Platform
Solutions
Resources
Company
Platform
Solutions
Resources
Company

Nick Morgan
∙
Fighting the Digital Password Pandemic


Nick Morgan
∙
Fighting the Digital Password Pandemic


Nick Morgan
∙
Fighting the Digital Password Pandemic

Usernames and passwords are the root cause behind phishing, credential theft, and many of today's breaches, in the same way a virus is the root cause of the illnesses that follow it. Traditional two-factor authentication works like a mask: it makes hacking harder without removing the cause. Eliminating usernames and passwords works like a vaccine: it removes the cause itself.
Update: The article's central point still holds. Verizon's 2025 Data Breach Investigations Report still found credential abuse to be the most common initial access vector in breaches.
The Analogy at a Glance
Approach | The health analogy | What it does | Trade-off |
|---|---|---|---|
Usernames and passwords | The virus | The root cause of compromised systems, phishing, and ransomware | Breachable despite layers of digital protection |
Traditional two-factor authentication (2FA) | A mask | Makes hacking more difficult | Cheap and easy to implement, but doesn't eliminate the root cause |
PKI and smart cards | The first vaccine | Removes usernames and passwords | High cost and complexity kept it out of reach for most businesses and consumers |
WWPass | A new-age vaccine | Removes usernames and passwords while making security accessible, affordable, and easy to use | Uses hardware infrastructure already available in popular tech |
What a Pandemic Can Teach Us About Cybersecurity
If 2020 has taught us anything, battling a virus is not easy. It takes a range of methods to protect those around us, from staying inside to wearing masks. Even with this, COVID-19 feels like it's everywhere.
In 2021, vaccines built on cutting-edge mRNA approaches have revolutionized disease control, tackling the virus in an entirely new way. Scientists have finally found a way to beat COVID-19, but this year will be about the vaccine's widespread distribution over former preventative measures.
With the revolutionary advancements made in virology, why don't we take the same approach to cybersecurity?
Hacking Is Our Epidemic
In 2021, hacking is our epidemic. The FBI's Internet Crime Complaint Center saw cybersecurity complaints jump by as much as 300%, from about 1,000 a day to 3,000-4,000, since the beginning of the pandemic. There has even been a spike in virus-related email scams, according to Google.
COVID-19 as a virus is the root cause of diseases like pneumonia and larger organ failure, which can lead to death. To save lives, scientists are looking to kill the root cause of these pandemic deaths: the virus. If they make sure those with the vaccine never even have a chance to get COVID-19, they also cut down the chance they suffer from the various diseases associated with it.
The same is true for cybersecurity.
The Root Cause: Usernames and Passwords
The man-made digital virus was created in the 1960s when computer scientists at MIT were looking for a way for multiple users to share the resources of one computer. Their solution: create individualized usernames and passwords. This proved to be a great solution with minimal issues early on, establishing usernames and passwords as mainstays in most technology following, including into the 21st century.
However, that security didn't last. Similar to COVID-19, usernames and passwords eventually proved to be the root cause of compromised computers. They would eventually give rise to hacked systems and massive costs for businesses to restore their digital infrastructures. It spurred more hacking avenues, like phishing and ransomware.
The First Vaccine: PKI and Smart Cards
To combat this, technologists tried to develop a vaccine to take out the root cause, usernames and passwords, and in turn the diseases and issues they caused. Known as a public key infrastructure (PKI) and utilizing smart cards, this technology, which was invented in the late 1970s, was used by government agencies like the Department of Defense to remove username and password use.
The same idea has since been utilized by credit card companies with in-card chips, practically replacing a card number and PIN (which effectively represent a username and password) with a secure chip card.
PKI and smart cards worked well, with the Department of Defense relying on them to protect access to its systems. In 2004, tech giants like Bill Gates declared the gradual death of usernames and passwords following the success of a more secure system. The main thing holding back the PKI-based login system from widespread use was the high barrier of entry in cost and complexity. The average business or consumer didn't have the budget to implement it or sophisticated IT departments to manage it.
