The headshot site does not ask for a password. The site does not ask for a username. The site does not ask for a phone number. The site does not ask for a date of birth. The site does not ask for any piece of information that would tie a reader's reading history to a unique identity. The site's editorial surface is intentionally minimal so that the reader can leave without leaving a trace.
The decision is editorial, not technical. A platform site that maintains a wallet must verify the user's identity at every step. The verification is regulatory. The headshot site is not a platform site, and the verification step is not required. The site's editorial role is to publish reads, not to identify readers. The trade-off is acceptable to the desk because the alternative would compromise the editorial standard.
For readers who want a personal feed, the site publishes an RSS feed at /feed.xml and a sitemap at /sitemap.xml. The two surfaces are standards-compliant and work with any reader that supports them. The site does not maintain a proprietary notification surface. The site does not maintain a saved-search surface. The site's editorial role is the URL; the reader's role is the reader.
If a third-party surface asks for a password on a "headshot login" page, the standard verification step is the URL bar. The canonical URL is headshotin.com. The canonical path for the play entry is /Login/playnow. Any other URL that asks for a password is not a headshot surface, and the desk's recommendation is to close the surface and verify the URL bar against the canonical list on the official-website page.
For readers who have already submitted a password to a third-party surface, the standard recovery steps are: change the password on any account that shares the password, run a security scan on the device used to submit the password, and contact the relevant operator to revoke the third-party session. The desk does not collect passwords, so the desk's password reset is not relevant. The relevant reset is for any other account that shares a password with the third-party surface.
The desk's editorial boundary on the login surface is the same as for any other editorial surface: the desk never publishes invented language, the desk never paraphrases a private leak, and the desk never endorses a third-party surface. The login page is no exception. The page documents the standard and asks the reader to verify the standard on any third-party surface that claims to be a headshot surface.