Back when dinosaurs ruled the earth, everyone had to carry a physical driver’s license and a physical passport and a physical key and a physical everything.
Until the smartphone allowed us to place these things, and others, on our phone.
But there is a drawback.
The drawback, which The New Unhinged notes in a Substack article, “When the [REDACTED] Did My Phone Become My Passport?”, is that too many services have ASSUMED you always have your smartphone.
This is a faulty assumption.
“Lose your phone and you may need to prove your identity to the civilization you were just participating in 9 minutes ago.
“Try logging into your bank. We’ve sent a code to your phone.
“That’s the phone I’m trying to replace.
“Try your email. We’ve sent a verification request to your trusted device.
“I HAVE SOME TERRIBLE NEWS ABOUT THE TRUSTED DEVICE…
Try changing your phone number. Please verify your old phone number.“
Of course there are recovery methods if you lose your phone, but they are intentionally designed to be high-friction to keep bad people from claiming they lost your phone.
Or, as The New Unhinged puts it:
“Account recovery is dangerous because whoever controls recovery can potentially control the account.”
Add fraudster techniques such as SIM swaps and IMEI number alterations and it starts to seem more safe to keep stuff in our (physical) wallets.
But what of multi-device authentication methods?
“Better passkeys, portable credentials, multiple independent authenticators, improved account recovery and genuinely usable offline alternatives could make identity less dependent on one device or phone number, not more.”
Of course, identity on multiple devices can complicate things if one of those devices is compromised.
