Ahad, 13 September 2026


Passwords were annoying.

Too many of them. Too many rules. One needs 12 characters, another wants a symbol, another somehow rejects the symbol you just used.

So we asked for something easier.

Now we unlock our phones with our face.

That feels better.

No typing. No remembering. No “forgot password” email at 2AM.

Just look at the screen and you're in.

But think about what changed.

A password is something you know.

Your face is something you are.

That is a very different kind of credential.

If a password leaks, you can change it.

If your face becomes part of an authentication system, things get more complicated.

You cannot exactly update your cheekbones.

That does not mean Face ID or biometric authentication is bad. In fact, for most people it is far better than reusing the same weak password across multiple apps.

The real issue is that convenience has slowly changed how we think about identity.

We used to log in with something private that existed only in our head.

Now our phone can recognise our face, our fingerprint can approve a payment, and passkeys can authenticate us using the device we already carry everywhere.

Honestly, that is pretty convenient.

But convenience always comes with a trust question.

Where is the biometric data stored?

Does it stay on the device?

Can an app access it directly?

What happens if someone forces you to unlock the phone?

What happens when the phone itself becomes the thing proving who you are?

This is where passwords are slowly disappearing from the centre of digital identity.

Not because identity got simpler.

Because it moved somewhere else.

The broader cybersecurity version of this shift is explored in The New Security Perimeter Does Not Have a Network. It Has an Identity., where identity itself becomes one of the main control points in modern technology.

For everyday users, though, the strange part is much simpler.

We spent years complaining that passwords were too difficult.

Technology listened.

Now our face, fingerprint, phone and account ecosystem are all becoming part of the login.

Which is easier.

Probably safer too.

But also a little weird when you realise the thing replacing your password is basically... you.