The identity industry has spent years developing increasingly sophisticated credential and identity management frameworks, but many of those systems still suffer from a fundamental weakness: they cannot reliably prove that the person presenting a credential is the person to whom it was issued.
That was the central message of an opening keynote delivered by FaceTec Chief Identity Technology Strategist Jay Meier at Identity Week Europe in Amsterdam. Meier argued that the industry has focused heavily on cryptography, digital credentials, and identity verification workflows while neglecting the critical relationship between a verified identity and the human being behind it.
“The binding between the photograph, your face, and your verified identity data is critically important,” Meier told attendees. “That’s something that has been missing in much of the discussion of identity management systems over the years, and it’s created a lot of vulnerabilities.”
Meier framed identity credentials as a three-way relationship connecting verified identity data, biometric characteristics, and the privileges associated with an identity. A driver’s license, for example, links an individual’s verified identity and face to the legal privilege of operating a vehicle. Passports and payment cards function similarly, he said.
The challenge emerges when those relationships are transferred into digital environments. Large-scale data breaches have made personal information widely available to criminals, allowing them to create convincing counterfeit credentials using legitimate identity data. If those credentials are accepted during digital onboarding, a fraudster’s face can become associated with a victim’s identity within an identity verification system.
“We already know that all of our identity data has been stolen. It’s all available on the dark web,” Meier said.
The rise of generative AI is making the problem more acute, he added, pointing to the growing ability of AI systems to generate convincing identity documents that are difficult for human reviewers to distinguish from genuine credentials. FaceTec has also been drawing attention to the shift from spoof media to biometric injection attacks, a threat category in which attackers try to feed manipulated biometric data directly into verification systems.
Meier also questioned assumptions underlying some digital identity architectures. While describing modern credential frameworks as cryptographically sophisticated, he argued that many systems focus on the holder of a credential rather than the verified owner of that credential.
“The problem is we don’t know who the holder of the device is,” he said. “It is not necessarily the owner.”
Smartphone biometrics illustrate the issue. Device-based authentication confirms that a presented face matches biometric data stored on the device, but does not inherently prove the identity of the person using it. If a criminal gains control of a device and enrollment credentials, they may be able to replace the original biometric profile with their own.
The result is that even highly secure identity ecosystems remain vulnerable to probabilistic uncertainty. Cryptographic protections may be deterministic, but human identity verification can only increase confidence rather than eliminate risk entirely.
“We cannot know for sure, ever, if you are who you say you are,” he said. “All we can do is raise the probability that we know who you are.”
As a potential solution, Meier proposed bringing trusted identity data out from behind government firewalls while preserving the relationship between identity attributes and biometrics established by issuing authorities.
The concept centers on digitally signed biometric barcodes, which FaceTec markets as UR Codes. The technology embeds identity information and biometric data within a digitally signed QR code that can be stored digitally or printed onto physical credentials and documents. Rather than querying a central database, a relying party would compare a live biometric sample against biometric information contained within the code itself.
“It’s the database file moved into the hands of the consumer,” Meier said.
FaceTec has been advancing the UR Code concept as a way to extend verified identity beyond controlled environments, and has also described potential applications for healthcare identity workflows. Meier argued in Amsterdam that such an approach could allow organizations to verify identity while reducing dependence on centralized lookups and limiting the amount of personal information shared with governments or other third parties during transactions.
The keynote reflected a broader debate unfolding across the digital identity sector as governments, financial institutions, and technology providers seek stronger assurances that digital credentials remain tied to the individuals they were originally intended to represent. Much of the industry’s attention has focused on digital wallets and biometric approval flows, verifiable credential governance, and interoperability frameworks. Meier’s remarks placed biometric binding at the center of that discussion.
–
By the ID Tech Editorial Team






Follow Us