The internet was never designed with identity in mind. When its foundational protocols were built, the assumption was a small, trusted network of researchers – not a global public square handling banking, healthcare, elections, and commerce. Today, billions of people navigate cyberspace with the most fragile form of identity imaginable: a username and a password. Efforts to build something better – a robust, secure, and universally accepted digital identity infrastructure – have been underway for decades. Yet a truly secure cyberspace identity mechanism remains elusive. The reason is not a lack of technology. The obstacles are structural, cutting across social norms, market economics, legal accountability, and system architecture. Understanding these four barriers is key to understanding why the internet still doesn’t know who you are.
Table of Contents
- Why “good enough” is the enemy of secure
- The market barrier: who pays for trust?
- The legal barrier: the liability problem
- The architectural barrier: choosing how to prove who you are
- Something you know: passwords
- Something you have: digital certificates and tokens
- Something you are: biometrics
- The standardisation challenge
- The road not yet taken
Why “good enough” is the enemy of secure
The first and perhaps most underappreciated barrier is a cultural one. Most people simply don’t feel that anything is broken. Internet usage continues to grow at a phenomenal pace. People shop, bank, vote, and socialise online every day – and, for the most part, those activities feel fine. There is no visible friction, no flashing warning, no moment where a user consciously thinks, “this identification method is insecure.” The risks are largely invisible until something goes wrong.
This is what researchers call the social norms barrier. Public awareness of identity-related threats remains low, even as the damage from those threats climbs. According to the Identity Defined Security Alliance’s 2024 report, a staggering 90 per cent of organisations experienced at least one identity-related security incident in the past year, and 84 per cent of those reported direct business impacts – up from 68 per cent the previous year. Despite these numbers, most ordinary users do not connect their everyday online behaviour with the concept of systemic risk.
This disconnect creates a powerful inertia. When users perceive no problem, they push back against changes that introduce friction – such as multi-factor authentication, digital certificates, or passkeys. The market responds to user demand, and if users are comfortable with insecure defaults, there is little pressure to move away from them. Recent research from Hypr and 451 Research found that despite widespread awareness of phishing-resistant authentication, usernames and passwords remain the dominant method for 76 per cent of respondents, with passwordless adoption remaining flat year-over-year. The gap between knowing better and doing better is, itself, a barrier.
The market barrier: who pays for trust?
Even if public awareness were not an issue, there remains a fundamental market problem: it is genuinely unclear how a secure, open-standard identity infrastructure can be made profitable. Building the pipes of a trusted identity ecosystem is a public-goods problem – the benefits are diffuse, shared by everyone, and do not neatly accrue to the companies doing the building.
Private companies providing identity verification services can, of course, charge per transaction or per subscription. But a 2025 UK government sectoral analysis found that relying parties – particularly those in retail environments – remain unclear on the concrete benefits of adopting digital identity technologies, which directly suppresses demand and makes it harder for identity providers to build sustainable business models. Meanwhile, the analysis found that smaller market players face particular difficulty investing in the safeguards needed to combat evolving threats such as AI-generated synthetic identities.
The deeper issue is that developing an open standard – a universal identity layer that any service could plug into – requires investment with no guaranteed return. Any single company that builds such infrastructure essentially creates a public utility that competitors can use for free. This is why economic incentives for open-standard identity infrastructure are structurally weak, and why government intervention is frequently cited as a necessary component. The U.S. National Strategy for Trusted Identities in Cyberspace (NSTIC), launched in 2011 under the Obama administration, directly acknowledged this dynamic, positioning the federal government as a necessary partner to the private sector to ensure that an identity ecosystem could be built at all. Even with government backing, agencies struggled to implement it due to technical, policy, and cost barriers.
The market barrier, in short, is that the product everyone needs is the product nobody has a strong individual incentive to build.
The legal barrier: the liability problem
Of all the barriers, the legal one may be the most practically consequential – because without clear liability rules, no one is sufficiently motivated to invest in better security. When a digital identity is stolen or misused, who is responsible? The user who chose a weak password? The platform that stored it insecurely? The identity provider that issued the credential? Or the attacker? In current legal frameworks, the answer is frequently: nobody, or nobody with deep enough pockets to make a difference.
Legal scholars have long argued that liability in digital identity cases should follow the concept of the “least cost avoider” – the party best positioned to prevent the harm at the lowest cost. Legal analysis published through the Berkeley Electronic Press draws a compelling analogy: just as a landlord – not individual tenants – is responsible for securing common building areas because only the landlord has the power to do so, database holders are often the only parties with real ability to protect user data. Individual users, by contrast, are in a poor position to control how their personal information is stored or secured once they hand it over to a platform.
Yet the law has been slow to formalise this logic. The U.S. Department of Justice prosecutes identity theft under statutes like the Identity Theft and Assumption Deterrence Act of 1998, which criminalises the misuse of another person’s identification. But criminal prosecution of thieves does not resolve the civil question of which legitimate actor in the identity chain should bear financial responsibility when a breach occurs. Without that clarity, companies have limited incentive to invest in costly security upgrades – particularly if they believe that legal exposure for a breach is uncertain or manageable. The liability problem does not just create confusion; it actively reduces the incentive to build secure systems.
