The internet was never designed with identity in mind. When its foundational protocols were built, the assumption was a small, trusted network of researchers – not a global public square handling banking, healthcare, elections, and commerce. Today, billions of people navigate cyberspace with the most fragile form of identity imaginable: a username and a password. Efforts to build something better – a robust, secure, and universally accepted digital identity infrastructure – have been underway for decades. Yet a truly secure cyberspace identity mechanism remains elusive. The reason is not a lack of technology. The obstacles are structural, cutting across social norms, market economics, legal accountability, and system architecture. Understanding these four barriers is key to understanding why the internet still doesn’t know who you are.

Table of Contents

Why “good enough” is the enemy of secure

The first and perhaps most underappreciated barrier is a cultural one. Most people simply don’t feel that anything is broken. Internet usage continues to grow at a phenomenal pace. People shop, bank, vote, and socialise online every day – and, for the most part, those activities feel fine. There is no visible friction, no flashing warning, no moment where a user consciously thinks, “this identification method is insecure.” The risks are largely invisible until something goes wrong.

This is what researchers call the social norms barrier. Public awareness of identity-related threats remains low, even as the damage from those threats climbs. According to the Identity Defined Security Alliance’s 2024 report, a staggering 90 per cent of organisations experienced at least one identity-related security incident in the past year, and 84 per cent of those reported direct business impacts – up from 68 per cent the previous year. Despite these numbers, most ordinary users do not connect their everyday online behaviour with the concept of systemic risk.

This disconnect creates a powerful inertia. When users perceive no problem, they push back against changes that introduce friction – such as multi-factor authentication, digital certificates, or passkeys. The market responds to user demand, and if users are comfortable with insecure defaults, there is little pressure to move away from them. Recent research from Hypr and 451 Research found that despite widespread awareness of phishing-resistant authentication, usernames and passwords remain the dominant method for 76 per cent of respondents, with passwordless adoption remaining flat year-over-year. The gap between knowing better and doing better is, itself, a barrier.

The market barrier: who pays for trust?

Even if public awareness were not an issue, there remains a fundamental market problem: it is genuinely unclear how a secure, open-standard identity infrastructure can be made profitable. Building the pipes of a trusted identity ecosystem is a public-goods problem – the benefits are diffuse, shared by everyone, and do not neatly accrue to the companies doing the building.

Private companies providing identity verification services can, of course, charge per transaction or per subscription. But a 2025 UK government sectoral analysis found that relying parties – particularly those in retail environments – remain unclear on the concrete benefits of adopting digital identity technologies, which directly suppresses demand and makes it harder for identity providers to build sustainable business models. Meanwhile, the analysis found that smaller market players face particular difficulty investing in the safeguards needed to combat evolving threats such as AI-generated synthetic identities.

The deeper issue is that developing an open standard – a universal identity layer that any service could plug into – requires investment with no guaranteed return. Any single company that builds such infrastructure essentially creates a public utility that competitors can use for free. This is why economic incentives for open-standard identity infrastructure are structurally weak, and why government intervention is frequently cited as a necessary component. The U.S. National Strategy for Trusted Identities in Cyberspace (NSTIC), launched in 2011 under the Obama administration, directly acknowledged this dynamic, positioning the federal government as a necessary partner to the private sector to ensure that an identity ecosystem could be built at all. Even with government backing, agencies struggled to implement it due to technical, policy, and cost barriers.

The market barrier, in short, is that the product everyone needs is the product nobody has a strong individual incentive to build.

Of all the barriers, the legal one may be the most practically consequential – because without clear liability rules, no one is sufficiently motivated to invest in better security. When a digital identity is stolen or misused, who is responsible? The user who chose a weak password? The platform that stored it insecurely? The identity provider that issued the credential? Or the attacker? In current legal frameworks, the answer is frequently: nobody, or nobody with deep enough pockets to make a difference.

Legal scholars have long argued that liability in digital identity cases should follow the concept of the “least cost avoider” – the party best positioned to prevent the harm at the lowest cost. Legal analysis published through the Berkeley Electronic Press draws a compelling analogy: just as a landlord – not individual tenants – is responsible for securing common building areas because only the landlord has the power to do so, database holders are often the only parties with real ability to protect user data. Individual users, by contrast, are in a poor position to control how their personal information is stored or secured once they hand it over to a platform.

Yet the law has been slow to formalise this logic. The U.S. Department of Justice prosecutes identity theft under statutes like the Identity Theft and Assumption Deterrence Act of 1998, which criminalises the misuse of another person’s identification. But criminal prosecution of thieves does not resolve the civil question of which legitimate actor in the identity chain should bear financial responsibility when a breach occurs. Without that clarity, companies have limited incentive to invest in costly security upgrades – particularly if they believe that legal exposure for a breach is uncertain or manageable. The liability problem does not just create confusion; it actively reduces the incentive to build secure systems.

