The Oldest Problem
1.0 What this chapter gives you#
- You will be able to explain, in one sentence at a dinner table, why a village needs no identity system and a city cannot survive without one.
- You will be able to name the moment a society stops asking “do I know you” and starts asking “can you produce a credential”, and say what it gains and what it loses at that moment.
- You will be able to describe how a Mesopotamian cylinder seal worked, and say exactly what a seal impression proved and what it never proved.
- You will be able to carve, on paper, an English Exchequer tally for a real sum of money using the notch widths recorded in the twelfth century, and split it into its two halves.
- You will be able to explain why a split tally is a shared secret held by two parties, and why that is a different kind of proof from a seal.
- You will be able to state what a handwritten signature actually proves, what it does not prove, and why it took until the seventeenth century to become legally load-bearing in England.
- You will be able to read the Roman watchword drill and the shibboleth incident as authentication protocols, and point at the failure mode of each.
- You will be able to say why identity documents are a very recent invention, and give the dates of the 1920 Paris conference that fixed the shape of the passport in your drawer.
- You will be able to trace the line from a lump of clay to the machine readable passport specification that governs border control today.
Every identity system ever built has been an answer to one question, and the question has not changed in five thousand years. The question is: this person in front of me, or at the other end of this letter, or on the other side of this network connection — are they the one I think they are, and how would I know if they were not?
In a small enough group the question answers itself. You do not check your mother’s credentials, or ask your neighbour of thirty years for proof of address. Recognition is free, instant, accurate and needs no technology. It is also the only identity system human beings evolved to use, and it is why the rest of this book has to exist: recognition has a hard ceiling, we went straight through it about five thousand years ago, and we have been improvising ever since.
Everything after that ceiling is a substitute for recognition. A seal pressed into clay, a stick broken in two, a password whispered at a gate, a signature at the foot of a page, a passport, a bank card, a one-time code, a passkey on your phone — all substitutes for the thing a baker in a village of two hundred people does for free when he looks up and says your name. Each substitute is worse than recognition in some specific way, and better in some other specific way, and knowing exactly which is the whole of the professional skill.
This chapter walks the history as engineering, not decoration. Every object in it — the seal, the tally, the watchword, the signature, the passport — is a design with a threat model, a verification procedure and a documented failure mode. When we reach passkeys and certificate chains in later volumes, you will find the designs have not multiplied. There are only a handful of ideas, all invented in clay, wood, wax and speech long before anybody had a computer, and the computer only made them faster.
The plain version#
The baker who knows your face#
Imagine a village of two hundred people. There is one baker. Every morning you walk in, and he hands you your bread and writes a mark in his book, and once a week you pay him.
Notice what has not happened. He did not ask your name, or for a card, or check anything against anything. He looked at you, and the looking was the check. He has seen your face perhaps three thousand times, knows your voice, knows how you walk, knows your mother; and if a stranger with your exact face walked in tomorrow claiming to be you, he would know within seconds that something was wrong, without being able to say how he knew.
This is recognition, and as an identity system it is astonishingly good. It costs nothing, happens in under a second and uses no equipment. It cannot be stolen from you, because it is not stored anywhere you could be robbed of — it lives in the baker’s head. It is hard to fake, because it is not one signal but dozens, all checked at once and none written down. And it gets stronger over time rather than weaker, because every morning adds another observation.
It has exactly one problem. It does not scale.
What happens when the village becomes a city#
The baker can hold a few hundred people in his head. Not a few hundred names — a few hundred people, faces and voices and histories together. Beyond that, faces start to blur.
Now put that baker in a city. Around 3100 BC the city of Uruk in southern Mesopotamia, in what is now Iraq, covered something like 250 hectares and may have held around 40,000 people, with perhaps 80,000 to 90,000 in the surrounding countryside — on current estimates the largest urban area in the world at the time. A baker in Uruk could not know his customers. A temple official could not know the men who brought grain to the storehouse. A merchant sending forty jars of oil upriver could not accompany them and could not know the man at the other end.
Something had broken, and in a very specific way. It was not that people had become dishonest. It was that the number of people you might have to deal with had grown far past the number you can hold in your head, and the two numbers had come apart permanently.
Pause on the shape of that break, because every single thing in this book is a consequence of it. In a village, the number of people you deal with is smaller than the number you can remember, so recognition covers everything. In a city it is enormously larger, so recognition covers a tiny fraction and something else must cover the rest. There is no clever version of recognition that fixes this. You cannot remember harder. The only way out is to stop relying on memory and start relying on an object.
