A few handshakes among a small group of Silicon Valley techies are presenting the best chance yet to wipe out passwords in favor of modern identity protection.
Near the end of last week's RSA conference, Google and Microsoft both showed off their biometric technology as a trigger for PayPal transactions without passwords. Both technology giants boasted how this technology would retire passwords for good. It's a common prophecy in technology, one that
So what's different this time?

Google and Microsoft are brandishing their ID technology days after agreeing to standards for the tools that integrate authentication checks onto browsers, websites and connected devices. The FIDO Alliance and World Wide Web Consortium have agreed to this
PayPal, for example, enjoys a
If that's enough to force
Programmers and vendors from across fintech have been
Google's plan is to use a fingerprint scan to approve PayPal purchases. Microsoft's plan is to use
PayPal, Microsoft and Google aren't alone. The authentication standards list includes Apple, which has advanced
The standards list also includes Alibaba, the dominant Chinese e-commerce company, which is affiliated with
"This has more potential than any other biometric single sign-on announcement I've ever seen," said Avivah Litan, a vice president at Gartner Research. "With the mobile phone being the way most people log in, it is a ubiquitous token if the phone's ID is supported by the operating systems. Then you have a nearly ubiquitous authentication mechanism."
The standard, called WebAuth, dictates how application programming interfaces are built and integrated. That supports FIDO's client-to-authenticator protocol, which in turn allows a device's security technology to transport phishing and malware-resistant authentication over USB, Bluetooth or NFC—connecting the device to secure in-app or contactless payments. So while the promise and technology are old, the way the devices communicate with each other is new.
The mobile environment will lead the way in dumping passwords, said Julie Conroy, a research director at Aite Group, who categorized the move away from passwords as a steady oozing rather than a dramatic shift.
In mobile devices, "technology like biometrics creates both a better user experience as well as greater security," Conroy said. "The computer-based environment will lag, just because consumers are still very comfortable. And worse, we have survey data from last year that shows that most consumers still believe passwords are an effective security mechanism, which we know is not true."
While the influence of the participants is the strongest encouragement of new authentication technology in years, that's also a double-edged sword, according to Litan.
"It gives those companies so much power, almost a monopolistic power," Litan said. "Whoever controls the credentials has tremendous control over the customer experience."
There's no argument to maintain passwords. Nobody likes
And what probably makes the Google/Microsoft/Apple/Paypal/Ant collaboration the best game in town is the far-off promise of other identity security innovation.
But widespread adoption of blockchain in general, and its broad use for identity protection, won't happen anytime soon.
"There's nothing else on the horizon that can solve this issue," Litan said. " 'Bring your own