SQRL wan't wrong, it was early

The internet says Steve Gibson saw the future — but showed up before the party started

TLDR: SQRL was an early attempt to replace passwords years before passkeys went mainstream, but it never got the industry support needed to catch on. In the comments, people are split between calling it a brilliant idea ahead of its time and dunking on it as flawed, overhyped, or basically doomed like passkeys themselves.

A decade before Big Tech started selling the world on “password-free” sign-ins, Steve Gibson was already out there yelling, “What if we just ditched passwords entirely?” That was the promise of SQRL, an older login idea the article argues was less wrong than simply way too early. The big twist? Today’s passkeys — the shiny new system backed by Apple, Google, and Microsoft — look an awful lot like the future SQRL fans thought they were getting years ago.

And the comments? Absolutely not calm. One camp is doing the victory lap, basically saying, “We told you so.” One user said they think of SQRL every time they use the QR-style login flow on Discord or Steam, which is the internet equivalent of spotting your ex’s fashion trend on a celebrity. Another commenter argued SQRL was “far more advanced” than the “rolling disaster” of passkeys, which is spicy enough to start a small platform war on its own.

But the haters showed up too. A blunt reply dismissed SQRL as “pretty obviously wrong” compared to FIDO, the industry-backed login standard already around at the time. Ouch. Then came the doomers, warning that both SQRL and passkeys still have the same nightmare problem: if your device is lost, your precious sign-in secrets can go with it — unless giant companies step in, and not everyone trusts them to do that without grabbing control.

So the vibe is clear: visionary or vanity project? The crowd can’t agree. But they can agree on one thing: timing, not just clever design, decides who becomes the future and who becomes a very smug footnote.

Key Points

  • The article presents Steve Gibson’s SQRL as an early passwordless web authentication system that anticipated some of the goals later achieved by passkeys.
  • SQRL used asymmetric cryptography to provide a different identity for each website, avoiding reusable passwords and reducing the value of stolen server-side secrets.
  • The author says Wirehive adopted SQRL support internally after seeing its potential during the period when the company was working with SSH certificates.
  • The article states that SQRL never achieved broad adoption despite implementations and a committed community, largely because the ecosystem did not coordinate around it.
  • The article argues that passkeys succeeded in part because Apple, Google, and Microsoft backed shared standards and integrated support across platforms, browsers, and related products.

Hottest takes

"pretty obviously ‘wrong’" — DANmode
"the rolling disaster which is Passkey" — breput
"both solutions are a lost cause" — paulryanrogers
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.