Then there ought to be a way tp cheaply produce verified but ephemeral identities, which may be discarded after a particular transaction.
User: I want to use this site.
Site: we need your trusted identity.
User: Trusted Third Party, please make an anonymous identity for me.
TTP: I know you, user; here's your new identity.
User: Site, look here, TTP which you trust says I'm legit.
Site: OK, transaction completed. '
User: (destroys the identity's private key.)
It's not very different from TLS certificates, or OAuth tokens, or even ephemeral credit card numbers. The thing is to have a common Trusted Third Party, and somehow keep the number of such parties large enough.