The summary.
IDENTIFICATION, AUTHENTICATION AND AUTHORISATION ARE THREE DIFFERENT THINGS
Conflating them causes serious faults. And two passwords are not two factors.
PHISHING-RESISTANT AUTHENTICATION BINDS THE PROOF TO THE SITE
Which is why security keys and passkeys defeat phishing where codes do not — a code can be relayed to a fraudulent site.
The hard problem with passwordless is recovery, and recovery must not be weaker than the primary method. Attackers target the weakest route.
BIOMETRICS CANNOT BE CHANGED IF COMPROMISED
Never transmit or centrally store raw biometric data. Match on device, in secure hardware, and always offer a non-biometric alternative.
Accuracy varies across demographic groups — test against your actual population.
A VERIFICATION PROCESS ASSUMING UNIVERSAL DOCUMENTATION EXCLUDES LEGITIMATE CUSTOMERS
Which matters here. Provide alternative routes and human review, and retain the result rather than copies of documents.
DATA NOT COLLECTED CANNOT BE BREACHED, MISUSED OR DEMANDED
Pseudonymisation is a security measure, not anonymisation — re-identification from supposedly anonymous data is well documented.
Automate deletion at end of retention, because manual deletion does not happen.
AUTOMATE ENRICHMENT AND TRIAGE FREELY; AUTOMATE DISRUPTION CAUTIOUSLY
A false positive that isolates production causes the outage the attacker wanted.