One Human, Once
Stefan Zweig travelled to India and America before 1914 without owning a passport. He recorded this in his memoirs, with the astonishment of a man who knows that nobody will believe him any more. You got on and you got off; nobody asked, nobody stamped anything. The passport as we know it is an emergency measure of the First World War. In 1920 the League of Nations set a standard for it in Paris, explicitly as a transitional arrangement until the world had calmed down. The transitional arrangement is now a hundred and six years old. Zweig felt it as an insult: the moment the state began to distrust every traveller on principle, and a human being became a suspect who has to prove his harmlessness with papers.
A hundred years later, people queue to look into a chromed sphere the size of a bowling ball and have their irises scanned. Eighteen million have done it by now. In return they received proof that they are a human, and only once, and in many countries a few tokens on top. The distrust has changed direction. In 1920, states distrusted the people at their borders. In 2026, networks distrust their own accounts, and they are right to.
The problem the sphere is meant to solve carries a name from the psychiatric literature. In 2002, John Douceur at Microsoft Research described how a network without a central authority fundamentally cannot tell whether a thousand voices are a thousand people or one person with a thousand accounts. He called it, at a colleague's suggestion, the Sybil attack, after the bestseller about a patient with sixteen personalities. That the book itself is now considered largely fabricated, the personalities more likely produced in the therapy than present in the patient, only makes the name more accurate. The title of this text is the literal answer to Douceur's question. One human, once.
How large the demand for this answer is can be seen from who is buying it. On 17 April 2026, Tinder, Zoom and Docusign announced partnerships with the sphere company, along with Okta, Shopify and Vercel. They did so although the procedure has been banned or halted in Spain, Portugal, Brazil, Kenya, Indonesia and the Philippines. Kenya's High Court ordered the destruction of the data of over three hundred thousand people in May 2025; the Bavarian data protection authority forced the deletion of the German records. Tinder buys anyway, because Tinder has an authenticity problem it cannot solve any other way. A procedure objected to from Nairobi to Munich finds paying enterprise customers. That is not a footnote about a crypto project. That is the price the market is willing to pay for the answer to Douceur.
From this it is easy to draw the wrong conclusion: that identity in crypto has failed. What has failed can be seen from the projects that solve the same problem and that no authority moves against. Self, zkPassport and Privado collect nothing. They own no database that could be deleted, and whoever stores nothing has nothing to say in reply to a deletion order. What is under attack is not decentralisation. What is under attack is the database. The one company wanted to be, itself, the place that certifies who is a human, and built an archive of eyes for it. The others read a place that has long existed.
That place is itself a by-product, and one that nobody built for this purpose. After September 11, the American Congress demanded that every country whose citizens may enter without a visa issue passports with a biometric chip. The International Civil Aviation Organization poured that into a standard, Germany began delivering in November 2005, and today around a hundred and eighty states issue passports with a radio chip inside. On the chip sit name, date of birth, nationality and document number, and over them sits a signature of the issuing state. Change one field and you destroy the signature. Built as an instrument of counterterrorism, paid for with the passport fees of billions of travellers, intended for border control. The infrastructure was complete before anyone had the idea of using it for something else.
The second ingredient was rejected at birth. In 1985, Shafi Goldwasser, Silvio Micali and Charles Rackoff proved that you can prove without showing, and their paper on it was turned down several times before it was allowed to appear. Goldwasser still enjoys telling the story. Later there was a Turing Award for it. Cryptographers once explained the principle in a paper written for children, with a ring-shaped cave whose inner door opens only to a magic word: whoever comes out of the passage the verifier calls out knows the word, and the verifier has still never heard it. Translated to the passport, it means this: the phone does not pass on the fields from the chip but computes a statement about them, for instance that the date of birth lies more than eighteen years back, plus a second number proving that the statement comes from correctly signed data. Anyone can check the second number. Nothing can be computed back out of it.
For the question of whether the same human has been here before, you have to look a moment longer, because the real question is how a place recognises a returner without keeping a list of people. The phone derives a number from the passport data and an identifier that is valid only for this one place. The same passport yields the same number at this place, every time, and a different one at every other place. So the place does not store nothing. It stores a number from which the passport cannot be computed back and which means nothing outside its walls. Two rooms can lay their lists side by side and find no overlap. The passport itself never leaves the phone.
So much for the parts. The reason I am writing this down now is a deadline.