The architectural barrier: choosing how to prove who you are

Even setting aside social, market, and legal challenges, there is a fundamental technical puzzle at the heart of digital identity: how should a system actually verify that a person is who they claim to be? Authentication mechanisms generally fall into three categories, each with its own strengths and critical weaknesses.

Something you know: passwords

The most familiar factor is knowledge-based authentication – primarily, the password. As authentication experts have noted, passwords remain the most common form of digital authentication and simultaneously one of the most vulnerable. A weak or reused password represents what professionals call “low-hanging fruit” – easily guessable through brute-force attacks, dictionary attacks, or phishing. The problem is not that passwords cannot work; it is that human behaviour makes them work poorly at scale. People reuse them, choose predictable ones, and struggle to manage dozens of unique credentials. Microsoft’s security guidance explicitly acknowledges the usability trap: tighter password policies improve security on paper but often lead to workarounds that undermine it in practice.

Something you have: digital certificates and tokens

The second factor involves possession – something the user physically holds, such as a hardware token, a smart card, or a mobile device receiving a one-time code. The World Bank’s Identification for Development framework describes possession factors as physical or virtual cards, certificates, or hardware tokens. They are significantly more secure than passwords alone because an attacker must physically acquire the device, not just learn a secret. However, security researchers have noted that certificate-based authentication can be costly and time-consuming to deploy, and managing lost or compromised devices creates ongoing operational complexity.

Something you are: biometrics

Biometric authentication – fingerprints, facial recognition, iris scans, voice patterns – represents the third factor: something inherent to the individual. Its appeal is obvious. Biometric characteristics are unique and don’t need to be memorised or carried. The Identity Management Institute points out, however, that biometrics introduce a problem that no other authentication factor does: they are irreplaceable. If a password is stolen, it can be reset. If biometric data is compromised – if a fingerprint template is leaked from a database – that vulnerability is permanent. Voices can be recorded, faces photographed, and fingerprints lifted from surfaces. NIST’s implementation guidance cautions that high-resolution cameras have been shown to capture iris patterns in sufficient detail for authentication, and that biometric sensors themselves can be spoofed.

The standardisation challenge

Each of these three factors works better in combination than in isolation. The World Bank’s digital identity framework is explicit: secure authentication for higher assurance levels requires a multi-factor approach, combining possession, knowledge, and inherent factors. But herein lies the architectural barrier – not just choosing the right mix for one system, but standardising that mix across thousands of services, platforms, jurisdictions, and device types. A 2025 UK government survey of digital identity providers found that the most commonly cited barrier to cross-border digital identity use was precisely this: regulatory diversity between countries, disparate technical systems, and the lack of agreed-upon terminology and concepts. A solution that works in one country or one platform often cannot be ported elsewhere without significant re-engineering.

The architectural problem is therefore not purely technical. It is also political and economic: who decides on the standard, who enforces interoperability, and who bears the cost of transitioning away from legacy systems?

The road not yet taken

These four barriers – social norms, market incentives, legal liability, and architectural standards – do not operate independently. They reinforce each other. Low public awareness reduces market pressure for better products. Weak market incentives slow the development of open standards. Unclear liability reduces the urgency of compliance. And fragmented architecture makes it harder to build the shared infrastructure that could, in turn, shift norms and create market opportunities. The U.S. National Strategy for Trusted Identities in Cyberspace put it plainly: overcoming these barriers requires close collaboration between the public and private sectors, and the complete Identity Ecosystem will take many years to develop. More than a decade later, that assessment still holds.

The road to a secure cyberspace identity mechanism is not blocked by a single obstacle. It is a road that requires building the bridge while standing on it – persuading users, restructuring markets, rewriting legal frameworks, and standardising technology all at once. That is a formidable challenge, but understanding each barrier clearly is the necessary first step toward clearing them.

What do you think? If legal liability were clearly placed on the organisations that hold your identity data – rather than on individuals – do you think companies would invest more in security? And given that biometric data cannot be reset once stolen, should users be more cautious about which services they trust with it?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.threatscape.com/cyber-security-blog/why-is-identity-the-new-cyber-security-perimeter/
  2. https://www.biometricupdate.com/202604/digital-identity-research-warns-of-password-debt-as-enterprises-delay-iam-rollouts
  3. https://www.gov.uk/government/publications/digital-identity-sectoral-analysis-report-2025/digital-identity-sectoral-analysis-2025
  4. https://en.wikipedia.org/wiki/National_Strategy_for_Trusted_Identities_in_Cyberspace
  5. https://law.bepress.com/cgi/viewcontent.cgi?article=3530&context=expresso
  6. https://www.justice.gov/criminal/criminal-fraud/identity-theft/identity-theft-and-identity-fraud
  7. https://www.cryptomathic.com/blog/digital-authentication-factors-mechanisms-schemes
  8. https://www.microsoft.com/en-us/security/business/security-101/what-is-authentication
  9. https://id4d.worldbank.org/guide/authentication-mechanisms
  10. https://www.techtarget.com/searchsecurity/tip/Use-these-6-user-authentication-types-to-secure-networks
  11. https://identitymanagementinstitute.org/biometric-authentication-challenges/
  12. https://pages.nist.gov/800-63-3-Implementation-Resources/63B/Authenticators/
  13. https://www.gov.uk/government/publications/international-use-of-digital-identities-and-credentials-stakeholder-survey-responses/international-use-of-digital-identities-and-credentials-stakeholder-survey-responses
  14. https://obamawhitehouse.archives.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Contemporary Scenario of Digital Media

