case file 04 · authentication

Prove it's you

For sixty-four years, computers have greeted humanity with the same demand: a secret, typed in the dark. This case file investigates the ritual — where it came from, how design shaped it, and why your face is quietly replacing it.

exhibit A · type a password (a fake one, obviously)
The meter is waiting. It has seen things.
this page has no server. nothing you type leaves this screen — that's the whole point of the article.
scroll to open the file ▾
the evolution of proving it's you
1961
MIT COMPATIBLE TIME-SHARING SYSTEM
LOGIN: corbato
PASSWORD:
// 1 CPU · 30 humans · 0 privacy
Change Password — IT Policy
New password (expires in 90 days):
✓ at least 8 characters
✓ one uppercase letter
✓ one number
✓ one special character
✗ must not resemble your last 24 passwords
EXPIRES IN 90 DAYS
Change Password — Revised Guidance
New passphrase (keep it as long as it's yours):
✓ long
✓ memorable
✓ checked against known breaches
✓ no forced expiry, no symbol circus
LENGTH BEATS COMPLEXITY — NIST, 2017
xW3qr9
I'm not a robot
side effect: you spent years digitizing old books, one wobbly word at a time
VERIFY-CO
Your code is 428 913. Never share this code with anyone.
VERIFY-CO
Your code is 119 407. Seriously, anyone.
⚠ FOOTNOTE
SIM-swap sold separately. NIST began quietly backing away from SMS codes in 2016.
a password you can't forget — or change
Sign-in request · Amsterdam, NL
PASSKEYFIDO2 · WEBAUTHN
no secret to steal
a key pair, born on your device, never typed, can't be phished, can't be reused against you.
1961 · MIT

The password is born on the Compatible Time-Sharing System — one computer, thirty researchers, and Fernando Corbató's simple fix for shared files. Within about a year, a PhD student named Allan Scherr printed the entire password file to get more computer time. The password and the password breach are practically twins.

2003 · THE RULES ERA

A NIST manager named Bill Burr writes the guidance that haunts you still: uppercase, number, symbol, rotate every 90 days. The result was predictable — literally. Humanity converged on P@ssw0rd1! and incremented the digit every quarter. Attackers noticed.

2017 · THE APOLOGY

Burr, retired, tells the Wall Street Journal: "I regret much of what I did." NIST rewrites the rules: length beats complexity, no more forced expiry, check against breached lists instead. One of the rare moments an industry admitted its ritual was theater.

2000s · PROVE YOU'RE HUMAN

Authentication grows a second question: not just who are you but are you even a person. CAPTCHA arrives — and reCAPTCHA turns your squinting into free labor, digitizing decades of old books and newspapers one wobbly word at a time. Tap the checkbox. It's load-bearing.

2010s · SOMETHING YOU HAVE

The second factor goes mainstream: a code, texted to the phone in your pocket. Better than nothing — meaningfully — but the phone number turned out to be stealable too. SIM-swapping made "something you have" into "something someone else briefly has," and NIST started backing away from SMS codes in 2016.

2013–2017 · SOMETHING YOU ARE

Touch ID (2013), then Face ID (2017), moved the secret into your skin. Design-wise it's the century's biggest authentication upgrade: the ceremony disappeared. Security-wise it's a trade: a fingerprint can't be guessed — and can't be rotated either. You only get ten.

2020s · THE FATIGUE ATTACK

Push approval seemed perfect: no codes, just a tap. Then attackers realized the button could be spammed until a human gives up. In 2022, Uber's network fell to exactly this — prompt after prompt until one exhausted contractor tapped Approve. You'll experience it yourself in a minute.

2022–NOW · THE EXIT

Passkeys: a cryptographic key pair instead of a shared secret. Nothing to type, nothing to phish, nothing to reuse. As of 2026 there are an estimated five billion of them in use. The password isn't dead — but for the first time in sixty-four years, it has a working successor.

the arithmetic of guessing

Why the rules never saved us

Every password is a bet about arithmetic: how long would a machine take to try everything? Here's the bet, at roughly ten billion guesses per second — with 2025's actual most-common password included for scale.

time to exhaust the search space · log scale, offline attack

"123456" has been the world's most common password in nearly every leak analysis since counting began. A quarter of the top 1,000 are pure digits.

