The queue at the reception desk was six people long, and every one of them was holding a small white rectangle of plastic and saying a version of the same sentence.
My key card has stopped working.
The clerk had the motions down to a reflex: take card, swipe through the encoder, hand it back, smile, next. She wasn’t troubleshooting. She was operating a repair line. Somewhere in the hotel’s operating model, a task that should occur rarely had become the single largest consumer of front-of-house labour, and it had been quietly reclassified as normal.
Nothing at that hotel is broken. The locks work. The encoder works. The cards are manufactured to the same specification they were manufactured to in 1995, and they hold their data exactly as well as they ever did.
What changed is the world the cards have to survive in.
The environment moved
In 1983, working independently, Masato Sagawa at Sumitomo Special Metals and John Croat at General Motors arrived at the same compound: neodymium-iron-boron. It was the strongest permanent magnet material ever made, and - crucially, after the cobalt price shock of 1978 - it didn’t depend on cobalt. Commercial production began late in the decade. Prices stayed high through the 1990s, then collapsed as Chinese mining and sintering capacity scaled through the 2000s.
That price collapse is the event that matters. Not the invention. Once a strong magnet cost pennies, it stopped being a component and became a design convenience. It went into handbag clasps, wallet closures, laptop lids, phone cases, fridge fixings, cupboard catches, headphone cables, tape measures, toys, and eventually into a ring of magnets on the back of every iPhone.
So the modern traveller walks up to a hotel door carrying a portable magnetic hazard they didn’t know they’d bought. A magnetic purse clasp produces somewhere in the region of 50 to 200 gauss. A MagSafe array reaches around 550 - and since the iPhone 12 in 2020, that array has been inside the phone itself, with a second ring in whichever case the owner snapped on top. Qi2 has since carried the same arrangement across to Android.
There’s an irony worth pausing on. For twenty years people warned each other not to keep a key card near a phone, and for twenty years they were wrong about the reason. A handset’s own electromagnetic emissions sit at roughly 50 to 57 gauss and never came close to erasing anything; the real culprit, in that era, was the clasp on the bag the phone was sharing a pocket with. The warning was superstition dressed as physics.
Then, around 2020, the industry quietly bolted a ring of neodymium to the back of every handset, and the superstition became true. The advice was right all along, eventually, for a reason nobody giving it had in mind.
Meanwhile, in the same two decades, magnetic storage vanished from ordinary life. Cassettes, VHS, floppy disks, Zip disks, minidiscs: all gone, all replaced by flash and by silicon. This is the part that deserves more attention than it gets. Consumer magnetic media went extinct at almost precisely the moment that strong magnets became ubiquitous. We stopped being vulnerable at the same time we became surrounded. The two curves crossed and nobody noticed, because the crossing produced no incident.
Except in the places where a magnetic medium survived.
The hotel key card is one of the last of them in daily civilian use. Let’s suppose, just for a moment, that floppy disks were still the medium of record. A floppy could shrug off roughly 300 oersteds before losing its data - the same flimsy grade as a hotel key card. The arrival of cheap neodymium would have produced a rolling, decade-long data-loss event, and we’d have a name for it.
The uncomfortable part
Here’s where the story stops being a neat parable about the march of progress, and becomes something more useful to anyone who runs systems for a living.
Magnetic stripes come in two grades - the trade calls them LoCo and HiCo. The cheap one gives up its data at around 300 oersteds. The tough one holds out to 2,750 - roughly nine times more resistant to stray fields - and costs a few pence more per card. Your bank card is HiCo. Your room key almost certainly is not.
But the more interesting reason your bank card survives the handbag is that you’ve stopped asking it to work. The stripe on a payment card is now vestigial. Between chip-and-PIN, contactless and the phone wallet, most people haven’t swiped a card in years, and Mastercard has committed to phasing the stripe out entirely - no new cards will carry one from 2029, and by 2033 it plans to have none in circulation at all. The stripe on the card in your pocket may already be erased. You’d have no way of finding out, and no reason to care.
That’s the actual lesson from payments, and it isn’t a lesson about materials science. The industry did not harden the stripe against the new environment. It routed around it. Contactless and NFC made the vulnerable component irrelevant rather than robust, and the failure mode went quiet because the function had already moved somewhere else.
Hotels did the same. Almost every modern hotel now issues RFID cards, which cannot be demagnetised at all because there’s nothing magnetic in them to demagnetise. This hotel is simply one of the ones that hasn’t gone yet.
So the hotel’s problem isn’t that an old technology met a new world. The hotel’s problem is that the cheapest available variant of an old technology met a new world, that the migration everybody else completed was deferred one budget cycle at a time, and that the procurement decision holding it all in place was made against an environment that no longer exists.
And the cost of that decision didn’t disappear. It moved. It moved onto the front desk, into a permanent queue of irritated guests, into staff time, into review scores, into the small daily erosion of a brand. It’s being paid in full, every day, in a currency that never appears on the line item where the saving was booked.
