I’ve been musing about a similar but more simple problem: how can we prove we are an individual human in the context of a web service. Think of this like the ultimate CAPTCHA where not only can you prove you are human but every person can do so at most once or, more pragmatically, O(once).
The closest thing we have in society today is Sign in with Apple, where you have a delegated identity provided by a company which has effectively put up a large portion of its brand value as collateral that it won’t be shady, for some definition of the term “be shady”. This is suboptimal for a number of reasons, not least of which is that they can be compelled by a government to divulge this data while (mostly) protecting their brand-value-collateral, and they can be selective in what types of services are allowed to use this system.
I’m hopeful some of the non-charlatan web3 folks can come up with some sort of scheme where a trusted entity (a government or a civil rights oriented NGO) can participate in a cryptographic handshake with an end user and a service where at the end the service receives a unique identifier for that user which can not be used to associate that user across services, or divulge to the trusted entity which services a particular individual is using. This wouldn’t fully solve the “can I give this person a loan” problem, but would make many things on the web much better (most bots pretending to be human would become cost prohibitive). I also feel like trustworthiness attestation can be incrementally built on such a system (if such a system is possible).