Anonymity and the Internet
Universal identification is portrayed by some as the holy grail of Internet security. Anonymity is bad, the argument goes; and if we abolish it, we can ensure only the proper people have access to their own information. We'll know who is sending us spam …
Context & Ripple Effects
The identification question had been cycling through the press for years before this piece: MSNBC's late-2005 look at demands for verified identity (Let's see some ID) was followed within weeks by Wired's report on packaging anonymity tools for ordinary users. By early 2010 the two camps were well defined — one treating universal identification as the fix for spam and fraud, the other building ways to opt out of identification entirely.
Schneier's essay enters that running debate on the anonymity side, attacking the premise that abolishing pseudonymity would ensure 'only the proper people have access to their own information.' It matters because he is arguing against a policy instinct — mandatory identity online — rather than a single product or ruling, giving the pro-ID position its most prominent security-community rebuttal to date in this coverage.
First-order effects
- Policymakers and platforms weighing identity-mandate proposals as an anti-spam and anti-fraud measure now face a direct counterargument from one of security's most widely read voices, forcing the pro-identification case to defend itself on attacker economics rather than intent.
- Ordinary users are the immediate constituency: under a universal-ID regime the verifiable cost falls on legitimate participants who lose pseudonymous cover, while the spammers and fraudsters the scheme targets have both incentive and skill to acquire clean credentials.
Second-order effects
- If authentication requirements spread, abuse shifts rather than disappears — stolen and rented real identities replace throwaway accounts, moving the burden onto identity issuers and the services that rely on them for trust decisions.
- Anonymity-tooling projects gain a policy rationale beyond circumvention: as the pro-ID camp pushes identification as infrastructure, tools that preserve unlinkability become the practical fallback for users the mandates fail to protect.
Third-order effects
- The essay crystallizes a structural tension that outlasts any single proposal: an internet organized around verified persistent identity versus one that preserves pseudonymous spaces for speech, whistle-blowing, and vulnerable users — a fault line regulators will revisit whenever spam, fraud, or harassment spikes.
- Security practice increasingly separates authentication (proving you control an account today) from identification (knowing who someone really is), suggesting durable architectures will authenticate actions without collapsing all activity into legal identities.
The trend: Each wave of anti-spam and security pressure revives calls for universal online identification, and each revival draws the same counterargument that anonymity protects legitimate users more than it shields attackers.