Most people have been in the frustrating situation of being locked out of an account and seeing the “forgot your password?” link for what seems like an endless number of times. It only seems like a small problem. But that moment captures something much bigger: a system that is decades old and is way past its prime, held together mostly by habit.
A few weeks ago, the European Commission made that tension very public. The European Commissioner for Technological Sovereignty and Data Security, Henna Virkkunen, gave a very serious warning: quantum computers could break even the most complex encryption systems in just seconds, and the defenses we have now may not work in four years. All of this information could be leaked, including private messages, bank information, business records, and secret government documents. By 2030, the EU wants to have all of its important systems switched to post-quantum cryptography. That deadline wasn’t picked at random.
Once upon a time, password authentication made sense. A secret set of characters that is kept somewhere and compared to what the user types. It’s simple, cheap, and simple to set up on any platform. It was enough for about thirty years. But the architecture was always weak in ways that the business world was slow to admit. Accounts being stolen, passwords being used on dozens of different accounts, and the fact that some of the most common passwords are still variations on “123456” are all common problems. They’re normal.
Biometric authentication has been changing that picture in the background. Scanners for fingerprints, faces, and irises don’t need to know what a person knows; they just need to know what they are. That change is more important than it seems at first. In a practical sense, biometric data can’t be moved. It can’t be caught by a fake login page or guessed by a script that tries a million different combinations. Having a fingerprint that is linked to a certain device is a very different kind of lock than having a twelve-character string stored on a server. Adoption has been slower than developers had hoped, in part because people are worried about how to keep data safe and what will happen if biometric systems fail. But people are slowly getting used to the technology.

Passkeys are probably the clearest sign of where things are going. Passkeys are a type of public-key encryption that was created by Apple, Google, and Microsoft. One key is stored on the user’s device, and the service itself has a second key. No one’s shared secret is stored on a server, ready to be broken into. Almost by design, they don’t fall for phishing. They can also be synced between devices, so you don’t lose access when your phone breaks. Some platforms are still behind, and the technology isn’t fully used everywhere yet, but it’s clear that things are moving in the right direction.
79% of people who attended the 2023 BlackHat USA Conference who were polled thought that passwords were already becoming outdated. Almost three quarters said they used some kind of multi-factor authentication. Of course, that group is mostly technical, but security experts often see what’s coming before the rest of us do.
It’s still not clear how the change will affect most people, especially those who aren’t very good with technology or who live in places where everyone can’t access their devices. Because the EU roadmap lets each member state set its own schedule, the shift will happen in different ways. There will be faster and slower growth in different fields. No one wants to admit it, but legacy systems will last longer than anyone thinks.
Still, it’s amazing how quickly the conversation has changed. From passwords being the unquestionable standard to a serious push by institutions toward post-quantum encryption, 2030 seems less like a guess and more like a reckoning. It was a long time in the password. What comes next might not be as memorable, but it will be a lot harder to break.
