frustrated users.

Organisations feel the benefit as well. On average, those deploying passkeys report a 73 per cent reduction in sign in time and an 81 per cent drop in login related support tickets, easing a costly and persistent burden on help desks.

Users notice the difference too. Among the benefits people report are greater confidence in their security, faster logins and, importantly for the security world, a meaningful reduction in the phishing incidents that plague passwords.

Why the password refuses to die

For all the momentum, the old password is proving stubborn. Most services still require a traditional password alongside a passkey, which means the underlying attack surface has not actually shrunk as much as the headlines might suggest.

True passwordless security demands more. It requires removing passwords entirely rather than simply offering passkeys as an extra option, a step many companies have been reluctant to take for fear of locking frustrated users out of their accounts.

A walled garden problem

There is a final catch that frustrates many. A passkey created on an Apple, Google or Microsoft device is often locked into that company's own credential manager, making it hard to carry across platforms and leaving the dream of a truly seamless, password free internet still just out of reach.

Noah Mitchell
Stay updated
Noah Mitchell
Subscribe to get an email whenever Noah Mitchell publishes a new story. No spam, unsubscribe anytime.
Noah Mitchell
WRITTEN BY THE AUTHOR
Noah Mitchell
2026-08-31 · 3 min read · 0 reads
View profile →
VERIFY THIS STORY
ASK AI
MORE FROM Noah Mitchell
Report this articlesupport@avalw.com