The thing you carry instead of being known#
The first answer, and a very old one, was to give the person a thing.
In Mesopotamia, from around 3400 to 3100 BC, people carried a small stone cylinder, usually two to three centimetres long, drilled through the middle so it could be worn on a cord. Carved into its curved surface, backwards, was a picture: animals, a god, a banquet, a name. Rolled across a lump of wet clay, the picture came out the right way round, repeated as often as you rolled it.
So a merchant would tie a rope around the mouth of a jar, press a lump of soft clay over the knot, and roll his cylinder across the clay. Three useful things were then true at once. The jar could not be opened without breaking the clay, so tampering showed. The clay carried a picture the trade recognized as one particular merchant’s. And the merchant did not have to be there.
That last point is the whole invention. The cylinder seal let a person’s authority travel without the person. The man at the other end of the river did not know the merchant’s face, and did not need to. He knew the picture.
The same idea reappears in different materials. A signet ring is a cylinder seal flattened onto a finger. When the Book of Genesis, at chapter 41 verse 42, has Pharaoh take the ring from his own hand and put it on Joseph’s hand, that is not jewellery given as a present; it is administrative authority transferred, because whoever holds the ring can make marks officials will obey. A wax seal on a medieval letter is the same object again, pressed into hot wax instead of clay. England’s Great Seal, used to authenticate documents issued in the sovereign’s name, worked on this principle for centuries, and copying it illegally was punishable by death.
The stick that was broken in two#
The seal solves one problem: proving that a message or a jar came from a particular source. It does not solve a second problem, which is proving that two people agree about something.
Suppose you lend the king a large sum. He gives you a receipt. Later you come back and ask for your money. How does his treasurer know the receipt is the one his office issued, and not a good copy, or a genuine one for a smaller sum with a nought added?
England’s answer, in use from around 1100 under Henry I and running for well over six hundred years, was beautifully simple. Take a stick of hazel or willow. Cut notches all the way across it, in an agreed code that records the amount. Then split the stick down its length, through every notch, so each half carries the same notches with the same irregular grain running through them.
The longer half is the stock, and goes to the person who handed over the money. The shorter is the foil, and stays with the Exchequer, the government’s finance office. When you claim, you produce your stock, the clerk fetches the foil, and he puts them together. If the notches line up and the grain runs continuously across the join, the claim is genuine.
Notice what makes this work. Nobody has to trust either half alone, and nobody has to recognize you. The proof is not in the wood but in the match, and the match is very hard to forge, because you would have to reproduce not just the notches but the random split of one particular piece of wood.
This is, in a real sense, the first two-party shared secret. Two parties each hold a piece of something. Neither piece proves anything on its own. Put them together and the truth falls out. Every shared-secret scheme since — the password you and a website both know, the key you and your bank both hold — is doing the same trick with different material. Chapter 13 handles shared secrets properly.
The word at the gate#
There is a third problem the seal and the tally both fail to solve: speed. Sometimes you must check a hundred people in the dark in ten minutes, and nobody has time to fetch a stick.
The Roman army’s answer was the watchword. Polybius, writing his Histories in the second century BC, describes the drill in book 6, chapter 34, and it is more careful than most people expect. Each evening a military tribune wrote the night’s word on a small wooden tablet. The tablet went to a man from the tenth maniple — a maniple being a unit of the legion — who carried it back to his own quarters and passed it, before witnesses, to the commander of the next maniple, and so on up the line until it reached the maniples camped nearest the tribunes’ tents, who had to hand it back to the tribune before dark.
Read that again, because there is a second mechanism hiding in it. Distributing the word is the obvious part. Returning the tablet is the clever part. If every tablet comes back, the tribune knows the word reached every unit. If one does not, he knows exactly where it went wrong, because the missing tablet names the maniple that broke the chain and the officer who answers for it. Distribution and audit in one loop, in the second century BC.
The watchword is fast, costs nothing to carry, and can be changed every night. It also has an obvious weakness, which the Romans understood perfectly well: the moment one person tells it to the wrong person, everybody who knows it is equally undetectable, because the word does not remember who spoke it.
The word you cannot learn in an afternoon#
There is a variant of the watchword that fixes exactly that weakness, and it is older and darker.
In the Book of Judges, at chapter 12 verses 5 and 6, the men of Gilead hold the crossings of the river Jordan against the fleeing men of Ephraim. When a man asks to cross, they ask whether he is an Ephraimite. If he says no, they tell him to say the word shibboleth. He says sibboleth, because, in the words of the text, he could not pronounce it right. The passage records forty-two thousand of Ephraim falling at the fords.
