Passwordl-ish ≠ Passwordless
Eve Maler
The security industry loves bold claims, and few terms have spread faster than “passwordless.” But not every solution that wears the label deserves it. Many are really passwordl-ish — close, but not quite. And that distinction matters.
What “Passwordl-ish” Really Means
In The Princess Bride, Miracle Max Miracle Max observed that “There’s a big difference between mostly dead and all dead. Mostly dead is slightly alive.” Passwordl-ish is like that: removing most of the password risk, but not all of it.
Some solutions keep passwords off the runtime wire, giving users a “passwordless experience.” That can improve usability. But if passwords still exist in the system — even as a backup — then you haven’t eliminated the threat. You’ve just hidden it. True passwordless means secrets are gone entirely.
Why Half-Measures Get Marketed as Passwordless
The word “passwordless” is powerful. It signals a future free from static shared secrets. But passwords are deeply ingrained in IT. They’re cheap, universally supported, and easy to deploy. Ripping them out completely is hard, so marketing fills the gap.
The Hidden Risks of Passwordl-ish
At first, passwordl-ish looks harmless. If users only type a password occasionally, their day-to-day experience improves. But complexity shifts behind the scenes.
Recovery flows, cookie expirations, integration quirks — all still have to account for passwords. Those flows are easy for administrators to lose track of. And when they do surface, users may be unprepared: forgetting them, mishandling them, or running into confusing edge cases. That paradox can leave organizations less secure, not more.
What True Passwordless Looks Like
For users, true passwordless means fewer clicks, less reliance on memory, and flows that “just work.” Security isn’t bolted on with friction; it’s built in.
For security teams, it means nothing left to steal — no secrets floating around to sniff, phish, or reconstitute. Risk-based heuristics become support, not the foundation.
For IT, it means integration that’s both deep and seamless. It works across the systems employees actually use, without kludges or compromises.
Advice for Evaluating Solutions
When you hear “passwordless,” ask: Where does the first secret appear, and how is it protected? That one question reveals whether you’re looking at a true passwordless authentication method — or something for which a better name is passwordl-ish.
Closing Thought
Passwordl-ish may feel like progress, but settling for “mostly” leaves risk alive. It’s now possible to go all the way: to passwordless without compromises.