You have probably verified your identity today without giving it much thought. Maybe you unlocked your phone with your face. Logged into your bank. Confirmed your age on a website. Uploaded an ID document to a service you were using for the first time. Perhaps you recorded a short video of yourself turning your head from side to side because an app wanted to make sure you were a real person.
A few years ago, some of these things would have felt strange. Today, they are becoming routine.
Digital services need a way to know who they are dealing with. Banks need to identify customers. Governments need to identify citizens. Financial platforms need to prevent fraud.
Your passport can be cancelled. Your password can be changed. Your face, date of birth and personal history are a different story.
That is where identity verification becomes interesting.
Your face is becoming a credential
Biometrics seem like a natural answer to the problem.
Passwords can be stolen. Your face is always with you. A fingerprint is difficult to copy physically. A voice can be used as another signal. From a usability perspective, this makes a lot of sense.
There is, however, a slightly uncomfortable difference between a password and a face. If someone gets your password, you change it. If someone gets biometric data that is being used as part of an identity system, there isn’t an equivalent “change my face” button. And your face is not exactly secret information. It appears in photographs, video calls, social networks, company websites and sometimes public records. The same is true of your voice.
That doesn’t make biometric authentication a bad idea. Used properly, it can be very useful. The problem comes when we start treating a successful biometric check as if it proves everything else about a person.
Sourced from 1
The problem with proving that someone is really there
This is where liveness detection comes in. You may have encountered it already. An app asks you to turn your head, blink, look at a particular point or follow some other instruction. The idea is simple – a photograph shouldn’t be able to do that. Except attackers don’t necessarily use photographs anymore.
A video can be manipulated. A face can be replaced. A camera feed can potentially be interfered with. Generative AI can produce realistic faces and voices that never belonged to a real person. The technology on both sides keeps improving.
ENISA’s 2025 Threat Landscape analysed 4,875 incidents covering the period from July 2024 to June 2025 and highlighted the growing role of AI in the threat environment.2
That doesn’t mean liveness detection has suddenly become useless. It means something more mundane and more difficult: security controls cannot remain static while the attacks against them evolve.
An attacker doesn’t need to defeat every part of an identity system.
They just need to find one part that doesn’t work as well as the others.
AI has made impersonation cheaper
You don’t need a large production team to create convincing fake material anymore.
A photograph can be generated. A voice can be cloned. A document can be manipulated. A fake profile can be created in minutes. Messages can be written in fluent language without the attacker having to speak it.
This matters because fraud has always been partly an economic problem. If creating a convincing fake costs more than the potential reward, most criminals won’t bother. If the cost drops dramatically, the calculation changes.
Entrust’s 2025 research found that digital document forgeries had increased sharply compared with the previous year and linked the changing fraud environment to the availability of digital manipulation and generative AI tools.3
But there is another side to this that is easy to miss. The attacker doesn’t always need to fool the technology. Sometimes they only need to fool a person.
A fake employee calls the help desk. A fake customer contacts support. A fake executive asks for an urgent transfer. A fake recruiter asks for identity documents. A fake bank employee tells you that your account needs to be verified immediately. The AI doesn’t have to defeat a biometric algorithm. It just has to make the story believable enough.
The verification company becomes part of the risk
There is another issue I think is worth paying more attention to – where your identity information ends up after you have successfully verified yourself.
Imagine opening an account with a company you use once. During registration, you provide your passport, selfie, date of birth, address and phone number. The verification succeeds. You forget about the company six months later. Then the company is breached.
You didn’t lose your password because you didn’t even use the service anymore. But somebody might now have a copy of an identity document that you were required to provide.
This is the uncomfortable trade-off with digital identity. Verification can reduce fraud at the point of registration while simultaneously creating a valuable database that has to be protected afterwards.
The more information an organisation collects, the more attractive that organisation can become as a target. That makes data minimisation more than a privacy principle. It is also a security principle.
If a website only needs to know that you are over 18, there is a good argument for not giving it your exact date of birth, home address and passport number.
Sometimes the safest piece of personal information is the piece the company never received.
“Identity verified” sounds more definitive than it is
There is something psychologically powerful about seeing a green tick next to a verification result.
Identity verified… It sounds final.
In practice, verification usually means that a collection of checks produced an acceptable result.
- The document passed.
- The face matched.
- The person appeared to be present.
- The phone number worked.
- The email account was accessible.
- The device didn’t immediately look suspicious.
All of those things can be true while the overall conclusion is still wrong.
