Out of curiosity, what's current thinking (broad strokes) on methods to address this?
My first guess would be third-party attestation of identity, with stored credential disposal on a short schedule? Essentially normal-user-verification-as-a-service?