2026.04.02

Nobody Can Count

On authentication, accelerometers, and the math everyone ignores

On September 11th, 2001, Cantor Fitzgerald lost 658 of its 960 New York employees. The firm needed access to client accounts locked behind the dead employees' passwords. According to accounts of the recovery, Microsoft sent technicians. They ran brute-force attacks on servers. When that wasn't fast enough, Howard Lutnick called the families.

Grieving spouses picked up the phone days after the towers fell and were asked to remember. Their wedding anniversary. The street where he proposed. The restaurant on their first date. The hotel where they spent their wedding night. All fed into a machine, one guess at a time, trying to become the string a dead person had memorized.

The system worked exactly as designed.

The same architecture fails you every time you get a new device. Same manufacturer. Same operating system. Same account. Every app logged out. Every session dead. Hours re-entering passwords, re-verifying accounts, re-authenticating to services that already know who you are. Half your two-factor codes are locked to the old device. The recovery codes are in a file on a computer you had two computers ago.

The average person has 168 accounts requiring passwords. None of them follow you anywhere.

Meanwhile, your phone knows it's you. Not because you told it. Because it felt the specific way you walk — the cadence, the asymmetry, the micro-signatures of your gait across accelerometer and gyroscope. Because it heard you and matched your voice against a model built from physics no two people share: the shape of your vocal tract, the geometry of your jaw, the cavity dimensions of your throat. Because it tracked the rhythm of your tapping and the pressure of your swipe. None of this required your attention or participation.

Gait recognition alone achieves a 97.77% true positive rate. Voice biometrics runs a false acceptance rate of 0.01%. The device built a model of you by being near you, and that model is more reliable than your spouse picking you out of a lineup.

Whether it uses that knowledge — and for what — should be yours to decide. Not Google's. Not Apple's. Not Discord's. Yours.

And yet: please find the parking meters.

Authentication Is One Question

Not ten. Not a hundred. Not a recurring subscription. One.

Is this person who they say they are?

You answer it once. After that, you're not authenticating — you're verifying. These are different operations. Verification is cheap, passive, continuous. Authentication is a specific event with a specific answer that either happened or didn't.

The industry never made this distinction. Session timeouts. Please log in again. We've sent a code to your phone. The system re-asking a question it already answered. Not because the answer changed. Because it never learned how to count.

That's amnesia dressed up as security.

The Horror Show Is Structural

Absurd circular dependency loop: password reset requires email, email requires password, password requires 2FA, 2FA requires the device you don't have

SIM-based two-factor authentication. The architecture stores your cryptographic key in databases replicated across dozens of facilities, accessible to hundreds of people, with no hardware-level protection that survives a $50,000USD offer to the right DBA. This is the second factor. The one that's supposed to make the first factor stronger.

Security questions. Your mother's maiden name. The street you grew up on. The name of your first pet. Researchers reconstructed correct answers for most people from their social media in under an hour.

Password reset flows. You forgot your password, so the system sends an email to your registered address. Your email is now the authentication factor. Which has another password. And a 2FA code. And a confirmation tap. Then the reset link. Then the new password. Four attestations to answer a question you already answered once, with an insecure plaintext transmission in the middle.

CAPTCHA. reCAPTCHA's own documentation notes the system increasingly relies on behavioral signals — mouse movement, hesitation, scrolling — rather than the puzzle answer. The puzzle is a decoy. Bots solve it better than you do.

Every one of these is a patch on a foundation that was wrong to begin with.

The Parts Were Already on the Workbench

A worn wheel with a grinding axle beside disassembled ball bearing parts sitting untouched on a workbench

Wheels existed for four thousand years before ball bearings. Not because the friction was invisible — axles wore down, carts broke, everyone knew. But the wheel worked. You pushed harder. You replaced the axle. You accepted the grind as the cost of rolling.

Passwords are the same engineering. They work. They break. You reset them. You memorize another one. You push harder. You accept the grind.

The ball bearings have been sitting on the workbench the entire time.

Shamir secret sharing: 1979. Hardware secure elements: 1980s. Public key cryptography: 1976.

The correct assembly of these things into an authentication system that counts to one — nobody picked them up. So here they are.

First Device

A phone showing a single username field and an ATTEST button. Nothing else.

Get it. Turn it on. Type a handle. If it's unclaimed, it's yours.

FIRST BOOT
device identity derived from hardware-burned secret
private key never leaves hardware
handle binds to public key on network
authentication event: complete. count: 1.

That's it. You start from zero because you're at zero. No passwords to set. No email to verify. No security questions to invent answers to. You exist on the network now.

New Device

A cryptographic key bridging two phones as apps and data flow seamlessly from old device to new

You already have a life attached to that handle — messages, apps, preferences, files. Tap new device to existing one. Existing device signs the new keypair. Everything follows you. Not because anything was magically synchronized. Because your identity was always the key, and the key just moved to new hardware.

Lost Everything

A person at center connected to trusted friends and family, three of them glowing — the Shamir threshold met

Every device gone. Ask a friend. A trusted person attests the new device the same way the original worked — same mechanics, different trigger. Your identity recovers because your relationships are real, not because a corporation kept a copy of your password in a database.

What about private data that never touched anyone else's device? Shamir secret sharing across your social graph. Your sister holds a fragment. Your spouse holds a fragment. Your oldest friend holds a fragment. No single person can reconstruct anything. No single person even knows what they're holding. The fragments are inert until a threshold you chose is met — three of five, four of seven, whatever your trust topology looks like — and only if none of your existing devices are active. If you're still holding a device, recovery goes thru it. Your social graph is the fallback for total loss, not a side door.

The math handles it. Nobody needs to understand the math for it to work. You just need people you trust, which you already have, because you're a person.

No credential database. Nothing to breach. Nothing to phish. No shared secrets. No codes read aloud. No numbers typed into boxes.

The math has been available. The hardware has been available. The cryptographic primitives are decades old. Nobody is selling you this. It's free. It's yours. It was always supposed to be yours.

The answer is one. Someone keeps counting higher.

1