Sometimes I wonder if we should consider using some sort of a hardware key going forward, like a Yubikey or similar product. Physical devices are fairly easy to understand, and a simple on-device PIN or fingerprint-reader adds a 2FA that prevents a lot of fraud. While an ID number is fairly easy to steal, a GPG private key is nearly impossible if handled right.
Of course, the flip-side, this would open up more opportunities for tracking (requiring the hardware keys to log into Facebook). However, in most societies, we do need some way of authenticating who is who, and at least this approach makes fraud much more difficult.