Note the final move, because it’s the one that should make you uneasy: the failure has been reframed as user error. You shouldn’t keep it near your phone. The institution has arrived at a story in which the environment is the guest’s fault.
The same shape, somewhere more expensive
If that pattern feels distant, consider SMS one-time passcodes.
When SMS became the default second factor, the underlying bet was reasonable. A phone number was a slow, physical, stubbornly human thing. Porting it required paperwork and a shop. Intercepting a text meant compromising a carrier. The technology wasn’t strong, but the environment around it was, and the combination held.
Then the environment moved. SIM swapping industrialised. Carrier retail staff became a routine social-engineering target. Number porting got faster and more automated, because faster and more automated is what customers wanted. Signalling-layer interception moved from a conference talk to a service you can buy. Adversary-in-the-middle phishing kits made real-time code relay a commodity.
The SMS didn’t get weaker. Everything around it did.
NIST’s response tells you how far this has gone - and for how long. As far back as 2017, SP 800-63B placed SMS and PSTN one-time passcodes in a formal category of their own: restricted authenticators. You may still use them, but you owe your users an alternative that isn’t restricted, meaningful notice of the risks, and a documented migration plan for the day the method is disallowed entirely. The 2025 revision keeps them exactly where they were. That’s not a technical judgement about SMS. It’s a regulator writing down, in public - nearly a decade ago now - that a system’s environmental assumptions have expired. Most of the industry read it, nodded, and kept sending texts.
And the same reframing has already happened. When an account is drained after a SIM swap, the story that surfaces is usually about what the customer should have done differently.
The structure is identical to the hotel: a component that still performs to specification, an environment that has silently withdrawn the conditions it depended on, an upgrade path that is cheap relative to the losses and expensive relative to this quarter, and a failure mode that gets dumped on the user rather than owned by the operator.
Regenerated, not inherited
There’s a version of this that is no longer historical.
A language model reproduces the median of everything it has ever read, and what it has read is thick with LoCo defaults: SMS as a second factor, tokens decoded without verifying the signature, CORS opened to everything, password hashing that was defensible in 2014. The model emits them fluently, with confident comments, in code that clears review because it reads like code that has been reviewed.
The difference is who’s behind it. Legacy code carries an expired assumption that somebody, once, made deliberately and understood. Generated code carries the same expired assumption with nobody behind it - no author to ask, no minuted trade-off, no moment at which the environment was considered at all. The contract was never signed. It was inferred from a decade of examples and copied forward.
Which means the eighteen-month drift into invisibility no longer takes eighteen months. It happens on commit.
What to actually do with this
The bigger point is that a technology is not an object. It’s a contract with an environment. The toughness of a stripe is not a property of the card; it’s a property of the card and the fields it will meet. Phone-number-as-identity was not secure or insecure in itself; it was secure given a set of assumptions about carriers that have since lapsed.
Those assumptions are almost never written down. They’re implicit in the choice, and they become invisible about eighteen months later, when the people who made the choice have moved on and the system has become simply how things are done. Nobody revisits them. Why would they? Nothing has broken.
Five questions, then, for anything you currently operate:
What is this system assuming about the world around it, and when was that assumption last true? Not does it work - it does work, that’s the trap - but what has to remain true for it to keep working.
Who absorbs the failure when the assumption lapses? If the answer is your support desk, your users, or your frontline staff, the cost is real and you’re simply not measuring it. Costs you’ve pushed onto other people don’t show up in the business case for the fix, which is precisely why the fix never clears the bar.
Is the cheap upgrade being blocked by capex optics? HiCo card stock costs pennies. Passkeys cost an integration sprint. The hotel is spending vastly more than the upgrade every month, in a budget line nobody has connected to the decision.
Is the right fix hardening this, or removing the need for it? The payments industry didn’t invent a better magnetic stripe. It made the stripe irrelevant. Upgrading LoCo stock to HiCo buys a hotel a few years; going to RFID ends the problem permanently. Adding SMS rate-limiting buys you a quarter; passkeys make the interception worthless. Hardening the vulnerable component is often the more expensive answer disguised as the cheaper one, because it keeps you in the same contract with the same environment.
And who made this decision - or did anyone? For anything written in the last two years, this is no longer rhetorical. A defensible answer is a person who weighed the trade-off. “It was the pattern that came out” isn’t an answer, and it’s now the most common one.
The practical tell is the one visible in the lobby. When a single complaint dominates your support load and your organisation has stopped treating it as a defect, that is not stability. That is an expired assumption being paid for in instalments.
The front desk is not a cost centre. It’s a sensor. That queue was telling the hotel something precise and actionable, and everyone in it - staff and guests alike - had agreed to hear it as weather.
Which of your systems is paying for an expired assumption?
We work with engineering teams to security-harden the software they’ve built - including the software their tools have written for them - and to migrate authentication off methods whose assumptions have quietly expired.

