[1/2]
> Many many services ask for phone number as a proxy for "this is a unique human".
Anyone can get as many phone numbers as they want for less than $5/each.
And there is a better way to rate limit account creation -- you pay $5 to create an account. For a legitimate user this is a nominal one-time fee, but a spammer has their account banned in minutes and has to pay over and over, and the fee directly pays the costs of fighting spammers so the more there are the more funding you get.
The biggest problem with this is, ironically, that we messed up our payments systems so that it's really hard to pay anyone over the internet without disclosing your identity. Which makes "pay a nominal fee instead of giving your identity" pretty hard to implement. If you want to fix something, fix that.
> Strong identity should be the default, anonymity only when needed or desired by a select digital community.
Anonymity has to be the default because it's needed by specific people rather than specific communities. Most people on some huge social network don't need to be anonymous but the minority who do need it desperately. They're a minority that needs to be protected even though a conglomerate would be willing to steamroll over them because they're not a large enough population to affect the bottom line.
> The iPhone has been remotely exploitable since its introduction. Still, I don't know of a single Secure Enclave exfiltration exploit because it's hardware separated. Regardless, your doom and gloom scenario has yet to play out so I'm calling FUD.
It hasn't been a huge problem because the majority of people haven't had a single-root digital ID on their phone and the majority of services don't currently accept one. But there have been known to be vulnerabilities in various hardware security modules, some of them remotely exploitable. It's a bad assumption that no one will ever find another one.
And the problem isn't just the scale, it's the scope. Even Apple had a Secure Enclave vulnerability, which was reported to require physical access, but sometimes the attacker has physical access. And then it's not that you can access the bank accounts of millions of people, it's that you can access all the accounts of anyone whose phone you can steal because you've put every egg into the basket of that single ID. Which the attacker can then use without showing their face in a physical place.
> There is no that.
That's my point. That is the law against giving false information on an application for government ID, which isn't any more effective than a law against giving false information on an application for a bank account, and shouldn't be necessary on an application for phone service or similar.
> I don't know of any banks that let you bypass identity verification because you lost your credential. You have to go get a new credential.
You did the identity verification when you opened your account. They generally don't need to see your ID again. They were going to send a new card there anyway because the cards expire every few years and they automatically send you a new one.
> Fun fact, phone companies are now requiring ID verification via state issued credentials to make changes to your account.
Not because they care about your name, because they don't want attackers stealing their actual customers' phone numbers and digital credentials can be stolen remotely, so they resort to physical ID. Making the government ID a remotely stealable digital credential is not solving their problem.
> Nobody cares if the human uses a user-agent software to browse the web.
You don't want players using bots to play your game, so you say captcha to continue if they play suspiciously well or suspiciously long. Asking for ID doesn't work because the bot can present the human's ID.
You don't want Archiveteam scraping your site, but they have many volunteers willing to each run a slow crawler from a separate IP and it's hard to distinguish the bots from real users, so you use captchas. Using IDs instead doesn't work because each of the volunteers has a unique ID.
Company wants to use AI marketing bots in the same way as they pay astroturfers, but now instead of paying $1000/month they pay 100 times as many people $10/month just to use their ID. Each bot gets an ID, and the bots aren't conspicuous so they don't get banned quickly, they just post a lot of 20th percentile-quality content and really love that company's products. If anybody's ID gets banned the company replaces them with someone else. There are a million people willing to take a ban from a site they don't use in exchange for a little money.
Lots of people currently use captchas in places where asking for ID wouldn't do any good. Rate limiting by ID overlaps heavily with rate limiting by IP address.
> All these things are enabled by a lack of scarcity in identity or anonymity (two sides of the same coin).
These are not at all the same thing. You can get access to a large number of unique identities with a relatively modest amount of resources, and demanding ID won't be effective for anything requiring more of a deterrent than that. Conversely, you can rate limit based on anything scarce, not just ID.
Having users post a bond is particularly effective because you can make the amount scale with how aggressively you need to deter bad actors, and it's technically possible (though not currently convenient) to do this anonymously.
You can also rate limit by reputation by using vouching systems etc. etc., none of which requires the person doing the vouching or the person being vouched for to be using the same identity on your site as they use in any other place.
> Because strong identity is scarce, you don't get to make up accounts for a bot and then just roll a new one when that bot is banned. You get one shot and if you blow it and don't play by the rules your account is banned, your spam and abuse potential is now zero instead of one.
This is what I mean by creating new problems. What do you do if you get hacked and then banned from everything? It's one thing to lose a $5 deposit or have to start over with a new account on one service, what do you do after your ID gets banned from all social media and every major infrastructure provider in a consolidated market? Tying everything to one root is bad.
> If you're being targeted by your government then you can't use systems with strong identity anyway (whether it's form the 20th or 21st century isn't important), so it's a moot point. You can't use banks with KYC because all your accounts are frozen or being watched. You can't communicate using government regulated comms channels.
There are different levels of being targeted by the government. If your abusive ex is a cop, you need to be able to operate under the radar so they can't find you. That doesn't mean they can have your bank account frozen without raising red flags, so you can still go to the bank to get enough cash to run away.
> If you don't like yours then move elsewhere or yes reach for true anonymity and operate beyond the pale.
In general we try to improve the government, e.g. by increasing the ability for the public to maintain their anonymity. Especially when that country is the US and the US is the country preventing other countries from e.g. providing their citizens with an anonymous bank account. Where are you even suggesting someone go? Sealand?
> Nooo. Trust is not rooted in your address. It's rooted in presentation of a birth certificate and residency documents to a government agency. Only after you attest to your name and bind your name to an address is an address trusted.
A birth certificate is just a piece of paper with a name on it. They have no way of knowing if that's your name. No authentication is happening there.
This stuff isn't based on cryptography or signature verification or anything. It's based on it being a crime to lie about it in particular contexts, which deters people from doing that. "Attesting to your name" is something you could do just the same to the bank. All you have to do is make it illegal to give a false social security number to a bank and you have the same level of security as you do to get the government ID.
> Any system where I can't just make up arbitrary details about myself is to be destroyed. Okay that's practical.
Being made up is where names come from, and people don't have a single name. Married people often change their name and carry on using both of them in different contexts.
A particularly relevant example is stage names. Their name in the credits isn't the name on their mortgage or in their high school year book. They'll use their stage name for a social media account. Using their other name is dangerous because if their social media account gets hacked, the name on their mortgage gets out and stalkers show up at their house.
This is as true for minor celebrities as major ones, if you do certain kinds of work or discuss certain kinds of topics, so those people need to use a pseudonym on the internet. With no way for anyone to tie it to where they live. Even if they're not famous enough to have Big Tech CEOs in their address book.