Previously, there were three different layers of “fraud” (and its corollary, validation) on the Internet. These are important in case a transaction is litigated:
- Is this a real identity/user
Think: this is a valid government document, the profile is real and maps to a government database, etc. - Is the “person” I am interacting with the valid owner of this identity/user/credential
Think: identity not stolen, so the credential user maps to the credential identity. - Is the person of sound mind to make this decision?
Think: casino not letting you gamble while clearly intoxicated.
1 and 2 are the most common, but for particularly large “card not present” transactions where issues of friendly fraud arise (“Oh, I never made that OnlyFans or Zynga Poker $10,000 purchase!”) there’s some validation of 3.
Agents complicate all of this. An agent can have delegated authority, but how? How is the whole validation chain preserved for the ultimate transaction? Who bears the risk?