In 2023, researchers at the University of Notre Dame tested 46 commercially available identity verification apps and found that 30% of fraudulent submissions passed undetected — not occasionally, not in edge cases, but as a measurable, repeatable failure rate across real-world conditions.

You probably use one of these apps right now. Your bank almost certainly does.

That number should make you stop and think. Not because technology is bad, but because the gap between what these tools promise and what they actually deliver has real consequences: drained accounts, stolen credit lines, and gig workers being impersonated for months before anyone notices.


The Nightclub Bouncer Problem

Think of it this way: most verification apps work like a nightclub bouncer checking IDs with a flashlight. They look at the surface. They check that the face on the document roughly matches the face in the selfie. They flag obvious fakes. But a well-made deepfake, a printed photo held in front of a camera, or a spoofed video feed? That bouncer waves it through without a second look.

The technical term for what most apps are doing is passive liveness detection. The app analyzes a single image or short video and runs it through a model trained to distinguish real faces from fakes. It does not ask you to do anything. It does not observe you over time. It just looks.

And the people building fraud tools have had years to study exactly what those models are looking for.


Meet the Gap Between “Verified” and “Actually Safe”

Consider the case of a pseudonymous fraud victim I’ll call “David K.” (a composite drawn from documented cases in the 2023 FTC Identity Theft Report). David submitted a standard selfie-plus-ID verification on a popular gig platform in early 2022. Eleven months later, he discovered someone had been accepting delivery jobs under his identity in three states. The platform’s verification vendor had passed a spoofed submission because the attacker used a printed photo manipulated to pass passive liveness checks. The platform’s logs showed: Verified. Confidence score: 91%.

The confidence was high. The accuracy was wrong.

This is not a one-off. A 2022 report from Gartner predicted that by 2025, 30% of enterprises would consider facial recognition verification untrustworthy for high-value transactions without additional layers. That prediction is aging well.

Did You Know: The FTC received 1.1 million identity theft reports in 2022, with impersonation via digital onboarding up 45% year-over-year. Many of those breaches started at exactly the kind of verification step you completed the last time you signed up for a new financial app.


Why You’re Using Broken Tools (And Why No One Told You)

Here is what actually showed up in the data when researchers dug into why these apps persist despite known failure rates: the incentive structure protects the vendor, not the user.

Verification apps are sold to platforms on friction reduction. The pitch is not “we catch every fraud attempt.” The pitch is “we make onboarding fast, and our false positive rate is low.” Low false positives means fewer legitimate users get flagged and frustrated. That is what converts users. That is what platforms buy.

Ask yourself why they do not advertise this part: a low false positive rate and a high false negative rate can coexist. You can build a system that almost never wrongly blocks a real person while still waving through a significant percentage of fake ones. And the platform selling that system has every reason to emphasize the first number and stay quiet about the second.

Convenient, right?

The same dynamic appears in other tech sectors. If you read our analysis of the AI valuation myth that’s reshaping investment decisions, you’ll recognize the pattern: metrics that look good to buyers are not always the metrics that protect users.

And who benefits from you not knowing this? Every platform that wants fast, cheap onboarding without liability.


What Actually Works

Not all verification is equally broken. Here is what the current research actually supports as more reliable.

1. Active liveness detection asks users to perform specific, randomized actions during verification: follow a dot, blink in response to a prompt, turn a specific direction. Because the challenge is unpredictable, pre-recorded deepfakes and static spoofs cannot pass. The tradeoff is friction. Users drop off more. Platforms hate that. But for financial services and healthcare onboarding, the security gain is worth the conversion cost.

2. Behavioral biometrics go further. Instead of verifying identity once at the door, these systems build a continuous behavioral profile: typing cadence, scroll speed, device-handling patterns. Companies like BioCatch (used by over 150 financial institutions as of 2024) have demonstrated fraud detection improvements of up to 80% over traditional methods in published case studies. It is not a one-time check. It watches how you actually use the system over time.

Pro Tip: When evaluating a new platform, ask specifically whether their liveness detection is active or passive. If their support team cannot answer that in one sentence, treat it as a passive system — and weigh the risk accordingly before submitting your biometric data.

Here is what makes behavioral biometrics genuinely different from everything else on this list: it does not give attackers a single moment to defeat. A static verification can be cracked once and the crack holds forever. A behavioral model has to be beaten continuously, in real time, across every session.

3. Decentralized identity frameworks, like those built on W3C Verifiable Credentials or the emerging eIDAS 2.0 standard in the EU, shift the architecture entirely. Instead of submitting your raw ID document to every new platform, you carry a cryptographically signed credential that proves attributes without exposing underlying data. You are not handing the bouncer your wallet. You are showing them a sealed court document that says you are old enough to enter. Microsoft’s Entra Verified ID and the EU Digital Identity Wallet (piloting across member states in 2024) are early real-world implementations of this model.

Warning: If a platform requires you to upload a raw scan of your government ID and does not clearly disclose how long they retain it, what encryption standard protects it at rest, and whether they share it with third-party vendors, you have a problem. Under CCPA (California) and GDPR (EU), you have the right to request deletion of stored biometric data. Exercise that right. Search the platform’s privacy policy for the words “biometric” and “retention period” before you submit anything. If those words are absent, your data is likely being stored in ways you have not consented to and may not be able to reverse.


The Bigger Picture You Are Not Being Shown

The 30% false negative figure is not a bug waiting to be patched. It reflects a market that optimized for the wrong outcome. Fast onboarding converts users. Rigorous verification annoys them. The platforms chose, and they chose conversion.

This same tension between what is easy and what is protective runs through a lot of the tech we trust daily. The friction-reduction logic that gave us broken verification apps is not that different from the dynamic behind why dating apps fail at the one thing they promise: the product is optimized for engagement, not outcomes.

When did you last actually check what verification system your primary bank uses? Not assumed, not guessed based on the fact that they asked for a selfie. Actually checked, by contacting them and asking whether they use active or passive liveness detection?

If the answer is “never,” you are not alone. Most people have not. Most people think “verified” means safe.

It does not always.


Your Next 3 Steps

Step 1: Contact your primary bank or financial platform today and ask one specific question: “Does your identity verification system use active or passive liveness detection?” If the customer service representative cannot answer, ask to be escalated to their fraud or compliance team. A legitimate institution using modern security should be able to answer this. If they cannot, that tells you something important about their verification maturity.

Step 2: This week, search your name and email address in the FTC’s free identity theft reporting and monitoring resource at IdentityTheft.gov, and run your accounts through HaveIBeenPwned.com to check for known data breaches that may have already exposed the credentials attached to your verified accounts. If any platform where you completed biometric verification appears in a breach, contact that platform to request deletion of your biometric data under CCPA or GDPR, and document the request in writing.

Step 3: Before submitting your ID to any new platform going forward, take 90 seconds to do this one check: search the platform’s name plus “biometric data retention policy” and review their privacy policy for the words “liveness,” “biometric,” and “third-party vendor.” If a platform stores raw biometric scans, shares them with unspecified partners, or cannot tell you their retention period, consider whether the service is worth the exposure. For platforms with high financial stakes, look specifically for whether they participate in W3C Verifiable Credentials programs or eIDAS 2.0 pilots — that signals a higher standard of identity architecture than a selfie-plus-ID upload ever will.

The tools to protect yourself exist. The verification industry just has no financial incentive to make sure you know about them.