The British company doing age verification for Discord got hacked and the hackers got about 70k user identity documents. Discord claimed that the scanned documents would be deleted after verification. Surprise! They were not deleted at all.
What about a signed attestation of your identity based on your passport? I don’t particularly want a future where we need to present ID for any online service, but for certain high-risk services (e.g. financial services, medical records, government portals) I’d rather a proper identity system than cobbling something like this together.
As an aside, when traveling internationally it’s not uncommon to need to provide your passport information if you want to get a sales tax rebate. I’ve never purchased something expensive enough abroad to bother with it.
https://www.theguardian.com/media/2025/oct/09/hack-age-verif...