A person's identity is precious, but because of the way technology and identity have evolved, today's systems don't treat it with the care it deserves.
That is not just a problem for the individual. It is at the root of hacking, account takeover, and fraud.
The issue is straightforward. Systems take a risk-based approach to identity when identity is actually binary. In isolation, a particular use case may not feel like it warrants strong identity verification, but the risk has to be considered through the lens of the user, not the use case.
A user's data is not used only in your interactions with them. They use it everywhere, because it is how they identify themselves to everyone. Bad actors exploit that ubiquity, correlating legitimate and stolen data to commit crime. A risk-based approach to identity provides the opportunity and creates the demand for the criminal activity that follows. The fact that a service does not always know who its user is, is both why it is hacked and how it is hacked.
The best identity systems are reserved (by virtue of cost) for banks and governments. Even those are flawed enough that money can still be stolen and identities compromised. That is not an argument for stronger versions of the same architecture. It is an argument for a different architecture altogether.
Companies should not be the arbiters or holders of a person's identity. The only viable universal context for a digital identity system is the individual person themselves. Everything else, from nationality to employment to qualifications, is a credential related to that person, not the identity itself.
Treating a person's identity with the care and respect it deserves looks like it might actually bear unexpected fruit. If the data isn't there to steal and the credentials can't be compromised, the problems caused by their presence also go away. Identity treated properly reduces cybercrime.