This is a different kind of test entirely. The watchword is a secret: it works because the enemy has not been told it. The shibboleth is not a secret at all — the guards say the word out loud to the person being tested, before he answers, and telling him does not help him. What is tested is not knowledge but a physical habit laid down over twenty years of learning to speak, which cannot be acquired between being asked and having to answer.
It is the ancestor of every check that measures what you are rather than what you know, and of every such check’s ugliest property: it does not test what it claims to test. It tests where you grew up. A loyal Gileadite raised among Ephraimites fails. That is not a hypothetical flaw. It is the flaw, and it will come back in this book every time a system tries to read identity off a body.
The little book you show at the airport#
Now jump a very long way forward, past most of recorded history, to the object you probably keep in a drawer.
Here is the surprise. For nearly all of that history, ordinary people crossing borders did not carry identity documents, because there were no identity documents to carry. Letters of safe conduct existed — England has an Act from 1414, in the reign of Henry V, that mentions them — but those were letters from a powerful person asking others to let the bearer pass unharmed, not records of who the bearer was. By 1900 a person could cross a great many European frontiers with nothing in their pocket.
The First World War ended that permanently, for reasons of espionage and manpower control rather than convenience. Britain passed the British Nationality and Status of Aliens Act in 1914 and issued, from 1915, a mass-producible passport carrying a photograph and a written description of the holder, valid for two years.
Then in October 1920, at a conference in Paris held under the new League of Nations, the shape of the modern passport was agreed: a booklet with a cardboard cover, roughly 15.5 by 10.5 centimetres, of 32 pages — four for the bearer’s details and the rest for visas — printed in the national language plus French, carrying a photograph, with countries asked to adopt it by 1 July 1921.
If you take your passport out and look at it, you are looking at that resolution. The country’s name at the top of the cover, the coat of arms in the middle, the word for “passport” at the bottom; the identity pages at the front; the visa pages behind. A century of technology has been added underneath, but nobody has changed the shape of the object agreed in Paris in the week of 15 October 1920.
And with that booklet, the question at the border changed. It stopped being “do I know you” and became “can you produce a credential”. Those are not the same question. Getting the difference clear is the point of this chapter.
Where the plain version stops being true#
Recognition is not free and it is not accurate#
The plain version said recognition is free, instant and extremely accurate. The first two are close enough. The third is wrong.
Human recognition of familiar faces is very good. Human recognition of unfamiliar faces is poor, and human confidence about it runs much higher than human accuracy, which is the dangerous combination. The history of mistaken identification in criminal courts is the history of confident witnesses being wrong. The useful statement is narrower than it sounded: recognition is excellent for people you know extremely well and unreliable for everyone else, and the boundary between those groups is not visible from inside your own head.
The honest version: recognition does not degrade gracefully as you move from familiar to unfamiliar. It fails while still feeling like success. That is the worst possible failure mode for a security check, and it is one reason the rest of the book keeps reaching for objects and mathematics instead of judgement.
“About one hundred and fifty” is a much softer number than it looks#
You will often see the ceiling on recognition given as a hard figure of about 150 people, attached to the anthropologist Robin Dunbar, from his 1992 paper “Neocortex size as a constraint on group size in primates” in the Journal of Human Evolution, volume 22, pages 469 to 493.
Treat that figure with care, because experts genuinely disagree. In 2021 Patrik Lindenfors, Andreas Wartel and Johan Lind published “Dunbar’s number deconstructed” in Biology Letters, volume 17, article 20210158, re-running the extrapolation with modern statistical methods. Their point was not that the central estimate was slightly off but that the confidence interval is enormous. Depending on the method, their predicted human group sizes ran from 69 to 109 with a 95 per cent confidence interval of 3.8 to 520, or from 16 to 42 with an interval of 2.1 to 336. They concluded that specifying any precise cognitive limit on group size is unfounded.
The honest version: there is clearly some ceiling, because nobody knows a million people personally, and that is all the argument here needs. But if you have been quoting “150” as though it were a measured constant like the speed of light, stop. It is a contested extrapolation, not a measurement. The scaling break is real; its exact numerical location is not established.
A seal proves possession, and possession is not personhood#
The plain version said the man downriver did not know the merchant’s face and did not need to, because he knew the picture. True, and this is precisely where the trouble starts.
A seal impression proves that whoever made the impression had the seal in their hand at that moment. It proves nothing else. It does not prove the seal’s owner was present. It does not prove the owner consented. It does not prove the owner was alive. A stolen seal produces impressions indistinguishable from genuine ones, because they are genuine ones — the check has no way to tell an authorized rolling of the cylinder from an unauthorized one.