A stolen identity document can be genuine. A stolen account can be controlled by a real person. A phone number can belong to the attacker. A compromised email account can receive perfectly legitimate verification codes.
This is why a good identity system doesn’t rely on one signal.
| Verification signal | What it tells you | What it doesn’t tell you |
|---|---|---|
| Identity document | The document appears genuine | That the presenter is its legitimate owner |
| Facial match | The face resembles the document | That the image isn’t manipulated |
| Liveness check | The interaction appears to involve a real person | That the person’s identity is legitimate |
| Phone number | Someone controls the number | That it belongs to the claimed person |
| Email address | Someone controls the account | That the account hasn’t been compromised |
| Address | A real location is associated with the data | That the applicant actually lives there |
| Device information | The device and behaviour appear consistent | Who is actually operating it |
None of these checks is useless. The mistake is expecting any single one to answer a much bigger question than it was designed to answer.
There is also a risk of getting legitimate people wrong
Security discussions tend to focus on false negatives – an attacker gets through. There is another problem. A legitimate person gets rejected.
Maybe their passport is damaged. The camera quality is poor. Their document format is unusual. The facial recognition system struggles with the image. They don’t have the required form of identification. They have an accessibility issue that makes a particular verification flow difficult. The system says no.
From the perspective of the software, that may look like a successful security decision. From the perspective of the person trying to access an essential service, it can be a very different experience.
The World Bank’s figures are relevant here again. Hundreds of millions of people still lack official proof of identity, while billions don’t have access to a government-recognised digital identity that can be used to transact online.4
There is a balance to find. A system that accepts everyone is easy to abuse. A system that demands perfect documentation from everyone can exclude people who are perfectly legitimate.
Good identity systems have to deal with both problems.
Think about what you’re actually being asked to prove
One of the easiest habits to develop is to question the amount of information being requested.
A company asks for your passport.
Why?
- Does it really need the complete document?
- Could it verify the required information another way?
- How long will the data be stored?
- Who has access to it?
- Will the document be used only for verification, or retained for another purpose?
These aren’t paranoid questions. They are basic questions about data handling.
- If you need to prove you’re old enough to buy something, proving your exact date of birth may be unnecessary.
- If you need to prove that you’re resident in Switzerland, perhaps the service doesn’t need every detail printed on your passport.
- If you need to prove that you control an account, a full identity document might be excessive.
This is where privacy and security overlap.
Every unnecessary piece of information you give away becomes another piece of information that somebody eventually has to protect.
The identity arms race isn’t going away
There probably won’t be a moment when someone invents the perfect identity verification system and the problem disappears.
Security doesn’t work like that.
Every improvement changes the economics for the attacker. Better document checks lead to better forgeries. Better facial recognition leads to better attempts at facial manipulation. Better liveness detection leads attackers to look for weaknesses somewhere else.
That shift is worth paying attention to.
Fraud isn’t necessarily becoming one spectacular technical attack. It can be a collection of relatively ordinary tricks that work together.
- A stolen document.
- A fake face.
- A compromised email.
- A convincing phone call.
- A weak recovery process.
Each part on its own may look manageable.
Together, they can be enough.
Your identity is becoming part of your security perimeter
Passwords used to be the centre of online security. They aren’t anymore.
Your email account, phone number, devices, recovery methods, biometric information, identity documents and behaviour all form part of the same picture.
An attacker doesn’t necessarily need to “steal your identity” in one dramatic event.
Security is a process, not a product.
Bruce Schneier
They can collect pieces.
A leaked phone number here. An old password there. A photograph from social media. A copy of an identity document from a breached service. Enough information to make the next attack considerably easier.
That’s why protecting your identity requires a slightly different mindset.
Don’t ask only:
- Is my password secure?
Also ask:
- How many places have copies of my identity documents?
- Who can reset my accounts?
- What information am I giving away unnecessarily?
- Would I trust this company with a physical copy of my passport?
- Those questions are much harder to answer with a green tick.
And perhaps that is the point.
Digital identity is going to become more important, not less. We will use it to open bank accounts, prove our age, access government services, sign documents, travel and interact with businesses. The answer isn’t to stop verifying identity.
It’s to become more selective about how we verify it, who we trust with the information, and how much information we reveal. There isn’t one verification method that makes your identity safe forever. There are layers, decisions and habits.
And sometimes the safest decision is surprisingly simple – Don’t give someone your entire identity when all they need is one small piece of it.




