
The future has no passwords
The future has no passwords: how passwordless authentication changes everything (and is still an easy step towards better security)
If you have been around long enough, you remember that once we only needed a password of 6 characters to be safe. Hackers didn’t have the tools nor the means to crack passwords at large scale. But stepping into 2026 we all know and have been reminded numerous times that a password isn’t safe anymore. It’s easy to understand why:
- The computer power a hacker has at hand rises every minute. The time it takes to “guess” a long password becomes shorter. If two years ago a 12-character password would be regarded as impossible to crack, you would now need 16+ characters to have a safe password.
- You cannot use the same password for different applications. Every application needs a unique password.
- Needless to say, when you have 100 applications and all of them need a 16+ character password that is unique, it’s impossible to remember all these passwords.
- Every measure you take to make it easier for you to remember a password will also make it easier for a hacker to crack the password.
What happens in the real world then?
- People are still using weak passwords.
- The same password is used over and over again.
- Password managers are a very good tool to suggest and remember complex passwords, but can be vulnerable to attacks too, and cannot be used on any system.
- There are 17,431,283,012 pwnd accounts easily available for hackers, and every minute the number is rising. If your password is amongst the list of leaked passwords, hackers have access to it and they can simply upload an Excel file into their system and start guessing.
You can use the free tool HaveIBeenPwned.com to check if any of your accounts are in a list of hacked or leaked accounts. If they are, you should instantly change your password, add Multifactor Authentication, or change to a passwordless solution.

How does passwordless work?
One of the many perks of a passwordless solution is that it is user friendly. However, it still requires some more effort then e.g. a password manager that automatically inserts a user name and password. Although it seems cumbersome at times, the true benefit lies in the security it offers.
Let me give you an example of how passwordless works: when I login in my Hotmail account that I already have since the nineties, I’m no longer asked to enter a password, but I’m asked to choose which authentication method I want to use. If you’re always logging in from the same computer or smartphone, you can add a local passkey, e.g. the 6 digits you use to login to your computer or the face recognition on your smartphone. As it’s a Hotmail account that I use on several machines, I have to scan a QR code with my smartphone and with face recognition I’m allowed to login. It’s incredibly safe, because someone would need my phone and my face just to login. But I have to take my phone out of my pocket, scan and click before I can login.
You can make it virtually impossible to hack an account by using a hardware token to authenticate. Friendly hacker Rachel Tobac, a well-known security expert, describes it as the point when a hacker stops. If they find out that a hardware token is used, it’s not worth the try anymore to hack the account. You can watch the replay of a webinar with Rachel Tobac that will give you some interesting insights: Replay: Cyber Self-Defence: Strategies for Safeguarding Personal Data with Ethical Hacker Rachel Tobac (you need to register before you can watch).

And how can I start with it?
The FIDO association has been working on passwordless solutions for a long time. They want to make it possible to eliminate the use of passwords, for the benefit of more security. It took until a couple of years ago to get Microsoft on board, but now that they have joined the program, the most often used applications can use a FIDO solution to login.
Although Microsoft will be most often used, and they offer the solution themselves too with Windows Hello, not every application or machine can use the Microsoft software. Specialist companies provide a broader platform that will secure Microsoft accounts, as well as other accounts and machines, even if the internet is down. They also offer an extra layer of security and convenience, e.g. with an app that detects if your smartphone has been compromised or an application that leverages AI to decide if it’s necessary to use an extra authentication layer. If you’re working from home, on the computer you always work on and on the regular home network, there is no need for extra security. The same goes if you’re travelling regularly to the same locations, the application will know and lets you easily authenticate. But if something is out of the ordinary, you will need a stronger authentication to make sure only the right person can login.
Start small, expand when possible
Going passwordless doesn’t have to be a massive leap. With the right solution you can take a phased approach, starting with a high-risk user group first, and then expanding passwordless adoption over time.

