ONLINE
LA--:--:--
ATL--:--:--
LDN--:--:--
LIVE WIRE
FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027
← THE PASSWORDLESS POST
thePasswordlessPOSTIDENTITY · ACCESS · SECURITY
01

24 Billion Passwords Walk Into a Server Room

Issue #1 · July 2026 · by Mazy Holiday

A woman's face being scanned by a biometric mesh — passwordless identity.

The future of authentication isn't “prove you're human” — it's “prove you're authorized.”

24 Billion Passwords Walk Into a Server Room

Cybernews researchers just discovered an exposed Elasticsearch database containing roughly 24 billion records — usernames, email addresses, plaintext passwords, and the login URLs they belong to. The data was compiled from years of past breaches and infostealer malware logs circulating on Telegram channels and other cybercrime marketplaces. Researchers don't yet know how many unique people are affected, but the scale suggests billions of online accounts could be at risk. (Read the Cybernews report.)

Billion, with a “B.” Your information could be in there even if you've never heard of the database operator — because the records were stitched together from countless breaches you may not even know happened. Every single one of those credentials was a password someone typed in. Someone chose it, memorized it — or more likely reused it across a dozen services — and trusted it to protect something that mattered. A bank account, a medical portal, a work email. That password was supposed to be a wall; it turned out to be a welcome mat.

This isn't a new story, but the scale has crossed into the absurd. Twenty-four billion records means there are roughly three stolen credentials for every human being on Earth. Passwords don't protect people — they give people the feeling of protection.

The Part Where I Couldn't Sign Up for a Newsletter

Here's where it gets personal, and extremely frustrating when technology moves at the speed of government instead of AI.

I'm building FaceIn.id, a passwordless identity system. Part of my job is staying current on industry and authentication trends. I asked my AI agent, Ford Prefect, to sign up for a handful of security and cybersecurity newsletters on my behalf. A simple, zero-risk task — enter an email, click subscribe, maybe confirm — yet it couldn't do it. Most sites blocked the agent with two-factor authentication challenges, CAPTCHA walls, or bot-detection gates that demanded proof of humanity before allowing access to a free newsletter signup form. The same class of authentication that failed to prevent 24 billion credentials from sitting in a publicly exposed database successfully prevented a founder from reading industry news.

Two-factor authentication couldn't stop info-stealers from harvesting passwords at planetary scale, but it absolutely crushed my AI agent's attempt to subscribe to a mailing list about — of all things — cybersecurity.

A newsletter signup is a zero-risk action. Nobody's transferring funds, accessing medical records, or launching nuclear weapons — it's a mailing list. The authentication gatekeeping treats it with the same gravity as a wire transfer. Why are the collective “we” checking IDs at the door of an open-air park? I'm not.

The Wrong Question

The security industry has spent two decades asking one question — “how do we block all bots?” — and the answer has been a progressively annoying stack of CAPTCHAs, SMS codes, authenticator apps, puzzles, and endless images of bridges, crosswalks, fire hydrants, stop lights, buses, cars, motorcycles, squirrels, bad outfits — need I go on? Every year the gates get taller, and every year the bad actors who are supposed to be kept out walk through with no effort.

That's because it's the wrong question, so the answer is moot. The right question is this — how do we tell the difference between a bot signing up for a newsletter and a bot scraping credentials? Between an AI agent booking a flight on your behalf and an agent draining your frequent flyer miles, that difference isn't humanity. It's identity verification proportional to risk.

Two-factor authentication is a blunt instrument that applies the same friction regardless of what's at stake, and it fails precisely where the stakes are highest. It blocks the wrong things because the idea itself is flawed, meaning the application will never work.

The World That's Coming Whether We Like It or Not

AI agents are going to be doing everything, and they kind of already are. You cannot 2FA your way into that future. The answer isn't “prove you're human.” The answer is “prove you're authorized.”

Identity verification doesn't care whether the entity at the door is made of carbon or silicon. It cares whether that entity has legitimate authority, and it scales the verification to match the risk. Signing up for a newsletter? A verified identity token is plenty. Transferring $50,000? Now we're talking biometric confirmation with zero-knowledge proof.

That's what we've built at FaceIn. Passwordless identity verification with zero-knowledge architecture — a system that doesn't block non-humans but verifies intent and identity regardless of whether the agent is human or AI. No passwords to steal, no codes to intercept, no CAPTCHAs to solve or circumvent. Just cryptographic proof that the right entity is doing the right thing at the right level of risk. And a human gave it that authority by proving they had it.

The billions of people whose credentials are sitting in that Elasticsearch database right now — in plaintext, with the URLs attached — deserved better than passwords. And the AI agents that will handle a growing share of the internet's transactions deserve better than being treated like intruders every time they try to subscribe to a blog.

Coming Next Issue

Issue #2: “Does TSA already have your face in the system?”We'll dig into why most “biometric authentication” gets the architecture completely backwards, and what zero-knowledge biometrics means for a world where your face is already in a hundred databases you never consented to.

→ Join the FaceIn waitlist — be first to access identity verification built for humans and their agents

Get The Passwordless Post

New issues, straight to your inbox. No 2FA required.

Identity, authentication, and the slow death of the password — a few times a month. No spam, ever. Unsubscribe anytime.