“Trust me. I am me.”… At 8:17 on a Monday morning, Aya received a message from her bank. A transfer had been attempted from an account she had never seen. She opened her banking application. Her password still worked. Her phone was still in her hand. Nothing appeared to have been stolen. Yet somewhere on the internet, someone was behaving as Aya. The problem, she realized, was larger than a stolen password. For years, people had spoken about “identity verification” as though identity were a single fact that could be checked. Show a passport. Take a photograph. Compare a face. Enter a phone number. Answer a security question. But each method proved something different. A passport could establish that a document had been issued to a particular identity. A biometric check could establish that a living person was present. A cryptographic credential could establish possession of a particular secret. None of these, by itself, answer...