Passwords should be dead soon and this article should be irrelevant soon after. PSA: For most basic and routine websites/apps of low-value, please, please use the FaceID/TouchID protected platform authenticators for passwordless authentication. And for those archaic sites that still insist on passwords (why? tell them about passwordless by writing feedback/app reviews), use the platform built-in password managers. Do…
No, thank you, I don't wear my passwords on my face or my fingers because they need to be secret to serve their purpose. I don't really feel like wearing a balaclava and gloves all the time.
Also sometimes I need to change them (if they get compromised, if computing progress made them easier to bruteforce, etc.), and I don't really want to have to use cosmetic surgery when that happens.
Biometrics are closer to a username than a password in this regard.
> Don't do passwords by memory.
We can agree on this (and the disaster that SMS OTP is due to lousy carrier security mostly), you will still need a password for that password manager usually though. You can have a key based setup but you still need a way to store/remeber that key. So passwords will not die just based on this, they might become less ubiquitous.
It sounds like you want to trivialize a problem that has existed for way longer than computer science and systematically relies at some point on human memory if you want a certain level of security and secrecy.
Obviously if you decrease these requirements, you can get away with weaker authentication mechanisms... but you will not secure whatever that password was securing as well then.