How Apple and Google will kill the password
Prediction: Your phone is about to become a universal biometric ID and debit card — Computerworld - Imagine sitting down at a public PC, surfing the Web, visiting Facebook, checking your online bank account and buying something on Amazon.com …
Context & Ripple Effects
Computerworld's forecast builds on an idea the New York Times' Bits blog floated back in March 2009, when it described an iPhone that alone knows your password — the phone-as-credential thesis is two years old at this point, and this piece pushes it further by adding biometrics and payments to it. Both halves of the prediction — the phone replacing passwords and the phone replacing the debit card — are framed here as rumors about Apple's and Google's intent, not announced products.
The backdrop is a mobile market where Google is visibly deepening its consumer-commerce push: its Click-to-Call ad feature, launched a year earlier, was already handling millions of calls per month per people familiar with Google's numbers, and Instant Previews had just arrived on iOS Safari. Whoever controls the handset, the argument goes, controls the login and the checkout.
First-order effects
- Banks, Facebook and Amazon are the named endpoints of the prediction: their username-and-password flows would be replaced by device-held credentials, making Apple and Google the authentication layer between consumers and every site they visit.
- For handset makers themselves, holding users' biometric identities and wallet functions converts the phone from a communications device into an indispensable key — raising switching costs well beyond apps and contacts.
Second-order effects
- Card issuers and payment networks face direct substitution pressure if phone-as-debit-card takes hold, since the same tap-to-pay moment they own becomes something the platform holder intermediates.
- Security vendors whose business rests on password infrastructure — provisioning, reset helpdesks, credential databases — see their addressable work shrink if authentication moves onto devices they do not manage.
Third-order effects
- If the pattern holds, web identity consolidates around whichever company holds the handset, shifting trust from thousands of independent site-level password stores to a handful of platform vendors — with the liability and regulatory questions that follow such concentration still unresolved.
- The same consolidation logic applies to money: a universal phone wallet would make the operating system vendor a de facto gatekeeper over merchants and banks, a structural role no single card network holds today.
The trend: The smartphone is being positioned as the universal credential — collapsing authentication and payment into the device, and moving the trust anchor from websites to platform owners like Apple and Google.