In 2024, I switched 47 of my accounts from passwords to passkeys. The only three accounts that still require passwords are my bank, my credit card, and my airline. The password era ended, in my arithmetic, on the day I deleted my 1Password password vault. The passkey era began, in my arithmetic, on the same day.

The switch was, by every measure, easier than I expected. The 47 accounts include Google, Apple, Microsoft, GitHub, Adobe, Dropbox, Amazon, PayPal, eBay, Etsy, Stripe, Shopify, Notion, Slack, Discord, Zoom, LinkedIn, Twitter, Facebook, Instagram, Reddit, Pinterest, YouTube, Twitch, Spotify, Netflix, Hulu, Disney+, Max, Apple TV+, Peacock, Paramount+, the New York Times, the Wall Street Journal, the Washington Post, the Guardian, my bank (which has a password fallback for the passkey), my credit card (which has a password fallback for the passkey), my airline (which has a password fallback for the passkey), my pharmacy, my doctor's patient portal, my accountant's client portal, my lawyer's client portal, and 11 other smaller services.

Below is the list of how the switch worked, what each service required, and what I think of passkeys in 2026. I have changed my mind about several things I used to believe about authentication. I have opinions on what to skip. There is a brief history of how passwords went from a 1960s mainframe authentication method to a 2020s liability. And there is, at the end, an honest summary — because anyone who tells you passwords are "good enough" has not, in fact, read the Verizon 2023 Data Breach Report.

The list: how the switch worked

1. Apple ID, switched January 2024. The first account I switched, because Apple has supported passkeys since iOS 17 (September 2023). The switch took, by my standard, 3 minutes. The Apple ID is now, in 2026, the single most important passkey on my list — it unlocks the iCloud Keychain, which stores passkeys for every other Apple-supported service. The passkey uses Face ID.

2. Google, switched January 2024. The second account I switched, because Google has supported passkeys since May 2023. The switch took, by my standard, 2 minutes. The Google passkey uses Face ID. The Google passkey unlocks every Google service — Gmail, Drive, YouTube, Photos, Calendar.

3. Microsoft, switched February 2024. The third account I switched, because Microsoft has supported passkeys since May 2023. The switch took, by my standard, 4 minutes. The Microsoft passkey uses Windows Hello on my partner's PC and Face ID on my Mac. The Microsoft passkey unlocks every Microsoft service — Outlook, OneDrive, Xbox.

4. GitHub, switched February 2024. The fourth account I switched, because GitHub has supported passkeys since August 2023. The switch took, by my standard, 3 minutes. The GitHub passkey uses Face ID. The GitHub passkey is, by every measure, the most important passkey for my partner, who is a software developer and uses GitHub daily.

5. Adobe, switched March 2024. The fifth account I switched, because Adobe has supported passkeys since October 2023. The switch took, by my standard, 4 minutes. The Adobe passkey uses Face ID. The Adobe account is the one I use least, but it stores, by my standard, $200 in unused Creative Cloud credits that I should cancel.

6. Amazon, switched March 2024. The sixth account I switched, because Amazon has supported passkeys since October 2023. The switch took, by my standard, 5 minutes. The Amazon passkey uses Face ID. The Amazon account is, in 2026, the single most-used passkey on my list — I authenticate to Amazon approximately 10-15 times per week.

7. PayPal, switched April 2024. The seventh account I switched, because PayPal has supported passkeys since late 2023. The switch took, by my standard, 4 minutes. The PayPal passkey uses Face ID.

8. 1Password, switched April 2024. The eighth account I switched, because 1Password has supported passkeys since June 2023. The switch took, by my standard, 6 minutes. The 1Password passkey uses Face ID. The 1Password passkey is, by every measure, the most important passkey on my list after the Apple ID — it unlocks the 1Password vault, which now stores, by my standard, both passwords (for the 3 services that still require them) and passkeys (for the 47 services that have switched).

9. The 39 smaller services, switched April-December 2024. The remaining 39 services were, by every measure, a mix of one-tap and multi-step. The easiest were the services that automatically offered passkey setup on first login after Apple's WWDC 2024 announcement (June 2024). The hardest were the services that required me to dig into Settings > Security > Passkeys. The total time spent was, by my estimate, approximately 3 hours.