Ancient administrations knew this and responded exactly as a modern security team would. Seals were worn on the body rather than left in a drawer. Seals were buried with their owners. When an English monarch died, the matrix of the Great Seal was destroyed, so that no document could be sealed in a dead sovereign’s name. That is key revocation and key rotation, in silver, several centuries before anybody used those words. Chapter 30 deals with revocation as a discipline.
The honest version: a seal is a bearer token. Whoever holds it, wields it. Every bearer token in this book — a session cookie, an API key, a bank card with no PIN — inherits the cylinder seal’s exact strength and its exact weakness, and no amount of cryptography changes the fundamental bargain.
A split tally proves a pair, not a person#
The plain version said the tally is the first two-party shared secret. That is a fair description of the mechanism and a misleading description of what it proves.
The tally proves that the stock in your hand is the mate of the foil in the Exchequer’s chest. It says nothing about you. If you steal a stock from somebody’s strongbox, it fits the foil exactly as well as it did before you stole it, and the clerk pays out. The tally authenticates a debt, not a creditor. It is a bearer instrument, which is precisely why tallies were bought and sold as financial assets — the word “stock” in the sense of stocks and shares comes down to us from the longer half of a split stick.
This distinction — between proving a relationship and proving a person — is one of the most persistent confusions in the field, and chapter 3 separates the verbs properly.
The watchword is a group secret, so it cannot identify anybody#
The plain version said the watchword is fast, cheap and changeable. All true. But it does not identify a person, and it was never meant to.
A watchword divides the world into those who know it and those who do not, and inside the knowing group it draws no distinctions at all. It cannot tell you which soldier spoke, nor whether a soldier who knows it today should still know it tomorrow, and it leaves no evidence afterwards about who used it. Any secret shared by more than two parties has this property, and it weakens with every person added, since each one is another chance of a leak.
The honest version: a shared secret held by a group is an access control mechanism, not an identity mechanism. Building an identity system out of one — a departmental password, a team’s shared login, a family’s Wi-Fi key — gives you a system that can let people in but can never afterwards say who came in.
The shibboleth is not a password and does not behave like one#
The plain version got the shibboleth roughly right and skated over its mechanics. Two corrections.
First, what exactly failed for the Ephraimites is not settled. The leading scholarly account, associated with E. A. Speiser and Pierre Swiggers and set out in Gary Rendsburg’s entry on shibboleth in the Encyclopedia of Hebrew Language and Linguistics volume 3, is that Gileadite speech kept an old Semitic sound, a soft “th” as in “thin”, where Ephraimite speech had no such sound and substituted an “s”. Rendsburg notes plainly that this explanation has not won universal acceptance, and that other reconstructions have been proposed by Alice Faber, Ronald Hendel and Robert Woodhouse. The word itself means either “ear of grain” or “flowing stream”; at a river crossing, “stream” reads better, though even that derivation is questioned.
Second, and more useful to an engineer: the famous modern examples are shakier than their retelling suggests. The Parsley Massacre in the Dominican Republic, from 2 to 8 October 1937, is very well attested, with scholars converging on roughly 20,000 deaths and published ranges from around 14,000 to 75,000. The story that soldiers selected victims by making them pronounce the Spanish word perejil, meaning parsley, is much less well attested; the historian Lauren Derby’s work indicates the pronunciation test is largely mythical rather than documented in personal accounts, and most scholars now treat it as a later construction laid over a real massacre.
The honest version: a shibboleth is a low-quality biometric with a high error rate in both directions, deployed by people under time pressure who very much want a simple answer. Chapter 19 treats biometrics with the error rates they deserve.
A signature proves far less than everybody assumes#
The plain version has barely introduced the signature, for a reason. In the history above, the signature is a latecomer, and its reputation is out of all proportion to what it does.
A handwritten signature proves, at best, that a particular hand moved in a particular practised way. It does not bind the signer to the content above it — you can sign a blank page. It does not prove the signer read or understood the document, and it does not prove when it was signed. Its verification procedure is a human comparing two squiggles, usually a clerk with four seconds and no training.
The honest version: the handwritten signature’s real function is not cryptographic but ceremonial and evidential. It marks the moment a person committed, it makes them slow down, and it creates evidence a court can weigh later. It is weak as a technical check and surprisingly strong as a social and legal one, and confusing those roles causes a great deal of trouble. Chapter 32 covers digital signatures, which fix the technical weakness; chapter 33 covers what a signature means in law, which is a separate matter again.