The last text ended with an account that belongs to the barista in Lisbon, filled with dollars, for notes about coffee he would have written anyway. While writing it, I did not think about the fact that this account has a date. On 1 July 2027, Article 79 of the European anti-money-laundering regulation takes effect, and it prohibits banks, financial institutions and crypto service providers from keeping anonymous accounts, explicitly including accounts that anonymise transactions. Whoever reads the regulation instead of the commentary on it finds room to move, and it is drawn more precisely than the first fright suggests. The obligation falls on the parties that hold or exchange other people's money. The dividing line runs along the keys: whoever holds them can freeze an account and hand it over, and whoever can do that is taken into duty by the law. A self-custodied wallet is software on the user's device, its maker never touches the money, and Article 79 exempts him explicitly. The planned cap of one thousand euros on payments from such wallets was struck from the text in March 2024. But the moment a service provider is involved, it tips, and the check applies from one thousand euros.
From this follows a way of building that fits in one sentence. Pseudonymous in the room, named only at the till. The barista needs no legal name to leave a note about an espresso. If he wants to exchange into euros, he gives his name to the service provider doing the exchange, and that is where it belongs.
This way of building has a more venerable history than its critics suspect. The American constitution was defended by a pseudonym. Hamilton, Madison and Jay wrote eighty-five newspaper articles in 1787 and 1788 under the name Publius, and New York voted on arguments, not on men. Their legal names lay, meanwhile, where names belong: at the printer's, in office, before the court. The room in which the argument happened knew only Publius. Pseudonymous in the room, named at the till is not an invention of the crypto scene. It is the division of labour of the Enlightenment, and it disappeared from the net only because for thirty years nobody there built a till where a name would have cost anything.
Europe is currently building its own tool for the same task, and it is worth looking closely at why it is the wrong one. By the end of 2026, every member state must offer a certified digital wallet. It can do selective disclosure, it can do pseudonyms, and where no legal duty to identify exists, services must even accept those pseudonyms. On paper, that is exactly the tool. Except that whoever wants to query it must be a legal entity domiciled in a member state, must register, must declare in advance which data it will request and for what purpose, and afterwards stands in a public register kept, in Germany, by the Federal Office of Administration. A protocol cannot register. Neither can a community.
Germany has, incidentally, run this experiment before, and the result is in. The national identity card has been able to identify its holder online since November 2010, with selective disclosure, with a pseudonym function, technically clean. Whoever wanted to query the function needed an authorisation certificate from an office at the Federal Office of Administration. Seven years later, activation of the function had to be declared the default by law, because hardly anyone had ever used it, and not because the technology was bad. There were simply almost no places that had taken the registration route upon themselves. The wallet repeats this construction with better cryptography, and the cryptography was never the problem.
The chip in the passport demands none of this. No registration office, no directory, no application. It lies in a drawer in almost every household in Europe, and it answers two different questions at two different places. At the till it gives the name to the service provider, because the law wills it so. At the door it gives only the one piece of information, that this human has not been here before, and the name stays in the phone. One passport, two disclosures. The one at the till is prescribed by law. The one at the door then costs nothing more, because whoever must build the reader for the till anyway gets it at the door for free. The legislator has, without wanting to, made the most expensive component of the whole construction mandatory, at exactly the place where a company with a balance sheet and lawyers stands anyway. What remains is the cheap part.
This closes an arc the last text left open. WeChat could fuse the social and the financial only because a single company held the graph, the money and the identity in one hand, and exactly this concentration is what the West does not allow. The chain, so it said there, does on the money side what concentration did in Shenzhen, without the single owner. The chip in the passport is the same thing on the identity side. It is the third leg of the fusion, and it is the only one nobody has to own. One company tried to own it privately and was stopped in half a dozen countries. Europe is building the state version and demands for it, once again, a registered legal entity with an authority above it. The third possibility has been in use at every airport for twenty years and belongs to no one.
The picture is not complete, and the gaps belong in a paragraph rather than under the rug. The certificates used to check passport signatures are distributed by the civil aviation organisation under terms that rule out commercial use; the freer list kept by Germany's Federal Office for Information Security is a toleration, not a rail. When a passport is renewed, the link to the old proof breaks. In the basic form, nobody checks whether the person holding the phone is the person on the document. And the price hits the wrong people: the World Bank most recently estimated around eight hundred and fifty million people without any official proof of identity, the great majority in Africa and South Asia, and a passport is a step above that still. No chip, no proof. Whoever builds at this door builds this threshold too.
Which leaves Zweig. He took the passport for the moment the world closed, and suffered for the rest of his life from the fact that a human being now needed papers to count as harmless. The document that came of it could do exactly one movement for a hundred years: hold the name fast and have it shown at every border. Now it lies in the drawer, and with the chip inside it can, for the first time, do the reverse movement. It can vouch for a human and keep the name.
At the door, nobody asks your name. Zweig would have taken that sentence for a memory.
100% written with AI.