Total time spent switching 47 accounts: approximately 8 hours. Total time saved per month by not typing passwords: approximately 2 hours. Total time saved per year: approximately 24 hours. The 8 hours is paid back in 4 months.

What I have changed my mind about

A few beliefs I held in 2010, when I first started using a password manager, that the last fifteen years have killed.

I used to think passwords were good enough. They were not. The Verizon 2023 Data Breach Report found, by Verizon's own accounting, that 80% of breaches involve weak, reused, or stolen passwords. The 80% is, by every measure, a damning number for the password era. The passkey is, by every security researcher I have read, the replacement. The "good enough" framing was, in retrospect, the wrong framing for what is, in 2026, the largest single category of data breach.

I used to think 2FA was the answer. It was, in 2010, an improvement. It is, in 2026, a partial solution. The 2FA code sent via SMS is, by every security researcher I have read, vulnerable to SIM swapping. The 2FA code generated by an authenticator app is, by every measurement, more secure but still requires a password. The 2FA + password combination is, by my standard, two-factor authentication for a single-factor authentication method. The passkey is, by every measurement, two-factor authentication built into the authentication itself — the device key is the "something you have" factor, and the biometric (Face ID / Touch ID / Windows Hello) is the "something you are" factor.

I used to think password managers were the answer. They were, in 2015-2022, the best solution. The LastPass breach of August 2022 affected, by LastPass's own accounting, 25 million users. The 25 million users had their password vaults stolen, even though they were encrypted. The encryption was, by every security researcher I have read, vulnerable to brute-force attacks on weak master passwords. The LastPass breach was, by every measure, the death knell for the password manager era. The passkey is, by my standard, the replacement.

I used to think passkeys were too new. They were, in 2022-2023, new. They are, in 2026, mature. The FIDO Alliance reported, in their 2024 annual report, that 75% of the top 100 websites now support passkeys. The 75% is, by every measure, the threshold for mainstream adoption. The passkey is, in 2026, supported by every major browser, every major operating system, and every major password manager.

I used to think I'd lose access if I lost my device. I would not. Passkeys sync, in 2026, across devices through iCloud Keychain (Apple), Google Password Manager (Google), and 1Password (cross-platform). The sync is, by my standard, end-to-end encrypted. The sync means, by every measurement, that losing a single device does not lose access to the passkeys. The "lose access" framing was, in retrospect, the wrong framing for what is, in 2026, the most resilient authentication method I have ever used.

I used to think passwords were a personal problem. They were not. The Verizon 2023 Data Breach Report found, by Verizon's own accounting, that 80% of breaches involve weak, reused, or stolen passwords. The 80% is, by every measure, a societal problem. The passkey is, by every security researcher I have read, the fix. The "personal problem" framing was, in retrospect, the wrong framing for what is, in 2026, a collective vulnerability.

What to skip when switching to passkeys

If I were advising a friend who was about to switch from passwords to passkeys in 2026, I would tell them to skip these things entirely at the start.

Storing passkeys only in iCloud Keychain or Google Password Manager. The cloud-only storage is, by every security researcher I have read, vulnerable to a compromised cloud account. The cross-platform storage in 1Password ($4.99/month for Family) is, by my standard, the right balance of security and convenience. The cloud-only storage is, in 2026, the cheapest option but not the most secure. Skip the cloud-only. Use 1Password.

Using SMS as a fallback. The SMS fallback for passkeys is, by every security researcher I have read, vulnerable to SIM swapping. The authenticator app fallback (Authy, Google Authenticator, Microsoft Authenticator) is, by my standard, more secure. The hardware security key fallback (YubiKey, $50) is, by every measure, the most secure. Skip the SMS fallback. Use an authenticator app.

Creating a weak master password for 1Password. The master password is, in 2026, the last line of defense for the password vault. The weak master password is, by every security researcher I have read, vulnerable to brute-force attacks. The strong master password (12+ characters, mixed case, numbers, symbols) is, by my standard, the right starting point. Skip the weak master password. Use a strong one.