The Mask: Two-Factor Authentication
Instead of the widespread use of this digital vaccine, consumers opted for more mask-like solutions. They took to traditional two-factor authentication (2FA) methods, which were cheap and easier to implement, but at the cost of lessened security compared to PKI. While it made hacking more difficult, it didn't eliminate its root cause in usernames and passwords, making users more secure than before, but not entirely eliminating the risk of traditional logins.
SolarWinds: A Reminder That Passwords Still Fail
The SolarWinds hack, an allegedly Russian SVR-led attack on multiple commercial and government agencies across the globe, put a spotlight on how breachable usernames and passwords still are, despite a plethora of digital protections. Congress and the press focused on a password as simple as "solarwinds123" that was reportedly protecting a SolarWinds server. SolarWinds has said the credential belonged to a third-party application and had nothing to do with the SUNBURST attack, and, at the time, the company was still investigating how the attackers got in. Either way, a password that simple guarding company infrastructure shows how easily usernames and passwords fail.
Many other attacks have been carried out by leveraging usernames and passwords, too. The SolarWinds episode also once again raises a need for a more secure alternative to 2FA and a more accessible form of cybersecurity than PKI and smart cards. Above all else, it questions why we've continued to utilize usernames and passwords, which have continually been used as tools to benefit hackers long beyond their point of obsolescence.
A New-Age Vaccine: Removing Usernames and Passwords
Similar to the multiplicity of COVID-19 vaccines designed by different pharmaceutical companies, there are quite a few technologies besides PKI that allow for the complete elimination of usernames and passwords.
More than a decade ago, WWPass created its own usernameless and passwordless solutions to eradicate the root cause of hacker attacks that were using usernames and passwords, as well as the diseases that came with them. They build on the fundamentally successful aspects of PKI that remove the need for these dated logins, but leverage modern technology to make security accessible, affordable and easy to use. The hardware infrastructure required is at our fingertips already with popular tech. It's a privacy and security-first approach that's a cutting-edge, new-age vaccine for our digital world.
The result is giving businesses and consumers a chance to say no to living life behind a faulty digital mask and choosing the safety of a new-age WWPass vaccine. It's a life without the flaws and uncertainties of insecure usernames and passwords. It's taking a new approach to protection that significantly reduces risks of future hacker attacks.
FAQ
Why are usernames and passwords called the root cause of breaches?
Attackers keep targeting them, and credential abuse remains the most common initial access vector in Verizon's 2025 DBIR. Phishing, which often aims at stealing login credentials, and other attacks build on that weakness.
How is two-factor authentication different from removing passwords?
Two-factor authentication adds a second check on top of a username and password, which makes hacking harder but leaves the root cause in place. Removing usernames and passwords eliminates the credential itself.
Why didn't PKI and smart cards replace passwords everywhere?
Cost and complexity. They worked for organizations like the Department of Defense, but the average business or consumer lacked the budget to implement them or an IT department to manage them.
Did the "solarwinds123" password cause the SolarWinds hack?
That was never established. SolarWinds said the credential belonged to a third-party vendor application not connected to its IT systems and had nothing to do with the SUNBURST attack. The password still shows how weak credentials can end up protecting company systems.
Usernames and passwords are the root cause behind phishing, credential theft, and many of today's breaches, in the same way a virus is the root cause of the illnesses that follow it. Traditional two-factor authentication works like a mask: it makes hacking harder without removing the cause. Eliminating usernames and passwords works like a vaccine: it removes the cause itself.
Update: The article's central point still holds. Verizon's 2025 Data Breach Investigations Report still found credential abuse to be the most common initial access vector in breaches.
The Analogy at a Glance
Approach | The health analogy | What it does | Trade-off |
|---|---|---|---|
Usernames and passwords | The virus | The root cause of compromised systems, phishing, and ransomware | Breachable despite layers of digital protection |
Traditional two-factor authentication (2FA) | A mask | Makes hacking more difficult | Cheap and easy to implement, but doesn't eliminate the root cause |
PKI and smart cards | The first vaccine | Removes usernames and passwords | High cost and complexity kept it out of reach for most businesses and consumers |
WWPass | A new-age vaccine | Removes usernames and passwords while making security accessible, affordable, and easy to use | Uses hardware infrastructure already available in popular tech |
What a Pandemic Can Teach Us About Cybersecurity
If 2020 has taught us anything, battling a virus is not easy. It takes a range of methods to protect those around us, from staying inside to wearing masks. Even with this, COVID-19 feels like it's everywhere.
