Why passwords are no longer a reliable way to prove your identity
A cybersecurity expert explains why password reuse and poor digital habits remain a major cause of cyberattacks, and points to digital identity as the way forward beyond passwords.

In an opinion piece, Ludmila Bērica, head of SK ID Solutions' Latvian branch, argues that nearly sixty years after passwords were introduced in digital services, they remain the dominant way people prove their identity online — even though data breaches and account takeovers have not meaningfully declined. She contends the real issue is no longer password strength, but reliance on passwords as an identity check in the first place.
The article cites a 2026 PasswordManager.com survey showing 84% of US adults admit they don't use a unique password for every account, while a BitWarden study found a quarter of respondents across several countries reuse the same password on 11 to 20 or more accounts. Younger users are aware of the risk but often ignore it anyway. A Cybernews analysis of passwords leaked in 2024–2025 found that 94% of them were repeats, with "123456" the most common.
Industry recommendations
According to the author, major technology companies and cybersecurity bodies, including Verizon and Microsoft, are pushing for a shift toward multi-factor authentication and passwordless solutions, such as Smart-ID, already widely used in the Baltics. These combine something a user has (a device) with something they know (a PIN), making it far harder to simply hand access to someone else, unlike a password.
The piece also highlights an advantage of digital identity systems: the ability to confirm a single fact, such as whether someone is old enough, without revealing full personal data. This is becoming more relevant under the EU's Digital Services Act and rules on protecting minors online. Europe is also developing the EU Digital Identity Wallet, which will let people manage and prove various identity attributes in one place, gradually replacing passwords.


