But a year later when they suddenly decide to actually do that marketing, it's annoying because I no longer even know what that account is for - never mind how to log in.
Many places are making it truly one-click, but there are a fair number that still require you to authenticate before you can change 'account settings' like notification preferences.
Erm... TL;DR: Because of the existing relationship, I"m not sure that CAN SPAM applies.