“Can you produce a credential” did not replace “do I know you”#
The plain version ended with a clean switch from one question to the other. The switch is real but it is not clean, and pretending otherwise will mislead you about every modern system you build.
Recognition never went away. It went underground and got automated. When your bank decides that this login looks like you because it comes from the same phone, the same city, at the same hour, using the same rhythm of typing, that is the baker looking up and thinking you seem right. It is recognition, computed. Modern systems run both questions at once: a credential check that gives a yes or no, and a recognition check that gives a probability, with the second quietly overriding the first when it does not like the look of things.
The honest version: the move from recognition to credential is a move from one check to two checks, not a replacement. Every serious identity system deployed today is a hybrid, and the interesting failures happen in the seam between the two halves.
The technical version#
The scaling break, stated as arithmetic#
The transition this chapter is about can be written down. Let R be the number of distinct people one person can hold in memory well enough to recognize reliably, and let N be the number of distinct people that person may have to transact with. Recognition suffices when N is smaller than R. It fails when N is larger than R, and the failure is not partial — the fraction of your counterparties you can recognize is R divided by N, and as N grows that fraction falls towards zero.
R is a property of a human brain and is fixed on any timescale that matters. N is a property of a settlement pattern, and it exploded. There is no engineering available on the R side, so all five thousand years of engineering happened on the other side: build an external object or procedure that lets a verifier decide about a person the verifier has never met.
| Setting | Order of N | Recognition covers |
|---|---|---|
| Foraging band | tens | effectively all |
| Village | hundreds | most |
| Uruk, c. 3100 BC | tens of thousands | a small share |
| London, 1801 census | about 1 million | negligible |
| A payment network today | billions | none |
The Uruk figure is the archaeological estimate quoted earlier: roughly 40,000 inside a city of about 250 hectares at the end of the Uruk period, around 3100 BC, with 80,000 to 90,000 in the surrounding area. The 1801 figure is from the first British census. [UNVERIFIED: the exact 1801 census population of London, given variously as about 959,000 for the metropolis and about 1.1 million for the wider built-up area, depending on the boundary used.]
There is a second, subtler break underneath the first, and it is the one that actually creates the discipline. In a village, the verifier and the subject share a history. In a city they do not, so the verifier must rely on something a third party produced — a seal cut by a craftsman, a stick cut by a clerk, a booklet printed by a state. That third party creates the structure which dominates the rest of this book: an issuer, a holder and a verifier, with the verifier’s trust aimed not at the holder but at the issuer.
RECOGNITION - the village
verifier <===================> subject
one relationship,
built over years,
held in the verifier's head.
No third party. No object. Does not scale.
CREDENTIAL PRESENTATION - the city
ISSUER ----- issues -----> HOLDER
^ |
| | presents
| trusts v
+---------------------- VERIFIER
Two relationships and an object.
The verifier need not know the holder at all.
The verifier must know, and trust, the issuer.
Every remaining item in this chapter is a filling-in of that lower diagram with different materials.
The cylinder seal: how it worked and what an impression asserted#
A cylinder seal is a small stone cylinder, typically about two to three centimetres in width, pierced lengthwise so it can be strung and worn. The device is cut into the curved surface in intaglio, meaning cut into the stone rather than raised from it, and cut in mirror image, so that rolling it across soft clay leaves a raised, correctly oriented, indefinitely repeatable frieze.
They appear around 3500 to 3400 BC in the Near East, at Uruk in southern Mesopotamia and slightly later at Susa in south-west Iran, and stay in use until roughly the fifth century BC — a working life of about three thousand years, longer than any authentication technology since. Materials included haematite, obsidian, steatite, amethyst, lapis lazuli and carnelian, and later glass and faience. Southern Mesopotamia has almost no hard stone, so the raw material was imported, which made a seal expensive and therefore worth defending. The British Museum holds one of the major collections, catalogued across several volumes by Dominique Collon.
The procedure is worth writing out in the same form we will later use for cryptographic protocols, because the shape is identical.
Sealing and checking a consignment, Uruk, c. 3100 BC
1. sender : ties cord around jar mouth
2. sender : presses wet clay lump over the knot
3. sender : rolls cylinder across the clay
-> device impressed, clay left to dry
4. carrier : transports jar
5. receiver : inspects clay lump
is it intact? (tamper evidence)
does the device match (origin evidence)
the one he expects?
