Passwords Were Never the Point
Date Published

Most credential breaches don't start with someone guessing a password. They start with a password reused somewhere else that already leaked, a phishing page that looked close enough to the real thing, or a session token lifted from a browser that never expired. The password itself was often fine.
That's the case for passkeys and multi-factor authentication over yet another password-strength meter: they change what an attacker needs to steal, not how hard the thing they're stealing is to guess. A phishing-resistant second factor makes a perfectly guessable password a non-issue.
None of this makes authentication a solved problem — recovery flows, lost devices, and account takeover through support channels are still real weak points. But they're a different, more honest set of problems than "users should pick better passwords," which was never really the lever that mattered.