In 2021, vaccines built on cutting-edge mRNA approaches have revolutionized disease control, tackling the virus in an entirely new way. Scientists have finally found a way to beat COVID-19, but this year will be about the vaccine's widespread distribution over former preventative measures.
With the revolutionary advancements made in virology, why don't we take the same approach to cybersecurity?
Hacking Is Our Epidemic
In 2021, hacking is our epidemic. The FBI's Internet Crime Complaint Center saw cybersecurity complaints jump by as much as 300%, from about 1,000 a day to 3,000-4,000, since the beginning of the pandemic. There has even been a spike in virus-related email scams, according to Google.
COVID-19 as a virus is the root cause of diseases like pneumonia and larger organ failure, which can lead to death. To save lives, scientists are looking to kill the root cause of these pandemic deaths: the virus. If they make sure those with the vaccine never even have a chance to get COVID-19, they also cut down the chance they suffer from the various diseases associated with it.
The same is true for cybersecurity.
The Root Cause: Usernames and Passwords
The man-made digital virus was created in the 1960s when computer scientists at MIT were looking for a way for multiple users to share the resources of one computer. Their solution: create individualized usernames and passwords. This proved to be a great solution with minimal issues early on, establishing usernames and passwords as mainstays in most technology following, including into the 21st century.
However, that security didn't last. Similar to COVID-19, usernames and passwords eventually proved to be the root cause of compromised computers. They would eventually give rise to hacked systems and massive costs for businesses to restore their digital infrastructures. It spurred more hacking avenues, like phishing and ransomware.
The First Vaccine: PKI and Smart Cards
To combat this, technologists tried to develop a vaccine to take out the root cause, usernames and passwords, and in turn the diseases and issues they caused. Known as a public key infrastructure (PKI) and utilizing smart cards, this technology, which was invented in the late 1970s, was used by government agencies like the Department of Defense to remove username and password use.
The same idea has since been utilized by credit card companies with in-card chips, practically replacing a card number and PIN (which effectively represent a username and password) with a secure chip card.
PKI and smart cards worked well, with the Department of Defense relying on them to protect access to its systems. In 2004, tech giants like Bill Gates declared the gradual death of usernames and passwords following the success of a more secure system. The main thing holding back the PKI-based login system from widespread use was the high barrier of entry in cost and complexity. The average business or consumer didn't have the budget to implement it or sophisticated IT departments to manage it.
The Mask: Two-Factor Authentication
Instead of the widespread use of this digital vaccine, consumers opted for more mask-like solutions. They took to traditional two-factor authentication (2FA) methods, which were cheap and easier to implement, but at the cost of lessened security compared to PKI. While it made hacking more difficult, it didn't eliminate its root cause in usernames and passwords, making users more secure than before, but not entirely eliminating the risk of traditional logins.
SolarWinds: A Reminder That Passwords Still Fail
The SolarWinds hack, an allegedly Russian SVR-led attack on multiple commercial and government agencies across the globe, put a spotlight on how breachable usernames and passwords still are, despite a plethora of digital protections. Congress and the press focused on a password as simple as "solarwinds123" that was reportedly protecting a SolarWinds server. SolarWinds has said the credential belonged to a third-party application and had nothing to do with the SUNBURST attack, and, at the time, the company was still investigating how the attackers got in. Either way, a password that simple guarding company infrastructure shows how easily usernames and passwords fail.
Many other attacks have been carried out by leveraging usernames and passwords, too. The SolarWinds episode also once again raises a need for a more secure alternative to 2FA and a more accessible form of cybersecurity than PKI and smart cards. Above all else, it questions why we've continued to utilize usernames and passwords, which have continually been used as tools to benefit hackers long beyond their point of obsolescence.
A New-Age Vaccine: Removing Usernames and Passwords
Similar to the multiplicity of COVID-19 vaccines designed by different pharmaceutical companies, there are quite a few technologies besides PKI that allow for the complete elimination of usernames and passwords.