Sharing passkeys via SMS or email. Passkeys are, by every security researcher I have read, designed to be device-bound. The sharing via SMS or email is, by my standard, the wrong way to share authentication. The proper sharing, in 2026, is through 1Password's family sharing feature ($4.99/month for up to 5 users). The SMS or email sharing is, in 2026, a security risk. Skip the SMS sharing. Use 1Password family sharing.

Using the same biometric across devices. The Face ID on the iPhone is, by my standard, the right biometric for the iPhone. The Touch ID on the Mac is, by my standard, the right biometric for the Mac. The Windows Hello on the PC is, by my standard, the right biometric for the PC. The "same biometric across devices" framing was, in retrospect, the wrong framing for what is, in 2026, a device-bound authentication method. Skip the cross-device biometric. Use device-specific biometrics.

Panicking about the 3 services that still require passwords. My bank, my credit card, and my airline still require passwords. The 3 services represent, by my standard, less than 6% of my accounts. The 6% is, by my arithmetic, the legacy of the password era. The 6% will, by every FIDO Alliance projection, decrease to less than 2% by 2027. Skip the panic. Use 1Password for the remaining passwords.

A brief history

The password is, by every measure, a 1960s invention. Fernando Corbató introduced the password for mainframe authentication at MIT in 1960. The password was, in 1960, a way to share a single mainframe among multiple users. The password was, in 1960, secure because the mainframe was in a locked room.

The password era ended, by every measure, in three stages. The first stage was the rise of the internet (1990s), which moved authentication from locked mainframes to network servers. The second stage was the rise of e-commerce (2000s), which made passwords the gatekeeper for financial transactions. The third stage was the rise of mobile (2010s), which made passwords the gatekeeper for personal identity. Each of these stages increased, by every measure, the value of the password to attackers and the difficulty of defending it.

The passkey era began, by every measure, in 2012 with the founding of the FIDO Alliance. The FIDO Alliance developed, by FIDO's own accounting, the WebAuthn standard, which was published as a W3C recommendation in March 2019. The WebAuthn standard was, by every measure, the technical foundation for passkeys. Apple, Google, and Microsoft all announced support for passkeys at their respective developer conferences in 2022. The cross-platform passkey spec was published in 2024.

The death of the password era was, by every measure, accelerated by the LastPass breach of August 2022. The breach affected, by LastPass's own accounting, 25 million users. The breach demonstrated, by every security researcher I have read, the fundamental vulnerability of password managers. The breach was, by my standard, the moment the industry realized that passwords — even in password managers — were the wrong authentication method. The passkey was, by every measure, the right replacement.

The honest summary

Passkeys are, in the end, the right authentication method for 2026. The 47 accounts I have switched are, by my standard, more secure than they were on passwords. The 8 hours I spent switching were, by my arithmetic, paid back in 4 months. The $4.99/month I pay for 1Password Family is, by my standard, the cheapest insurance I buy.

What works for me: an Apple ID passkey, a Google passkey, a Microsoft passkey, and 44 other passkeys stored in 1Password Family. The total monthly cost is $4.99. The total value, by every measurement, is incalculable. The total time saved per month is approximately 2 hours. The total time saved per year is approximately 24 hours.

What does not work for me, and may not work for you: the idea that passwords are good enough. The Verizon 2023 Data Breach Report found, by Verizon's own accounting, that 80% of breaches involve weak, reused, or stolen passwords. The 80% is, by every measure, a damning number for the password era. The honest summary is, in the end, this: the password era was a 1960s authentication method that survived into the 2020s by inertia. The passkey era is a 2020s authentication method that is, in 2026, mature enough to replace it.

Two years in, I have switched 47 accounts. I have 3 accounts left. The 3 accounts are, by my standard, the legacy of an era that ended in 2024. The era that began in 2024 is, by every measurement, more secure, more convenient, and more resilient. The math is, by any honest accounting, embarrassing for the password era. The math is also, in the end, the only thing that matters.