What's the Password? Only Your iPhone Knows
A few weeks ago, I wondered if people would start to use their cellphones to verify their identities when logging on to Internet sites. I imagined a phone application similar to RSA's SecurID, the small gizmo many corporations issue to employees …
Context & Ripple Effects
This is the second swing at the same idea from the Bits desk. Back in October 2007 the corpus carried an iPhone password manager, treating the phone as a vault for credentials; today's column flips the framing, floating the unconfirmed notion — flagged as the writer's own speculation — that an iPhone app could verify website logins directly, playing the role RSA's SecurID fobs play inside corporations.
The significance is positional rather than proven: nothing here is a shipped product or announced deal, but the column puts a named incumbent, RSA, in the crosshairs of a device millions of consumers already carry in their pockets.
First-order effects
- If websites actually adopted phone-based verification, RSA's SecurID would face its first mass-market substitute — corporations buy tokens today that their employees already own as iPhones.
Second-order effects
- Apple gains leverage either way: every site that treats the iPhone as a credential deepens lock-in to the device and hands Apple a gatekeeping role over web logins it does not currently hold.
Third-order effects
- If the pattern holds — authentication migrating off dedicated hardware and onto handsets — the credential business consolidates around device makers and OS vendors, shrinking the standalone token market RSA built and shifting accountability for account security onto phone manufacturers.
The trend: Identity verification is drifting from purpose-built hardware like SecurID toward the phone itself as the universal credential.