More than a decade ago, WWPass created its own usernameless and passwordless solutions to eradicate the root cause of hacker attacks that were using usernames and passwords, as well as the diseases that came with them. They build on the fundamentally successful aspects of PKI that remove the need for these dated logins, but leverage modern technology to make security accessible, affordable and easy to use. The hardware infrastructure required is at our fingertips already with popular tech. It's a privacy and security-first approach that's a cutting-edge, new-age vaccine for our digital world.
The result is giving businesses and consumers a chance to say no to living life behind a faulty digital mask and choosing the safety of a new-age WWPass vaccine. It's a life without the flaws and uncertainties of insecure usernames and passwords. It's taking a new approach to protection that significantly reduces risks of future hacker attacks.
FAQ
Why are usernames and passwords called the root cause of breaches?
Attackers keep targeting them, and credential abuse remains the most common initial access vector in Verizon's 2025 DBIR. Phishing, which often aims at stealing login credentials, and other attacks build on that weakness.
How is two-factor authentication different from removing passwords?
Two-factor authentication adds a second check on top of a username and password, which makes hacking harder but leaves the root cause in place. Removing usernames and passwords eliminates the credential itself.
Why didn't PKI and smart cards replace passwords everywhere?
Cost and complexity. They worked for organizations like the Department of Defense, but the average business or consumer lacked the budget to implement them or an IT department to manage them.
Did the "solarwinds123" password cause the SolarWinds hack?
That was never established. SolarWinds said the credential belonged to a third-party vendor application not connected to its IT systems and had nothing to do with the SUNBURST attack. The password still shows how weak credentials can end up protecting company systems.
Usernames and passwords are the root cause behind phishing, credential theft, and many of today's breaches, in the same way a virus is the root cause of the illnesses that follow it. Traditional two-factor authentication works like a mask: it makes hacking harder without removing the cause. Eliminating usernames and passwords works like a vaccine: it removes the cause itself.
Update: The article's central point still holds. Verizon's 2025 Data Breach Investigations Report still found credential abuse to be the most common initial access vector in breaches.
The Analogy at a Glance
Approach | The health analogy | What it does | Trade-off |
|---|---|---|---|
Usernames and passwords | The virus | The root cause of compromised systems, phishing, and ransomware | Breachable despite layers of digital protection |
Traditional two-factor authentication (2FA) | A mask | Makes hacking more difficult | Cheap and easy to implement, but doesn't eliminate the root cause |
PKI and smart cards | The first vaccine | Removes usernames and passwords | High cost and complexity kept it out of reach for most businesses and consumers |
WWPass | A new-age vaccine | Removes usernames and passwords while making security accessible, affordable, and easy to use | Uses hardware infrastructure already available in popular tech |
What a Pandemic Can Teach Us About Cybersecurity
If 2020 has taught us anything, battling a virus is not easy. It takes a range of methods to protect those around us, from staying inside to wearing masks. Even with this, COVID-19 feels like it's everywhere.
In 2021, vaccines built on cutting-edge mRNA approaches have revolutionized disease control, tackling the virus in an entirely new way. Scientists have finally found a way to beat COVID-19, but this year will be about the vaccine's widespread distribution over former preventative measures.
With the revolutionary advancements made in virology, why don't we take the same approach to cybersecurity?
Hacking Is Our Epidemic
In 2021, hacking is our epidemic. The FBI's Internet Crime Complaint Center saw cybersecurity complaints jump by as much as 300%, from about 1,000 a day to 3,000-4,000, since the beginning of the pandemic. There has even been a spike in virus-related email scams, according to Google.
COVID-19 as a virus is the root cause of diseases like pneumonia and larger organ failure, which can lead to death. To save lives, scientists are looking to kill the root cause of these pandemic deaths: the virus. If they make sure those with the vaccine never even have a chance to get COVID-19, they also cut down the chance they suffer from the various diseases associated with it.
The same is true for cybersecurity.
The Root Cause: Usernames and Passwords
The man-made digital virus was created in the 1960s when computer scientists at MIT were looking for a way for multiple users to share the resources of one computer. Their solution: create individualized usernames and passwords. This proved to be a great solution with minimal issues early on, establishing usernames and passwords as mainstays in most technology following, including into the 21st century.
