Why I killed the WordPress password field for good (and let Gemini AI handle the botnets) šŸš€

by•

Hi everyone! Tomorrow I’m launching Sovereign AI Overseer, but I wanted to start a discussion today about a massive vulnerability we all just accept as "normal": Passwords.

If you run an agency or manage client sites, you know that "forgot password" tickets and brute-force botnets eat up your profit margins and server resources. Rate-limiting is just a band-aid.

I decided to deprecate the password field completely.

In my new architecture, I replaced it with native WebAuthn (Face ID / Touch ID). For active threats, I deployed a serverless Google Gemini 1.5 Pro AI Sentinel via a BYOI (Bring Your Own Infrastructure) model on Cloud Run to autonomously ban IPs in real-time.

I'm curious about how the community here is handling this in 2026:
1. Have you fully transitioned your clients to WebAuthn, or are you still relying on traditional 2FA plugins?
2. What is your take on the BYOI (Bring Your Own Infrastructure) model vs paying expensive monthly SaaS fees for AI security?

Would love to hear your architectural thoughts!

9 views

Add a comment

Replies

Be the first to comment