Sunday, August 9, 2026

UNDER THE KEYBOARD

Remember when passwords were simple?  You had one.  Maybe two if you were particularly security conscious. And where did you keep them? On a little piece of paper tucked under your keyboard, of course. For years, that seemed perfectly reasonable. We weren't protecting the nuclear codes. We were trying to get into AOL.


Then the internet grew up, and suddenly we needed passwords for EVERYTHING. Email. Amazon. The bank. The library. Facebook. Netflix. The pharmacy. The doctor's office. The electric company. Every store where we bought a pair of socks once in 2014.

Naturally, many of us used the same password for everything. That turned out to be a VERY BAD IDEA.

So the experts told us every account needed a different password. And not just any password. It needed an uppercase letter, a lowercase letter, a number, a symbol and presumably the maiden name of our third-grade teacher's hamster.

Eventually password managers arrived. I was a relatively early convert and now use 1Password. Instead of remembering dozens — okay, probably hundreds — of passwords, it remembers them for me. Progress!



Then came two-factor authentication. You enter your password. The website essentially says, "We don't believe you.” So it sends a six-digit number to your phone. You retrieve the number, go back to the website and type it in. "Fine," the website says. "You may enter." And now, just when I thought I understood the rules, apparently passwords themselves are on their way out.

Welcome to the age of the PASSKEY.

I read a fascinating NYT Wirecutter article about passwords and passkeys this week and discovered I've apparently already been using passkeys without giving them much thought.

Instead of typing a password, you prove you're you the same way you unlock your phone or computer — with your face, fingerprint or PIN.


I already use Face ID for all sorts of things, including Apple Cash. (I recently told Mr. 12 that when I die, he'd better hang onto my body for a while so he can keep holding my phone up to my face to send himself money). (He seemed remarkably untroubled by this plan).

Which brings us to passkeys.

Behind the scenes, some very clever cryptography takes place. I do not understand the clever cryptography. I do not NEED to understand the clever cryptography. This may be my favorite part.

The important thing is that a passkey is much harder for the bad guys to steal because there isn't a password for us to accidentally give them. And we don't have to remember anything.

Passkeys aren't everywhere yet, so for a while we're going to live in a strange hybrid world of passwords, password managers, verification codes, Face ID and passkeys.

But I like where this is headed. Think about the journey. We started with one password written on a scrap of paper under the keyboard. Then we needed 147 passwords no normal human could possibly remember.

So we invented software to remember them for us. Then we added another step to prove we were really us. And now we're inventing a system where we don't have to remember a password at all.

It only took about 30 years to get there.

Of course, I haven't thrown away 1Password. I'm not THAT brave. Besides, somewhere in America right now, there's still a website asking:

What was the name of your first pet?

And somewhere else there's probably still a little piece of paper under a keyboard.

Some technology dies harder than others.

4 comments:

  1. I do not understand Passkey and have resisted the push to convert to them even though I'm badgering by several sites I go to. I also have never trusted the safety of password keeping programs. Three times I've been put on notice from 2 BIG companies in healthcare or 1cfinancial institutions that they were hacked and my formation "out there." If they can't keep from getting hacked, changing the way I get into sites isn't going to matter. I still keep a book of my ever changing passwords. I miss the old days of having one or two!

    ReplyDelete
    Replies
    1. Passkey is the BEST way to keep people from using your files. You need your fingerprint or your face. Hackers can't do that ... yet.

      Delete
  2. I prefer Fingerprint ID or Facial Recognition, it's what they always used at the DA's Office and I'd prefer it to be used for everything coz I always have my Fingerprint and my Face with me. And my Memory Care Issues are getting in the way of Life now to some degree.

    ReplyDelete
    Replies
    1. Ah ha ha! I totally agree ... we do always have those two forms of ID with us. So many other things to memorize these days ...

      Delete

They Don’t Want My Cherished Treasures

I have downsized.  Repeatedly. At one time I owned seven sets of dishes. Yes, seven. And that doesn't count the two sets of Christmas di...