Back in primary school, we all learned the same lesson about information: sources matter. Primary, secondary, tertiary. A letter written in someone's own hand, a newspaper reporting on that letter, an encyclopedia summarizing the newspaper. What that lesson was really teaching us wasn't how to find information. It was how to trust it. You knew where a fact came from, who touched it along the way, and how far it had traveled from the original.

Then the internet arrived, and data didn't change. What changed is that the chain of custody disappeared. You're not watching the ink dry. You're not hearing the person speak. Everything arrives as a copy of a copy, over a wire, from somewhere.

The internet turned everything into a tertiary source, then asked us to trust it like a primary one.

The security guard problem

Think about how a school keeps track of who belongs inside it. The guard at the door isn't interrogating anyone. Most of the job is recognition: the same kids, the same parents, the same staff, day after day. Familiar faces walk through. It's only the unfamiliar visitor who gets routed to the front office to show an ID, sign in, and wear a badge. That simple, two-part system handles almost every case. Not because the guard is brilliant, but because physical reality does most of the work: one person, one body, standing at the door. A card the office can hold and tilt. A face to compare it against. A community small enough to know.

Now try that online. There is no recognition layer. Nobody at the door knows your face, so every interaction gets routed down the visitor path: prove who you are, from scratch, every time. Except you can't feel the card. You can't compare the face. And here's the part almost nobody says out loud: online, the act of checking is itself a risk. Ask a stranger to send their ID, and what comes back might not be an ID at all. Verification became a two-way street where either direction can carry an attack.

But the deeper difference isn't the checking. It's the materials. Offline, a cement wall today is a cement wall tomorrow. Online, that same wall can turn out to have had a window in it all along, hidden behind the storage closet, and nobody knew, not even the builder, until someone found it. That's what a "vulnerability" is: not a wall failing, a window being discovered. It's also what most breach letters are actually announcing: someone found a window in a wall you share with millions of other people. So a defense you set once can't just stand there the way a guard at a door can. Someone has to keep walking the walls.

The workaround we all inherited

The internet was built without a way to know who is on the other end. Identity was never in the blueprint. Anonymity is the default, and proof had to be bolted on afterward by every institution that needed it.

So what did they bolt on? The questions they had always asked. Your date of birth. Your mother's maiden name. The physical world's institutions accepted those for a century, so instead of challenging the status quo, the internet quietly built around it.

And notice the path it took. In-person verification became phone verification became a web form. The teller's window questions got photocopied onto a screen, but the window didn't come with them. At every step, the questions stayed exactly the same, while everything that made those questions safe was stripped away: the face, the familiar voice, the branch you walked into. The internet didn't invent new proof. It kept the old proof and threw away the room that made it work.

Facts are not secrets

Here is the mechanism at the bottom of all of it. Verification is supposed to rest on secrets: something only you know, only you have, or only you are. But your date of birth and your mother's maiden name are not secrets. They are facts. They come up at a barbecue. They are printed in yearbooks and obituaries. They sit in breach dumps from services you forgot you signed up for.

And unlike a password, they can never be changed. When a password leaks, you rotate it. You cannot rotate your mother's maiden name.

That is the paradox we all live inside: the information you would share by default with someone you just met, over something as benign as making plans, is the same information an institution accepts as proof that you are you. Not because you were careless. Because a decision made for a world with guards at the door was carried, unchallenged, into a world with no door to stand at.

That's the flaw. It was never yours, and understanding it won't make it go away. The questions aren't being retired, the institutions aren't rewriting them, and as long as they're in use, people will stay the way in. No amount of reading changes that.

Here's what does change. Remember the guard: the job was never thick walls. It was knowing what belongs, and routing what doesn't through the front office. Online, nobody is working your door, so the job falls to you. Learn what belongs in your accounts. Treat anything unfamiliar as a visitor, no matter how official it sounds. And send every visitor through your front office: the number on the back of your card, the website you typed yourself, never the link that arrived on its own.

Because most scams aren't lockpicks. They're someone walking a long street, trying handles. You can't get off the street. You can be the door that doesn't open.