Consumercide All articles
Investigative

Your Password Is a Product: The Multi-Billion Dollar Racket Hiding Behind the Login Screen

Consumercide
Your Password Is a Product: The Multi-Billion Dollar Racket Hiding Behind the Login Screen

Photo: David Shankbone, CC BY 3.0, via Wikimedia Commons

Let's set the scene. You want to check your airline miles. Simple enough, right? Except your password doesn't work. So you click "Forgot Password," wait for an email that takes eleven minutes to arrive, click a link that expires before you can type your new password, get redirected to a page demanding you download an authentication app, download the authentication app, create another account for the authentication app, verify that account via a second email, and finally — finally — discover you have 847 miles. Enough for a pack of peanuts.

Congratulations. You just participated in a $50 billion industry that had absolutely nothing to do with keeping you safe.

The Security Theater Playing at a Screen Near You

Here's the thing about mandatory account creation, forced password resets, and two-factor authentication hoops: some of it is legitimate security practice. A small amount. A sliver. The rest is what industry insiders quietly call "identity infrastructure" — which is a polished way of saying they've built a tollbooth out of your login credentials and they charge rent every time you pass through.

When a company forces you to create an account before you can buy a single tube of toothpaste from their website, they are not protecting you. They are harvesting you. Your email address, your device fingerprint, your browsing behavior, your purchase history, your location, and the precise time you shop — all of it gets bundled into what data brokers call an "identity graph." Which is a slightly less polished way of saying a dossier on your entire life that gets sold to anyone willing to write a check.

The identity verification market — the business of confirming that you are, in fact, you — was valued at over $12 billion in 2023 and is projected to more than quadruple by the end of the decade. That growth isn't coming from stopping fraudsters. It's coming from companies finding new and creative reasons to make you prove who you are before accessing something you already paid for.

Forced Resets: The Shakedown With a Friendly Email

The periodic forced password reset is one of corporate America's most elegant cons. Cybersecurity researchers have been saying for years — years — that mandatory password resets don't improve security. The National Institute of Standards and Technology, which is about as close to an official rulebook as cybersecurity gets, explicitly recommends against routine forced resets unless there's evidence of a breach.

And yet your bank makes you change your password every 90 days. Your insurance portal resets you annually. Your gym's app — your gym's app, a piece of software you use to book spin class — expired your credentials twice last year.

Why? Because every reset is a fresh data touchpoint. Every login attempt tells them what device you're on, what operating system, what browser, what time of day, and where in the country you're sitting. That's not security data. That's behavioral tracking data wearing a security costume.

The Authenticator App Trap

The authenticator app market deserves its own special circle of hell. Companies have been pushing users away from SMS verification — which, fine, SMS has real vulnerabilities — and toward proprietary authentication apps. Which sounds responsible until you realize that several of the most widely pushed authenticators are owned by or deeply integrated with the same advertising technology ecosystem that profits from your behavioral data.

Downloading an authenticator app to access your streaming service means you now have a persistent, always-on application sitting on your phone with permission to access your device identifiers, sometimes your contacts, and in several documented cases, your precise location. You were told it was for your protection. What it actually did was give a third party permanent residency on your most personal device.

And when you switch phones? Your entire authentication chain breaks. You get locked out of accounts. You call customer service. You spend 45 minutes on hold. You get transferred twice. You eventually verify your identity by answering questions about your childhood pet and your mother's maiden name — information that, incidentally, is available for purchase from a data broker for about $0.003 per record.

Single Sign-On: One Ring to Track Them All

"Sign in with Google." "Sign in with Apple." "Sign in with Facebook."

This is the masterpiece. The convenience is real — one button, instant access, no new password. But what you're doing when you use single sign-on is handing a tech giant a comprehensive map of every service you use, every app you open, and every time you open it. Google doesn't offer "Sign in with Google" out of generosity. They offer it because it is the most efficient identity surveillance product ever built, and they convinced the entire internet to install it voluntarily.

Apple's version is marginally better on privacy. But it still centralizes your digital identity inside one corporation's infrastructure, which means your access to dozens of services is contingent on your relationship with a single company. One account suspension — for reasons that can be as arbitrary as an algorithm's bad day — and you lose access to everything you signed in with it.

That's not security. That's dependency, engineered at scale.

What You Can Actually Do

Password managers — real ones, not the browser-based kind that sync to a corporate cloud — help. Open-source authenticator apps that don't report home to an ad network exist and work fine. Refusing to create accounts for one-time purchases, using temporary email addresses for mandatory registrations, and reading app permission requests before tapping "Allow" are all small acts of resistance that add up.

None of this fixes the structural problem, which is that the United States has no meaningful federal data privacy law requiring companies to justify what they collect, how long they keep it, or who they sell it to. Every other developed economy on the planet has moved on this. We're still debating it.

In the meantime, every time a company makes you jump through one more hoop to access something you already own, remember: the hoop isn't the product. You are.

All Articles

Related Articles

Pay to Pay: The Fee-on-a-Fee Economy Bleeding Americans Dry One Transaction at a Time

Pay to Pay: The Fee-on-a-Fee Economy Bleeding Americans Dry One Transaction at a Time

Fido's Vet Bill Is Bigger Than Your Rent, and That's No Accident

Fido's Vet Bill Is Bigger Than Your Rent, and That's No Accident

Ghost Landlords: The Hedge Fund Haunting Your Neighborhood

Ghost Landlords: The Hedge Fund Haunting Your Neighborhood