6. receiver : breaks clay, opens jar
What step 5 establishes:
the lump was impressed by THAT cylinder
the lump has not been re-formed since
What step 5 does NOT establish:
who was holding the cylinder
whether they were entitled to hold it
when the impression was made
The gap between what it establishes and what it does not is the entire subject of identity engineering, and it has never closed. It has only been narrowed, repeatedly, at cost.
One further point matters later. The seal impression is self-verifying to anyone who already knows the device and meaningless to anyone who does not. There is no registry to consult and no third party to ask, which makes it fast, cheap, and useless between strangers with no prior exposure to the device. Solving that — how a verifier who has never seen your credential can still check it — took until public key infrastructure, and volume III is the answer.
Three attacks on a seal, and the countermeasures actually used#
Because a seal impression proves possession, not personhood, ancient administrations faced exactly three classes of attack, and the countermeasures they adopted map one to one onto modern practice.
| Attack on the seal | Ancient countermeasure |
|---|---|
| Theft of the matrix | worn on the body, buried |
| Forgery of the device | intricate cutting, rare stone |
| Use after authority ends | matrix defaced or destroyed |
Theft was handled by physical custody. Cylinder seals were strung on a cord and worn, not stored, and frequently went into the grave with their owner, which is why so many survive.
Forgery was handled by making the device hard to reproduce: fine intaglio cutting in hard stone, executed by a specialist, is not something a counterfeiter improvises. That is exactly the logic of the guilloche patterns and optically variable inks on a modern passport, which chapter 6 covers.
Use after authority ends was handled by destruction. England’s practice is the clearest documented case: on the death of a monarch the matrix of the Great Seal was destroyed and a new one cut for the successor. The Second Great Seal of Elizabeth I was made by the miniaturist Nicholas Hilliard and completed in 1586, after about two and a half years’ work — a genuine key ceremony, with a genuine lead time. Charles III’s Great Seal of the Realm was approved for use by Order in Council on 6 May 2025 and unveiled that month. The matrix is a signing key, its destruction is revocation, and the gap between reigns is an operational problem modern certificate authorities recognize immediately.
Note the one attack they could not counter: an authorized holder sealing something they should not have sealed. No purely possession-based scheme can detect that, then or now.
The Exchequer tally: the notch code, a sum carved, and the split#
The English Exchequer tally is the cleanest surviving example of a two-party scheme, and unusually for something this old, we have its specification.
The Dialogus de Scaccario, the Dialogue Concerning the Exchequer, written in the late twelfth century, records the notch widths. They are given in body measures, because that is what a clerk always has with him.
| Notch cut | Value it records |
|---|---|
| thickness of the palm | 1,000 pounds |
| breadth of a thumb | 100 pounds |
| breadth of little finger | 20 pounds |
| a swollen barleycorn | 1 pound |
| rather narrower than that | 1 shilling |
| a score, no wood removed | 1 penny |
Two things are immediately striking to a modern eye. First, this is a positional-free additive notation: there is no zero and no place value, so a sum is recorded by repetition. Second, the denominations are 1,000, 100, 20, 1 pound, 1 shilling and 1 penny, which means there is no notch for ten pounds and none for five shillings. Any amount must be built from what exists.
Let us carve a real sum and carry it through the rest of this section. Take 1,234 pounds, 6 shillings and 8 pence — an amount chosen because six shillings and eightpence was a real and extremely common medieval unit, being one third of a pound, the classic lawyer’s fee. Decompose it against the available denominations, greedily, largest first.
Target: 1,234 pounds 6 shillings 8 pence
1,234 = 1 x 1000 + 2 x 100 + 1 x 20 + 14 x 1
remainder after 1000 -> 234
remainder after 2 x 100 -> 34
remainder after 1 x 20 -> 14
remainder after 14 x 1 -> 0
Notches to cut:
1 palm-width = 1,000 pounds
2 thumb-widths = 200 pounds
1 little-finger width = 20 pounds
14 barleycorn widths = 14 pounds
6 narrower cuts = 6 shillings
8 scores, no wood out = 8 pence
--
32 cuts in total, all made straight across
the whole width of the stick
Thirty-two cuts. Every one of them crosses the entire stick, which is the detail that makes the next step work.
Now split it. The stick is cut down its length, through all thirty-two notches, producing two pieces that each carry the full record. The longer piece, retaining the handle end, is the stock, and goes to the person who paid money in — which is why an instrument representing money owed to you is still called a stock. The shorter piece is the foil, and is retained by the Exchequer.
one stick, notched across, then split down its length
cuts go right across the stick
| | | |||||||||||||| ,,,,,, ........