However, that security didn't last. Similar to COVID-19, usernames and passwords eventually proved to be the root cause of compromised computers. They would eventually give rise to hacked systems and massive costs for businesses to restore their digital infrastructures. It spurred more hacking avenues, like phishing and ransomware.
The First Vaccine: PKI and Smart Cards
To combat this, technologists tried to develop a vaccine to take out the root cause, usernames and passwords, and in turn the diseases and issues they caused. Known as a public key infrastructure (PKI) and utilizing smart cards, this technology, which was invented in the late 1970s, was used by government agencies like the Department of Defense to remove username and password use.
The same idea has since been utilized by credit card companies with in-card chips, practically replacing a card number and PIN (which effectively represent a username and password) with a secure chip card.
PKI and smart cards worked well, with the Department of Defense relying on them to protect access to its systems. In 2004, tech giants like Bill Gates declared the gradual death of usernames and passwords following the success of a more secure system. The main thing holding back the PKI-based login system from widespread use was the high barrier of entry in cost and complexity. The average business or consumer didn't have the budget to implement it or sophisticated IT departments to manage it.
The Mask: Two-Factor Authentication
Instead of the widespread use of this digital vaccine, consumers opted for more mask-like solutions. They took to traditional two-factor authentication (2FA) methods, which were cheap and easier to implement, but at the cost of lessened security compared to PKI. While it made hacking more difficult, it didn't eliminate its root cause in usernames and passwords, making users more secure than before, but not entirely eliminating the risk of traditional logins.
SolarWinds: A Reminder That Passwords Still Fail
The SolarWinds hack, an allegedly Russian SVR-led attack on multiple commercial and government agencies across the globe, put a spotlight on how breachable usernames and passwords still are, despite a plethora of digital protections. Congress and the press focused on a password as simple as "solarwinds123" that was reportedly protecting a SolarWinds server. SolarWinds has said the credential belonged to a third-party application and had nothing to do with the SUNBURST attack, and, at the time, the company was still investigating how the attackers got in. Either way, a password that simple guarding company infrastructure shows how easily usernames and passwords fail.
Many other attacks have been carried out by leveraging usernames and passwords, too. The SolarWinds episode also once again raises a need for a more secure alternative to 2FA and a more accessible form of cybersecurity than PKI and smart cards. Above all else, it questions why we've continued to utilize usernames and passwords, which have continually been used as tools to benefit hackers long beyond their point of obsolescence.
A New-Age Vaccine: Removing Usernames and Passwords
Similar to the multiplicity of COVID-19 vaccines designed by different pharmaceutical companies, there are quite a few technologies besides PKI that allow for the complete elimination of usernames and passwords.
More than a decade ago, WWPass created its own usernameless and passwordless solutions to eradicate the root cause of hacker attacks that were using usernames and passwords, as well as the diseases that came with them. They build on the fundamentally successful aspects of PKI that remove the need for these dated logins, but leverage modern technology to make security accessible, affordable and easy to use. The hardware infrastructure required is at our fingertips already with popular tech. It's a privacy and security-first approach that's a cutting-edge, new-age vaccine for our digital world.
The result is giving businesses and consumers a chance to say no to living life behind a faulty digital mask and choosing the safety of a new-age WWPass vaccine. It's a life without the flaws and uncertainties of insecure usernames and passwords. It's taking a new approach to protection that significantly reduces risks of future hacker attacks.
FAQ
Why are usernames and passwords called the root cause of breaches?
Attackers keep targeting them, and credential abuse remains the most common initial access vector in Verizon's 2025 DBIR. Phishing, which often aims at stealing login credentials, and other attacks build on that weakness.
How is two-factor authentication different from removing passwords?
Two-factor authentication adds a second check on top of a username and password, which makes hacking harder but leaves the root cause in place. Removing usernames and passwords eliminates the credential itself.
Why didn't PKI and smart cards replace passwords everywhere?
Cost and complexity. They worked for organizations like the Department of Defense, but the average business or consumer lacked the budget to implement them or an IT department to manage them.
Did the "solarwinds123" password cause the SolarWinds hack?
That was never established. SolarWinds said the credential belonged to a third-party vendor application not connected to its IT systems and had nothing to do with the SUNBURST attack. The password still shows how weak credentials can end up protecting company systems.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.