~170
passwords the average person now juggles, per 2024 studies
25%
of the 1,000 most-used passwords are nothing but numerals
33%
of consumers got a breach notification in the past year (FIDO, 2026)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
the interrogation era

Your mother's maiden name is not a secret

For two decades, the backup plan for forgotten passwords was a quiz about your life — on the theory that only you knew the answers. The theory was wrong in a specific, researchable way: the answers were facts, and facts leak. Tap each exhibit to see where an attacker actually finds it.

"What is your mother's maiden name?"
tap to cross-examine
Found in: genealogy sites, public records, your cousin's family-tree project, and — famously — the 2008 breach of a US vice-presidential candidate's inbox, reset via exactly this kind of quiz.
"What was your first pet's name?"
tap to cross-examine
Found in: your own feed. There is a nonzero chance you posted a throwback photo of that exact animal, with its name, and a birthday. The attacker just scrolled.
"What is your favorite food?"
tap to cross-examine
Found in: statistics. Google's account-recovery research found attackers guessing "favorite food" got it in one try nearly 20% of the time. The answer was pizza. It's always pizza.
"In what city were you born?"
tap to cross-examine
Found in: your birthday posts, your school's alumni page, and any data broker with $2. Design lesson: knowledge-based authentication fails the moment knowledge becomes searchable — which was roughly 1998.
live experiment

Survive the fatigue attack

In 2022, an attacker with a stolen Uber password couldn't pass the push-approval step. So they didn't try to. They sent prompt after prompt after prompt — then messaged the contractor pretending to be IT — until the human did the human thing. Your turn: all you have to do is read one paragraph. Deny anything that interrupts.

your only job · read this

Push notifications were designed for consent — a doorbell for your account. But a doorbell that never stops isn't asking anymore; it's wearing you down. Security people call the result "MFA fatigue," and the name is honest: the attack isn't against your cryptography, it's against your patience. The defense that works isn't discipline. It's design — number matching, rate limits, and prompts that make "something is wrong" the easy conclusion instead of the paranoid one.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
how users see it now

The gap between knowing and doing

Users in 2026 are not confused about passwords being bad — they're exhausted. Before the numbers, calibrate yourself: which of each pair is safer?

round 1
A code texted to your phone
A code from an authenticator app
The app. SMS codes travel through a phone network and can be hijacked via SIM-swap; app codes are generated on the device and never travel at all. Both die to phishing, though — the code doesn't know who's asking for it.
round 2
Password + two-factor code
A passkey
The passkey. A fake login page can harvest your password and your code in real time. A passkey physically cannot be typed into a fake page — the cryptography checks the website's identity so you don't have to. It's the only option here that's phishing-resistant by construction.
round 3
8 characters of symbol soup, rotated monthly
A four-word passphrase you keep for years
The passphrase. This is Bill Burr's apology in one matchup: length beats complexity, and forced rotation mostly produces P@ssw0rd2!, P@ssw0rd3!, and a sticky note. NIST has agreed with the passphrase since 2017.

Now the field data, from the FIDO Alliance's 2026 global survey:

90%
of consumers have now heard of passkeys
75%
have enabled one on at least one account
49%
actually use them regularly when offered — the habit gap
47%
have abandoned a purchase because they couldn't remember a password

That last number is the design brief hiding in a statistic: authentication isn't a security screen users pass through. It's a checkout, a front door, and a mood — and half your users have walked away from money rather than face it.

closing argument

1961 vs. your face

Sixty-four years of evolution, side by side. Press start; both lanes attempt the same login.

LANE A · 1961–2016 STACK0.0s
password
code (texted)
LANE B · PASSKEY0.0s
waiting…

The ending isn't that passwords die — the ending is that the ceremony does. Authentication is dissolving into things you already do: holding your phone, looking at a screen, being where you usually are. The next design problem is already visible: when proving-it's-you becomes invisible, how does anyone know they're safe? Sixty-four years in, the answer is still being designed. Some of it by the person who wrote this case file.