1 Emergence of Digital Media

  1. Defining Digital Media
  2. Characteristics of Digital Media
  3. Digital Media in India
  4. Digital Media and Journalism: Emerging Trends
  5. Challenges

2 Information Society

  1. Technological Transformation and Human Progress
  2. The Emergence of Information Society
  3. What is a Knowledge/Information Society?
  4. Knowledge Economy and Knowledge Workers in an Information Society
  5. Skill Acquisition and Training for Work in Knowledge Society
  6. ICT Infrastructure and Knowledge Dissemination

3 Emerging Trends–Media, Internet, Globalisation

  1. Media
  2. Internet
  3. Globalisation and Human Rights

4 ICTs and Women (Issues of Access and Equity)

  1. Gender Issues in ICT
  2. Women’s Access to ICTs
  3. Strategies for Gender Equity
  4. Benefits of ICTs for Women

5 India Diaspora in Cyberspace

  1. Defining Cyberspace
  2. Understanding Virtual Community
  3. Indian Digital Diasporas
  4. A critical Overview of Literature on Indian Digital Diasporas
  5. ICTs, Nationalism, Religious Diasporas
  6. South Asian Digital Diasporas-Mobile (gadget) Generations

6 ICT and Disability

  1. ICT for Persons with Disabilities
  2. Present and Future of ICT
  3. ICT for various types of Disabilities

7 Convergent Technologies

  1. Electronic Information
  2. Networked Society
  3. Genesis of Convergence
  4. Driving Factors
  5. Technology Convergence
  6. Network Convergence
  7. Switching Convergence
  8. Access Convergence
  9. Service Convergence

8 Open Source Movement

  1. History of Open Source
  2. Open Source Movement
  3. Open Source Software: Philosophy, Principles and Licensing
  4. Types of Software
  5. Desirable Software Attributes
  6. Advantages of Open Source Software
  7. Legal Issues
  8. Other Successful Open Source Software
  9. Applications of Open Source in Other Fields

9 The Regulability of Cyberspace

  1. Desirability of Regulation of Cyberspace
  2. How Cyberspace can be Regulated
  3. Legal and Self Regulatory Framework
  4. Government Policies and Laws Regarding Regulation of Internet Content
  5. Regulation of Cyberspace Content in the United States
  6. Regulation of Cyberspace Content in Australia
  7. Regulation of Cyberspace Content in European Union
  8. Regulation of Cyberspace Content in the United Kingdom
  9. Regulation of Cyberspace Content in India
  10. International Initiatives for Regulation of Cyberspace

10 New Media and Ethical Issues

  1. Definition of New Media Ethics
  2. Rights and Ethical responsibilities of Content Creators
  3. Content Curation and Limits to Sharing
  4. Rights and Ethics of Online Readers
  5. Dealing with Ethical Violations

11 The Concept of Security in Cyberspace

  1. Cyberspace – Why is it not Secure?
  2. Why Should We Secure Cyberspace?
  3. Security Challenges in Cyberspace
  4. The Concept of Cyber Security
  5. Computer Related or Computer Facilitated Crime
  6. Application of Basic Criminal law Concepts

12 Cyberspace and Cyber Crime

  1. Real Space Vs Cyberspace
  2. Digital Identity: An Overview
  3. Verifying Vs. Revealing an Identity
  4. Cyber and Computer Crimes
  5. Architecture of Cyberspace
  6. Preventing Crimes
  7. Implications of Choosing the Link System
  8. Road to Implementation

13 Cyber Law

  1. Concept of Cyberspace
  2. Issues emerging from cyberspace and the need for regulation
  3. International and National Cyber Laws
  4. Information Technology Act, 2000 as amended
  5. Cyber Crimes

14 Information Technology (IT) Act

  1. Statement of Objects and Reasons
  2. Application of the Act – The Extra-Territorial Effect
  3. Electronic Signatures
  4. E-governance
  5. Adjudication
  6. Penalties and Offences
  7. Network Service Provider Liability
  8. Amendments to the Information Technology Act, 14000
  9. Amendments to Certain Statutes