This article is the result of a collaboration between Pierluigi Pilla and Luigi Castaldo, Wallet Ecosystem Director at Namirial.
A birthday, and a warning
“I’m turning 41, but I don’t feel like celebrating. Our generation is running out of time to save the free Internet built for us by our fathers.”
— Pavel Durov, Telegram founder, posted on X on his birthday, 10 October 2025 [1]
On the day he turned 41, Pavel Durov refused to celebrate. Among the “dystopian measures” he listed in his birthday message — alongside mandatory age checks in Australia and proposals to scan private messages in the EU — one item came first: government digital IDs. His warning crystallized a growing unease within the tech community.
The free internet, he argued, is not disappearing overnight; it is being reshaped by design choices and policies that make persistent identification the default. Government-backed digital identity systems are increasingly framed as neutral infrastructure — tools for security, compliance, and efficiency.
Yet identity is never just technical plumbing. Once embedded, it redistributes power, redefines access, and narrows the space for anonymity. The question is not whether digital identity works, but why its expansion so often feels like the end of something we are struggling to name.
Before going any further, hold on to one question. It will return, in different costumes, in every episode of this story: when we say no to digital identity, where does identity go?
Because it does not vanish. It moves.
The mark of the beast
The anxiety is older, and stranger, than today’s policy debates. When Georgia rolled out electronic identity cards in the early 2010s, resistance did not come from privacy lawyers. It came from Orthodox religious communities, where the new chip-based documents were described as the “mark of the beast” from the Book of Revelation — a sign of irreversible moral submission and total control.
Many citizens simply refused the cards. The pressure was real enough that in 2013 a government minister publicly pledged to purge the number 666 from identification numbers [2]. It is easy to smile at the theology. It is harder to dismiss the intuition underneath it: that an identity system, once accepted, cannot easily be given back.
The same fear, in constitutional language
In the United States, the same intuition speaks a constitutional language. The Electronic Frontier Foundation has consistently challenged government-backed digital identity wallets and mobile driver’s licenses on civil-liberties grounds, warning against function creep, centralized trust, and the gradual erosion of anonymity through infrastructure rather than explicit censorship [3].
A theological objection and a constitutional one, born continents apart, converge on a single fear: digital identity systems rarely remain optional. Once adopted, they become prerequisites.
And when access to digital services depends on state-sanctioned identity, architecture quietly becomes governance.
The other half of the story
Opposition, however, tells only half of the story. In parallel, a broad coalition of governments, institutions, and industry actors is promoting digital identity as a necessary upgrade to the internet’s trust layer.
In the European Union, eIDAS 2.0 and the European Digital Identity Wallet aim to provide interoperable, state-backed credentials for authentication, payments, signatures, and access to public and private services — replacing today’s fragmented login ecosystem and reducing dependency on platform-controlled identity [4].
At a global level, the World Bank’s Identification for Development (ID4D) initiative frames digital identity as a prerequisite for economic inclusion: a portable, verifiable ID as the entry ticket to banking, healthcare, education, and social protection [5].
UN agencies increasingly describe it as digital public infrastructure — as foundational as roads or payments.
One ambition, two architectures
These are no longer blueprints. National digital identity systems already operate at scale — and two of them, placed side by side, frame the entire debate.
Estonia’s eID underpins nearly all public services — yet the country maintains no central database of its citizens: data stays federated across separate agency registries, exchanged over an audited backbone (X-Road), with private keys held on the user’s own card or device [6].
India’s Aadhaar has enrolled more than a billion residents around a centralized biometric database [7] — a feat of inclusion that has also generated documented controversies over exclusion errors and data concentration. Same ambition, opposite answers to the same architectural question — where should data and keys live? — and, tellingly, opposite anxieties.
Which suggests something the polarized debate keeps missing: perhaps the risks of digital identity are not intrinsic to it, but contingent on how it is built.
Who fears the wallet most? Its own architects
And here the story takes its most instructive turn.
Ask who has written the most technically devastating critique of the European Digital Identity Wallet, and the answer is not Durov, not the EFF, not a pulpit in Tbilisi.
It is a group of researchers who have spent their careers building digital identity. In a recent white paper — “European digital identity: A missed opportunity?” [8] — researchers from SolidLab (Ghent University – imec) argue that the EUDI Wallet, as currently specified, risks re-centralizing trust rather than redistributing it.
The critique targets architectural and regulatory choices: reliance on OpenID-based flows that blur technical roles, static credential models that limit future interoperability, and institutional trusted lists that decide which wallets, issuers, and verifiers may participate at all. Many of the wallet’s promised benefits — privacy, user control, portability — are, in this reading, overstated; some risks are merely displaced from identity providers to wallet providers. Trusted lists, in particular, echo long-standing problems in PKI root programs and browser trust stores: new gatekeepers, new incentives for surveillance or lock-in.
Notice what the insiders are not saying. They are not asking to abandon digital identity — they treat identity as unavoidable. Their alarm is about timing: premature design decisions being frozen into regulation before they can be audited, extended, or repaired.
The most credible critics of digital identity, in other words, agree with its promoters on the destination and disagree violently about the blueprint.
What architecture can promise – and what it can’t
This reframes the entire controversy. No protocol requires surveillance; no standard mandates oppression. Surveillance remains a political choice.