The architectural barrier: choosing how to prove who you are
Even setting aside social, market, and legal challenges, there is a fundamental technical puzzle at the heart of digital identity: how should a system actually verify that a person is who they claim to be? Authentication mechanisms generally fall into three categories, each with its own strengths and critical weaknesses.
Something you know: passwords
The most familiar factor is knowledge-based authentication – primarily, the password. As authentication experts have noted, passwords remain the most common form of digital authentication and simultaneously one of the most vulnerable. A weak or reused password represents what professionals call “low-hanging fruit” – easily guessable through brute-force attacks, dictionary attacks, or phishing. The problem is not that passwords cannot work; it is that human behaviour makes them work poorly at scale. People reuse them, choose predictable ones, and struggle to manage dozens of unique credentials. Microsoft’s security guidance explicitly acknowledges the usability trap: tighter password policies improve security on paper but often lead to workarounds that undermine it in practice.
Something you have: digital certificates and tokens
The second factor involves possession – something the user physically holds, such as a hardware token, a smart card, or a mobile device receiving a one-time code. The World Bank’s Identification for Development framework describes possession factors as physical or virtual cards, certificates, or hardware tokens. They are significantly more secure than passwords alone because an attacker must physically acquire the device, not just learn a secret. However, security researchers have noted that certificate-based authentication can be costly and time-consuming to deploy, and managing lost or compromised devices creates ongoing operational complexity.
Something you are: biometrics
Biometric authentication – fingerprints, facial recognition, iris scans, voice patterns – represents the third factor: something inherent to the individual. Its appeal is obvious. Biometric characteristics are unique and don’t need to be memorised or carried. The Identity Management Institute points out, however, that biometrics introduce a problem that no other authentication factor does: they are irreplaceable. If a password is stolen, it can be reset. If biometric data is compromised – if a fingerprint template is leaked from a database – that vulnerability is permanent. Voices can be recorded, faces photographed, and fingerprints lifted from surfaces. NIST’s implementation guidance cautions that high-resolution cameras have been shown to capture iris patterns in sufficient detail for authentication, and that biometric sensors themselves can be spoofed.
The standardisation challenge
Each of these three factors works better in combination than in isolation. The World Bank’s digital identity framework is explicit: secure authentication for higher assurance levels requires a multi-factor approach, combining possession, knowledge, and inherent factors. But herein lies the architectural barrier – not just choosing the right mix for one system, but standardising that mix across thousands of services, platforms, jurisdictions, and device types. A 2025 UK government survey of digital identity providers found that the most commonly cited barrier to cross-border digital identity use was precisely this: regulatory diversity between countries, disparate technical systems, and the lack of agreed-upon terminology and concepts. A solution that works in one country or one platform often cannot be ported elsewhere without significant re-engineering.
The architectural problem is therefore not purely technical. It is also political and economic: who decides on the standard, who enforces interoperability, and who bears the cost of transitioning away from legacy systems?
The road not yet taken
These four barriers – social norms, market incentives, legal liability, and architectural standards – do not operate independently. They reinforce each other. Low public awareness reduces market pressure for better products. Weak market incentives slow the development of open standards. Unclear liability reduces the urgency of compliance. And fragmented architecture makes it harder to build the shared infrastructure that could, in turn, shift norms and create market opportunities. The U.S. National Strategy for Trusted Identities in Cyberspace put it plainly: overcoming these barriers requires close collaboration between the public and private sectors, and the complete Identity Ecosystem will take many years to develop. More than a decade later, that assessment still holds.
The road to a secure cyberspace identity mechanism is not blocked by a single obstacle. It is a road that requires building the bridge while standing on it – persuading users, restructuring markets, rewriting legal frameworks, and standardising technology all at once. That is a formidable challenge, but understanding each barrier clearly is the necessary first step toward clearing them.
What do you think? If legal liability were clearly placed on the organisations that hold your identity data – rather than on individuals – do you think companies would invest more in security? And given that biometric data cannot be reset once stolen, should users be more cautious about which services they trust with it?
References
- https://www.threatscape.com/cyber-security-blog/why-is-identity-the-new-cyber-security-perimeter/
- https://www.biometricupdate.com/202604/digital-identity-research-warns-of-password-debt-as-enterprises-delay-iam-rollouts
- https://www.gov.uk/government/publications/digital-identity-sectoral-analysis-report-2025/digital-identity-sectoral-analysis-2025
- https://en.wikipedia.org/wiki/National_Strategy_for_Trusted_Identities_in_Cyberspace
- https://law.bepress.com/cgi/viewcontent.cgi?article=3530&context=expresso
- https://www.justice.gov/criminal/criminal-fraud/identity-theft/identity-theft-and-identity-fraud
- https://www.cryptomathic.com/blog/digital-authentication-factors-mechanisms-schemes
- https://www.microsoft.com/en-us/security/business/security-101/what-is-authentication
- https://id4d.worldbank.org/guide/authentication-mechanisms
- https://www.techtarget.com/searchsecurity/tip/Use-these-6-user-authentication-types-to-secure-networks
- https://identitymanagementinstitute.org/biometric-authentication-challenges/
- https://pages.nist.gov/800-63-3-Implementation-Resources/63B/Authenticators/
- https://www.gov.uk/government/publications/international-use-of-digital-identities-and-credentials-stakeholder-survey-responses/international-use-of-digital-identities-and-credentials-stakeholder-survey-responses
- https://obamawhitehouse.archives.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf
Leave a Reply