+====v=====v====v==vvvvvvvvvvvvvv==vvvvvv==vvvvvvvv==+
| |
+- - - - - - - - - - - - - - - - - - - - - - - - - - + <- split
| |
+====^=====^====^==^^^^^^^^^^^^^^==^^^^^^==^^^^^^^^==+
upper piece = STOCK (longer, keeps the handle)
lower piece = FOIL (shorter, kept by the Exchequer)
Verification at redemption:
place stock and foil together
(a) do all 32 notches align?
(b) does the wood grain run unbroken
across the join along the whole length?
both yes -> pay out. either no -> reject.
Test (a) can be forged by a patient person with a knife and a copy of the notch code. Test (b) cannot, and test (b) is the actual security. Wood splits along its own irregular internal structure, and no two splits are alike. The foil is, in effect, a stored fingerprint of a unique physical event, and the stock is the only object in the world that matches it. Modern readers will recognize this as a physically unclonable function, though it would be anachronistic to say the twelfth-century Exchequer thought of it that way.
Note precisely what this scheme achieves and what it does not:
- It authenticates the instrument, by requiring two independently held halves.
- It resists forgery and unilateral alteration, because altering one half destroys the fit with the other.
- It gives no evidence about who presents the stock, since any holder of a genuine stock passes the test.
Point three made tallies transferable, and therefore tradeable, and therefore a real financial instrument. It also makes them a clean illustration of the difference between authenticating a thing and authenticating a person.
The system’s end is worth recording, because it is the source of a famous disaster. An Act of Parliament of 1782 required Exchequer records to be kept on paper rather than on tallies, but a clause delayed the change until the existing sinecure holders had died or retired. The last died in 1826, the Act came into force, and the tally system stopped after roughly seven hundred years. The accumulated tallies — two cart-loads of them — sat in store until 1834, when Richard Weobley, the Clerk of Works, ordered them burned in the furnaces under the House of Lords rather than given away as firewood. Two labourers, Joshua Cross and Patrick Furlong, did the burning. The flues overheated, the panelling caught, and on 16 October 1834 the Palace of Westminster burned down. Britain’s Parliament buildings were destroyed by the disposal of obsolete authentication tokens.
The chirograph and the indenture: the same trick on parchment#
The split-token idea was not confined to wood. Medieval European scribes used the identical mechanism on parchment, and the vocabulary survives in English law today.
A chirograph was made by writing the same agreement two or three times on a single sheet, then writing a word — commonly CYROGRAPHUM, in large letters — across the blank space between the copies, and cutting the sheet apart through that word along a wavy or toothed line. Each party took a copy. To verify, you brought the copies together: the letters had to complete each other and the irregular cut had to fit.
When the cut was jagged and tooth-like, the document was said to be indented, and the resulting deed was an indenture — which is why a contract binding an apprentice to a master was called indentures, and why the word survives in modern legal drafting long after anybody last cut a page with scissors.
| Split token | Material | What must match |
|---|---|---|
| Exchequer tally | hazel or willow | notches plus grain |
| Chirograph | parchment | letters plus cut line |
| Tessera hospitalis | bone or clay | the break surface |
The third row is older than both. In the Greek and Roman world, two households entering a bond of guest-friendship would break a token in two, each keeping a half. The Greek practice, described for Homeric times, used a knucklebone or die broken between the parties; the Roman tessera hospitalis worked the same way, and dividing the token is exactly what made the obligation hereditary. A descendant arriving generations later, personally unknown to the household, produced his half; if it fitted, he was received. The Greek word for the matching halves is symbolon, from which the English word “symbol” descends — a symbol being, originally, the half of a thing that proves itself by fitting the other half. A modern engineer recognizes this instantly: an enrolment ceremony that establishes a long-lived shared secret, after which no further recognition is needed by either side, and which survives the death of everyone who witnessed it.
The watchword drill written out as a protocol#
Polybius describes the Roman watchword system in the Histories, book 6, chapters 34 and 35. Written as a protocol, it looks like this.
Roman watchword distribution, per Polybius 6.34
Setup, each evening:
tribune writes the night's word on a
wooden tablet (the tessera)
Distribution:
tribune -> man of 10th maniple
10th maniple -> 9th maniple (before witnesses)
9th maniple -> 8th maniple (before witnesses)
...
2nd maniple -> 1st maniple (before witnesses)
1st maniple -> tribune, before dark
Audit, at dark:
tribune counts the tablets returned.
all returned -> word reached every maniple
one missing -> the tribune knows exactly
which maniple broke the
chain, and which officer
is answerable
Three design features deserve naming, because all three are still in use.
