← Back to list

The Growing Tyranny of Codes, PINs, Passwords, and Passkeys

How digital authentication quietly displaced the identity systems Americans relied on for 75 years — and what happens when it fails you

JESSE JAMES KARR · 2026-06-26 06:44 · 1 claps · 4.6 min read
#code #pin #passwords #passkey #online
Open on Medium ↗
Wiki topics: 🔧 · Data Engineering

The Growing Tyranny of Codes, PINs, Passwords, and Passkeys

How digital authentication quietly displaced the identity systems Americans relied on for 75 years — and what happens when it fails you

For roughly three-quarters of a century, the Social Security number served as the cornerstone of personal identity in the United States. From your hometown bank to your family physician, that nine-digit number — introduced in 1935 — was the key to virtually every consequential transaction in American life. Supplemented later by the driver’s license and passport, this framework functioned reliably across generations.

That framework no longer exists.

Most of us didn’t notice when it ended. We were, in a sense, asleep.

While We Slept, the Rules Changed

Beginning in the 2010s and accelerating sharply through the COVID-19 pandemic, surging fraud rates compelled banks, healthcare systems, retailers, and government agencies to adopt more dynamic methods of identity verification. Today, consumers are routinely identified through biometrics, one-time passcodes, PINs, complex passwords, and passkeys.

Notice what is absent from that list: the Social Security number. The driver’s license. The passport.

These once-primary identifiers have been quietly demoted to supplemental roles — used only to augment a person’s identity, not to establish it. The new primary anchor is something far more fragile.

Your cell phone.

This transition did not happen through public debate or formal policy. It happened incrementally, driven by technology developers and institutional risk managers working largely out of public view. Most consumers did not notice until the system failed them personally.

The Four Tyrants

For purposes of this discussion, let’s call them The Four: codes, PINs, passwords, and passkeys. They now govern access to the institutions and services that define participation in modern economic and civic life.

The most consequential of The Four is the code — that one-time text message sent to your mobile device to verify that you are who you say you are. It is deceptively simple. It is also exclusively tied to your phone. And that dependency creates a vulnerability that most people don’t recognize until it’s too late.

The Moment It Becomes Real

Imagine you leave your phone in a rideshare vehicle. Your natural first step is to contact the company’s customer service line to help locate the driver and recover your device.

What you will encounter instead is a verification requirement — specifically, a one-time code sent via text message to the very phone that is now in someone else’s car.

This is not a system glitch. It is the designed response. The institution’s authentication infrastructure cannot distinguish between a customer who has lost their phone and someone attempting unauthorized access. Both receive the same response: produce the code, or the matter cannot proceed.

Your phone was in the driver’s car. Sending you a code was and always will be of no value. But the system doesn’t know that — and it doesn’t care.

A Day in the Life of The Four

The practical reach of this dependency becomes clear when you trace it through a single ordinary day.

You wake up before a doctor’s appointment and need to ask a quick question. You call the physician’s office. Before any clinical information can be discussed, a verification code is required. You comply. First gauntlet cleared.

Next, you call your cellular carrier about a billing error. An automated system — not an AI, just an old-fashioned interactive voice system — asks for your Social Security number, then your telephone account PIN (a separate credential from your online password, which you may or may not have ever set). Eventually, a text-based code is required before a live agent will engage with you.

Then comes the bank.

You visit a branch in person because online access failed after too many incorrect password attempts. A representative unlocks your account. You proceed to the teller window with your debit card and your PIN. You are prepared to receive cash.

Then the screen asks for a phone code.

Your Social Security number, your government-issued ID, your physical debit card, and your PIN — none of it is sufficient. The code is non-negotiable. And without your phone, the transaction ends.

The Structural Problem No One Is Talking About

The problem is not that these authentication methods are illegitimate. The fraud losses that drove this transition are real and staggering — hundreds of billions of dollars annually in the United States alone. Static identifiers like Social Security numbers have proven catastrophically vulnerable to large-scale data breaches. The shift toward device-bound, dynamic authentication reflects a genuine institutional response to a genuine crisis.

The problem is the single point of failure.

When identity verification is anchored entirely to a mobile device, any disruption to that device — loss, theft, damage, change of phone number, or simply leaving it at home — cascades into an inability to access healthcare records, financial accounts, telecommunications services, and a widening range of daily necessities.

This is not hyperbole. An individual without access to their phone may be:

  • Unable to withdraw their own money from their own bank account
  • Unable to reach a live representative at their cellular carrier
  • Unable to access their own medical information before an appointment
  • Unable to recover access to a rideshare platform to locate a lost device

The transition has occurred without adequate public awareness, without meaningful alternatives for those who cannot carry a smartphone, and without sufficient fail-safe mechanisms for entirely predictable disruption scenarios.

What Hasn’t Changed — And What Has

For 75 years, losing your wallet was a serious inconvenience. You called the bank, presented yourself at a branch with backup identification, and resolved the matter.

Today, losing your phone is an existential event. You may be effectively locked out of the systems you depend on to function — financially, medically, professionally — until access is restored. And restoring that access, without the device the systems are built around, can take days.

The mobile phone has become what the Social Security number once was: the indispensable key to your identity. The difference is that your Social Security number could be memorized, written down, and stored in multiple places. Your phone — and more precisely, the real-time code it receives — cannot.

The Question Worth Asking

We did not vote on this transition. We were not given a disclosure form. We woke up one day and the rules had changed.

The question is not whether stronger authentication is necessary — it clearly is. The question is whether a society that has made the mobile phone the indispensable key to daily life has adequately prepared for, or even acknowledged, what happens when that key is gone.

Until that question is answered, the only practical advice is this: treat your phone as if your entire life depends on it.

Because increasingly, it does.

Gregory is President of Crossfire Utility Services and writes on technology, policy, and the systems that shape everyday life.


메타데이터
post_id
f0b7238d05ee
slug
the-growing-tyranny-of-codes-pins-passwords-and-passkeys-f0b7238d05ee
url
https://medium.com/@jessejameskarr1/the-growing-tyranny-of-codes-pins-passwords-and-passkeys-f0b7238d05ee
canonical_url
https://medium.com/@jessejameskarr1/the-growing-tyranny-of-codes-pins-passwords-and-passkeys-f0b7238d05ee
author_url
https://medium.com/@jessejameskarr1
status
ok
fetched_at
2026-06-27 18:37:17