
Stop Sharing Passwords: A Practical Path to Passkeys
This episode breaks down why shared spreadsheets, Slack-stored logins, and SMS two-factor leave businesses exposed, and explains how phishing-resistant passkeys can close the gap. It also offers a practical, phased rollout plan for moving teams to a password manager without creating browser conflicts or internal chaos.
Chapter 1
Why SMS Two Factor and Shared Passwords Keep Exposing Your Business
Ryan Haylett
If your team is still passing around logins for vendor portals or client management systems using a master spreadsheet or a pinned Slack message, you are running on borrowed time. I mean it.
Dave Rowley
Oh, absolutely. It is, it is the classic small business trap, right? You start out, there are three of you, somebody puts the QuickBooks password on a sticky note or in a shared doc, and it works fine. Until, well, until somebody leaves the company and you realize you have to reset forty different logins on a Friday afternoon.
Ryan Haylett
Or worse, you don't reset them. You forget three of those accounts, and an ex employee still has complete access to your customer billing database or your medical records portal six months later.
Dave Rowley
Yeah, exactly. And then the second part of that trap is people think, well, we put text message code verification on the account, so we are totally secure, right? But SMS two factor is, honestly, it is an illusion at this point. Cybercriminals can SIM swap your phone number in ten minutes, or they set up a dummy login page that grabs your password and that six digit text code in real time while you type it in.
Ryan Haylett
Right, it, it proxies the code straight to the actual site before it even expires. That is why cyber insurance carriers now are coming down hard on this. They are literally writing into policies that you need phishing resistant authentication, like FIDO2 passkeys, especially for anyone with admin access.
Dave Rowley
But when you say passkeys to a business owner, their eyes just roll into the back of their head. They think it is some overwhelming cryptographic headache that is going to break their whole workflow.
Ryan Haylett
Yeah, but it is actually way simpler than a password when you break it down. According to practical guidance from cybersecurity experts at Bitwarden, the best way to understand passkeys is to skip the math and just picture a digital car key. It is not something you remember and type out. It is a physical key that lives inside your hardware, like your smartphone or inside a team password manager like 1Password or Bitwarden.
Dave Rowley
Right. So when you log in, you just tap your finger or use Face ID. The key on your device talks directly to the server. And here is the magic part, a fake phishing website cannot steal it because the passkey is mathematically tied to the actual domain name. If you are on login dot fake site dot com instead of login dot your software dot com, your device just refuses to hand over the key. It literally cannot be phished.
Ryan Haylett
I mean, think about how much daily friction that cuts out. Dave, how many times this month have you locked yourself out of a developer tool or a portal because you forgot a character?
Dave Rowley
Man, we don't talk about that... Shifting from what a human tries to remember to a secure key a device holds, it just eliminates that whole layer of human error.
Chapter 2
The Phased Rollout Playbook for Going Passwordless Without Internal Chaos
Ryan Haylett
So if an owner wants to actually pull this off without their staff threatening to quit, where do they start? Because if you just drop new security tools on people without a plan, it turns into pure chaos.
Dave Rowley
The number one rollout killer, hands down, is the browser conflict. Research from IT deployment guides over at iFeeltech shows that if you do not turn off built in browser password saving in Google Chrome or Microsoft Edge before bringing in a real password manager, your staff gets hit with double pop ups every single time they log into anything. Chrome asks to save it, the manager asks to save it, people get confused, and your internal helpdesk gets flooded with panic tickets on day one.
Ryan Haylett
So step zero is literally toggle off save passwords in Chrome and Edge across your managed computers before you send out a single invite.
Dave Rowley
Step zero, every time. Once that is turned off, you use a three stage rollout. Stage one is a two week pilot. Grab three to five people on your team who are comfortable with technology, put them on the business password manager, set up passkeys for your main apps, and let them find where the friction points are.
Ryan Haylett
Right, get the kinks worked out with your power users first. Then stage two, you roll it out department by department. Finance first, then operations, then sales. Give each group a dedicated week to migrate their daily logins into shared team vaults.
Dave Rowley
And stage three is setting a hard cutoff date. You tell the team, look, as of Friday the fifteenth, the shared spreadsheet is getting deleted, the Slack notes are wiped, and all official business credentials live inside the manager. If it is not in the vault, it does not exist.
Ryan Haylett
And the payoff on the administrative side when you do this is unbelievable. Think about departure day for an employee. In the old world, you are spending three hours logging into fifteen different vendor portals trying to change passwords before they walk out the door.
Dave Rowley
With a centralized business password manager, you open your admin console, click revoke on their account, and instantly their access to every shared vault is cut off in a single tap. Their permissions disappear, the shared logins auto reassign, and you do not have to scramble to change a single password manually.
Ryan Haylett
It turns offboarding from a high stress nightmare into a two second admin task.
Dave Rowley
Exactly. So if you want a quick win this week, sit down and audit where your team's credentials actually live right now. Find the spreadsheets, find the sticky notes. And then turn on passkey login for your primary admin account on Google Workspace or Microsoft 365 just to feel how smooth it is.
Ryan Haylett
And if you want a team that can step in and help you map out and implement these exact security frameworks for your business, head over to modularity dot us. Good chatting, Dave.
Dave Rowley
Talk soon, Ryan.