{
  "slug": "the-standards-gap",
  "title": "What each standard proves, and what it cannot",
  "summary": "Each identity standard answers one question correctly. The questions differ, and the fraud has moved into the gaps between them. A reference for engineers.",
  "lede": "This is not a page about deficient standards. Every specification named here answers a precise question correctly, and most of them answer it better than anything that came before. The problem is that the questions are different from one another, practitioners assume they overlap more than they do, and the fraud has moved into the space between them.",
  "date": "2026-10-03",
  "reading_time": "26 min read",
  "category": "Pillar",
  "tags": ["standards", "WebAuthn", "OAuth", "3-D Secure", "Sigstore", "verifiable credentials", "eIDAS"],
  "image": "https://cdn.twc.sh/images/igcache/The%20Standards%20Gap/1200_630/blog.jpg",
  "url": "/blog/the-standards-gap.html",
  "wordcount": 5988,
  "related": ["passkeys-prove-login-not-transaction", "identity-failure-map", "receipts-and-portability"],
  "schema": "Article"
}
