Being known isn't the same as being watched
What it is
Your identity, online, is whatever lets you prove you’re you. Every login is a small identity ceremony: something you know (a password), something you have (your phone, a passkey), something you are (your face, your fingerprint). When you open a bank account or verify your age, the ceremony gets bigger — documents, photos, the works.
Proving who you are is genuinely useful. It’s how your bank knows the person moving your money is you, and how anyone can tell you apart from someone merely claiming to be you. Identity is not the enemy of privacy. Done right, it’s what lets you be precise: prove exactly the thing that’s needed — I’m me, I’m over 18, I’m the account holder — and nothing more.
Why it’s a problem
Two habits of today’s internet turn identity sour.
First, most proof-of-you is just data — a password, your date of birth, a photo of your license — and data can be copied. Anyone holding enough of your identifying data can be you to a system that only checks data. That’s all identity theft is. And because every service keeps its own copy, your proof is scattered across a hundred databases, each one a place it can leak from.
Second, proving one small thing usually means handing over everything. Need to show you’re over 18? Upload the whole license — name, address, exact birthday, the lot — to a company you’ll never think about again, which keeps it. The proof you needed was one bit of information. The price was a dossier.
Neither habit is a law of nature. They’re just how things are currently built — being known has been bundled with being watched, and the bundle is what needs breaking.
What it costs
Ask anyone who’s been through identity theft what it actually took: not the moment of the theft, but the months after. Fraudulent accounts opened in their name, credit freezes and disputes, tax refunds claimed by strangers, hours on the phone proving they are themselves to institutions that now trust the thief’s paperwork as much as theirs. The victim did nothing wrong — copies of their proof were simply sitting in enough databases that one of them eventually spilled. The breach-notification letters in your own mail are the same story in its opening chapter.
The over-sharing habit compounds it. Every full license upload, every form that demanded the dossier when it needed one fact, added another copy to the pile that can leak. The cost of “just to verify” is paid years later, by you.
Until proving-without-handing-over is how the internet works, the defense is making your accounts hard to steal and your habits hard to exploit — which is exactly what the playbooks below are for.