But architecture decides the price of that choice — how cheap, how easy, how invisible mass observation becomes once someone in power decides to attempt it. That is why design debates that look like engineering minutiae are, in fact, constitutional questions in disguise.
Which leaves a sharper, more honest question than the one usually asked. Not “can a state be trusted?” — no architecture can answer that. Rather: what can architecture itself guarantee, and what must remain a political question?
Consider a system that faced the harshest possible stress test. Ukraine launched its Diia app in 2019; within eight hours, two million people had signed up. Then, in 2022, came the invasion — and an identity system built for convenience became a lifeline. Millions fled without papers, so the government issued a digital eDocument that let displaced citizens prove who they were at checkpoints and apply for emergency payments in a few taps; in the first week alone, over 2.7 million aid applications were submitted through the app.[9]
Today Diia serves more than 21 million users across some 70 government services, from business registration to war-damage compensation — and Ukraine has since begun open-sourcing its code so others can inspect and reuse it.[10]
What makes Diia instructive is not that it is flawless, but what it reveals about the boundary between engineering and governance. Its designers deliberately kept data federated rather than pooled in one master database, exchanged over a secure backbone — the same architectural instinct as Estonia’s. Here is what such design can guarantee: that data stays compartmentalized, that exchanges leave verifiable traces, that no single breach exposes everything.
And here is what no architecture — Ukrainian, Estonian, or European — can guarantee: the political accountability of whoever governs the infrastructure. That part is not an engineering deliverable, and pretending otherwise is how identity debates go wrong in both directions.
What makes any of these systems defensible is not the degree of centralization, but how much must be taken on faith — and how much can be verified.
Europe places its bet
This is exactly the bet Europe is now placing with the European Digital Identity Wallet. Stripped of jargon, the wallet rests on three promises to ordinary people.
The first is user control: your credentials live on your own phone, not in a government or corporate database, and nothing is shared without your say-so.
The second is selective disclosure — the ability to reveal a single fact instead of a whole document. Asked to prove you are over 18, the wallet can confirm just that, without handing over your name, address, or date of birth.
The third is unlinkability: by design, the parties you show your credentials to should not be able to compare notes and stitch your separate interactions — a doctor’s visit, a bank login, a bar’s age check — into one running profile of your life.
Together these principles are what privacy by design actually means: not a promise to behave well, but a system built so that misbehavior is structurally hard.[11]
None of this removes the need for a trusted authority — and this is the point critics of any central role often miss. The wallet still relies on trust anchors: authoritative lists confirming which issuers and services are genuine. But their job is to protect the user, not to watch them. Without a trust anchor, nothing stops a counterfeit credential from impersonating a real bank, or a fake website from posing as a hospital to harvest your data. The anchor is the equivalent of the seal on a passport — it lets you verify that the other side is who it claims to be. The design challenge, as Europe’s own researchers warn, is keeping those anchors narrow: gatekeepers that certify authenticity without quietly becoming chokepoints for surveillance or exclusion.[12]
This is the real fault line of the debate — not whether digital identity has risks, but whether those risks are intrinsic or contingent. Function creep, exclusion, and single points of failure emerge from poor design and weak governance, not from the mere existence of identity infrastructure.
Architecture is the necessary condition; governance is the rest.
Meanwhile, the benefits are already tangible: reduced fraud, selective disclosure, lower onboarding costs, cross-border interoperability, and a check on the unchecked power of platform-controlled identity silos.
So – where does identity go?
Which brings us back to the question planted at the beginning: when we say no, where does identity go?
In practice, for most people and most uses, it does not disappear — it is outsourced. To platforms, to data brokers, to advertising ecosystems that identify us continuously, invisibly, and without recourse.
Rejecting public digital identity does not preserve anonymity; it mostly privatizes identification. The real choice is not whether to adopt digital identity, but how to design it so that trust is distributed, auditable, and accountable rather than concentrated and opaque.
This is where architecture becomes decisive: hardware-backed key management, user-held credentials, and wallet-based models that keep data on the person’s own device and minimize what is ever exposed.
Solutions such as the Namirial Wallet follow exactly this trajectory — building on strong cryptographic foundations while moving credential management into the user’s hands.
Durov is right about one thing: time is running out. But the clock is not counting down to the moment digital identity can still be stopped — that moment, if it ever existed, has passed. It is counting down to the moment its architecture hardens.
The free internet will not be saved by refusing to be identified; it will be saved, or lost, in design decisions being made right now.
Seen through this lens, digital identity is not the end of the free internet. It is one of the last opportunities to redesign its trust layer consciously — before it solidifies around infrastructures we neither control nor understand.
References
[1] P. Durov, post on X, 10 October 2025.
[2] G. Lomsadze, “Georgia Removes ‘666’ from ID Cards”, Eurasianet, 2013.
[3] Electronic Frontier Foundation, “Digital ID Isn’t for Everybody, and That’s Okay”, 2024; “DHS’s Flawed Plan for Mobile Driver’s Licenses”, 2021.
[4] Regulation (EU) 2024/1183 (“eIDAS 2.0”); European Commission, “European Digital Identity”.
[5] World Bank, Identification for Development (ID4D) initiative.
[6] e-Estonia, “e-Identity” and “X-Road / Interoperability Services”.
[7] Unique Identification Authority of India (UIDAI), Aadhaar.





