You Don't Want Your Identity Back
- Joeri Torfs

- Jun 24
- 6 min read

When a reusable trust credential doesn't return your identity but consolidates the system that took it.
Raj Ananthanpillai's The Trust Crisis: How Big Tech Stole Your Identity — and the New Model That Takes It Back arrives at the end of June, and it lands because the grievance under it is real. Something was taken. Every account, profile, score, credential, employment record, and login you depend on sits somewhere else, and the institution that holds it can suspend it, score it, leak it, monetize it, or be compelled to hand it over. Worse, each time you need to prove who you are, you surrender the same sensitive material again, to one more party that promises to keep it safe. That promise has failed often enough that no serious person should still believe it.
So the answer now forming across the identity industry feels obvious, even overdue: stop making people hand over the same data to everyone. Verify them once, give them a credential they carry and reuse, and let a bank or an employer or a counterparty check only what it needs without collecting everything underneath. Prove the claim without exposing the data. Make identity portable, private, reusable, verified.
This is real progress. It is also where the trap begins.
Because the most commercially legible version of this answer does not give the user their identity back. It builds a better institution to administer it. A private bureau verifies you once, scores you, screens you continuously, and lets companies check the result. Less raw data moves around; the user sees more; the verifier collects less. And then the old structure reappears in a cleaner form, a credit bureau for trust, a FICO score for the rest of life, a TSA PreCheck for the digital world. Its own builders reach for those comparisons approvingly, which should tell you something: they are describing the disease and offering it as the cure. That is not the opposite of the system that failed. It is its consolidation. The honeypot of personal data gets smaller. The bottleneck on legitimacy gets larger.
What the diagnosis gets right
Let's start with what the trust-bureau argument gets right, because it gets a great deal right. The verification system we live inside is structurally abusive. It forces people to overshare because the party doing the checking has no better way to check. A hiring system wants to know whether an applicant is real, employable, licensed, and safe. A gig network wants to know whether a driver or a caregiver is who they claim to be. A bank wants KYC and AML satisfied. The need to verify is legitimate. The method is broken: collect more data, then more, repeated across companies that have no relationship to one another. Every verifier becomes a data collector, every collector becomes a breach surface, every breach feeds more fraud, and every fraud event justifies still more verification. The loop feeds itself.
A reusable credential genuinely breaks part of that loop: verify once, reuse many times, disclose only what's needed, let the verifier check a proof instead of hoarding the data behind it. That is a better architecture than the one we have, and no one serious should wave it away.
A better method, the same structure
But a better verification method can sit on top of the wrong social structure, and that is exactly the danger. The old system said: give every company your data, so each one can decide whether you're acceptable. The trust bureau says: give one bureau the authority to make you acceptable everywhere. The second is more efficient and probably more private. It is not liberation. It changes the mechanics of verification while leaving the structure of judgment intact, and then it adds a threat the old mess never had.
A single company can lock you out of its own service. A bureau that sits between you and the conditions of entry can lock you out of all of them at once. Once employers, financial services, gig networks, and care providers treat one reusable credential as the entry ticket, whoever controls that credential no longer merely verifies identity. They govern participation. They decide whether other people are permitted to treat you as safe, employable, qualified, or acceptable at all. Lose one account today and parts of life get harder; lose standing with the bureau that everyone checks, and the door closes everywhere it is checked. That is not identity returned. It is acceptability centralized.
The line that actually matters
None of this is an argument against cryptographic identity. An identity system can't abolish control; it can only decide how control is held and what survives when it moves. There will be identifiers, keys, recovery paths, issuers, verifiers, and selective disclosure no matter what. That machinery is necessary, and it is not the problem. The question that separates an architecture of freedom from an architecture of capture is narrower and sharper: can you leave?
A custodian you can replace is a service provider. A custodian you cannot replace is a gatekeeper.
That is the whole line. Today almost no one can walk away cleanly. Your history, your credentials, your relationships, your accumulated standing stay behind in the system that administered them, because the record was never yours to carry. It was theirs to hold. A reusable credential issued and scored by a bureau you can't exit does not change that fact. It only dresses it better.
Deterritorialized, not repossessed
This is what it means for identity to be deterritorialized, and it is the opposite of the "take it back" reflex. The point was never merely to seize the vault and hold it yourself. Control matters, but control alone is not exit if the record that gives you standing remains trapped somewhere else. The point is that your identity should not live inside anyone's territory at all: not a company's servers, not a government's data store, not a private bureau's ledger. Deterritorialized Digital Identity is identity with no territorial dependency: identifiers you control and can move, claims you can prove without surrendering what sits behind them, and a standing that travels with you across contexts instead of staying with the institution that happened to register it.
The infrastructure for the verifiable half of this already exists and is being built on: decentralized identifiers and verifiable credentials, the KERI and vLEI/GLEIF lineage for institutional identity, and zero-knowledge proof for showing a claim is true without showing the data underneath. Convenience without surveillance is not a someday promise; it is buildable now. What that proves is feasibility: the pieces compose. Whether the world is ready to stop trusting a bureau and start trusting a record no one can repossess is unproven, and worth saying plainly. None of it is inevitable.
It is not only people who need this. An agent whose identity is a row in its operator's account has no continuity of its own: it dies when the account changes hands, and it can be redeployed under a new name to walk away from what it did. Identity that belongs to the actor and travels with it, whether human or agent, is the only kind that survives a change of owner.
What you actually want
So you do want something back, and it is worth being precise about what. You want control. Control over your identifiers, your keys, your disclosures, your consent, and above all your ability to leave. You want to stop handing raw personal data to every counterparty. You want to stop living as a row in someone else's database. All of that is real, all of it is yours to want, and all of it is now buildable.
What you do not want is the thing being sold to you under the same word. The danger was never that your credentials are portable, or that you hold them yourself. Portable and yours is the goal. The danger is that your identity gets reduced to those credentials: a bundle of proofs that stands in for you, that hardens into a score, that becomes the one thing everyone checks. A portable score is still a gate, even when you are the one holding it. You do not want to become a trust score in anyone's hands, including your own. And you certainly do not want a bureau, public or private, holding the switch that decides whether the rest of the world is allowed to treat you as acceptable.
So yes, you want your identity back. You just do not want it back the way they are selling it. Controlling the proof of who you are is necessary, and it is not the same as being free. Because even once you control every credential and can prove every attribute safely, there is a question none of it answers. Not who you are, but what you have done, and whether, when something is on the line, you can be relied on. A credential cannot carry that, and a score cannot compress it without destroying it. That is the other half of the trust crisis, and it is its own piece.
You do want your identity back. Just not as a thing anyone can hand you, or switch off.