The first is non-repudiable handover. Each pass is made before witnesses, so a unit cannot later claim it never received the word.
The second is completion by return. The system does not ask each unit to report success. It requires the token itself to come back, which is a much stronger signal, because a report can be fabricated by a lazy officer whereas a returned physical tablet cannot be conjured from nothing. Modern engineers would call this an end-to-end acknowledgement rather than a hop-by-hop one.
The third is fault localization. Because tablets are issued per chain and counted back, a failure identifies its own location. Any system that merely reports “distribution failed” is strictly worse than one that reports which hop failed, and Polybius is describing the better kind in the second century BC.
The weakness is unchanged since then. The watchword is a symmetric secret shared by an entire army for one night. It authenticates group membership and nothing finer. It can be extracted by capture, sold, or overheard; once compromised it is compromised for everyone; and there is no way to tell from a successful challenge which individual answered. Every one of those sentences is true, word for word, of a shared departmental password in 2026.
The shibboleth as an inherence factor, and its error rate#
The shibboleth is categorically different from the watchword, and the difference is the same one that separates the three factors of authentication that chapter 12 sets out in full.
A watchword is something you know. It is transferable in the time it takes to say it. A shibboleth is something you are — or more precisely something you have become, over a long period, in a way that cannot be reversed on demand. Its security does not come from the challenge being secret. The challenge is spoken aloud to the person being tested. Its security comes from the answer being expensive to produce if you did not spend your childhood producing it.
Judges 12:5-6 as a challenge-response exchange
claimant -> guard : "Let me go over."
guard -> claimant: "Are you an Ephraimite?"
claimant -> guard : "No."
guard -> claimant: "Then say Shibboleth."
claimant -> guard : "Sibboleth."
guard : REJECT.
The challenge is public.
Knowing the challenge does not help you pass it.
The claimed identity is stated first, then tested,
which makes this a one-to-one verification, not
a one-to-many search.
The biblical text puts the number who fell at the fords of the Jordan at forty-two thousand of Ephraim. As with the biblical explanation itself, the scholarly reconstruction of what phonetic distinction was being tested is contested, as set out earlier.
Now the engineering assessment, which is unkind. A shibboleth has, in modern terms, a poor false rejection rate and a poor false acceptance rate at the same time. It falsely rejects anyone from the right group who was raised elsewhere, who has a speech difference, who is frightened, or who is simply unlucky in the moment. It falsely accepts anyone from the wrong group with a good ear. And because it is applied by a human under stress, with an irreversible penalty and no appeal, the errors are never discovered and therefore never corrected.
This is the general shape of the problem with reading identity off a body, and it is why chapter 19 insists on stated error rates at stated thresholds rather than claims that a biometric “works”. A test whose error rate is unmeasured is not a strong test; it is a test whose failures are invisible.
The signature: a late arrival carrying the weight of the seal#
For most of European history, documents were sealed rather than signed. Magna Carta, agreed at Runnymede in 1215, was not signed by King John: it was authenticated with his Great Seal in wax. This is the ordinary medieval position. Literacy was scarce, the seal was the institution’s device, and a personal autograph was not what made a document good.
The signature took over gradually. Literacy spread, paper became cheap, seals proved too easy to detach and reattach and too plainly a bearer token, and the state began to want a mark tied to a person rather than to an office.
The legal turning point in England is precisely datable. The Statute of Frauds of 1677, cited as 29 Charles II chapter 3, required that certain classes of agreement be evidenced in writing and signed. The wording of section IV, in the original spelling, is worth having in front of you:
Statute of Frauds 1677, 29 Cha. 2 c. 3, section IV
(original spelling)
"unlesse the Agreement upon which such Action
shall be brought or some Memorandum or Note
thereof shall be in Writeing and signed by the
partie to be charged therewith or some other
person thereunto by him lawfully authorized."
Three things in that clause repay attention.
First, “signed by the partie to be charged”. Only the person against whom the agreement is being enforced needs to have signed. The signature is not a mutual ceremony; it is an evidential requirement pointed at whoever is being held to the bargain.
Second, “or some Memorandum or Note thereof”. The signature need not be on the agreement itself; a signed note recording it will do. From the beginning, English law treated the signature as evidence of assent rather than as a physical seal on a specific artefact, which is why, three centuries later, courts had comparatively little difficulty accepting typed names, marks and electronic forms.
Third, “or some other person thereunto by him lawfully authorized”. Delegation was contemplated in 1677: an agent’s signature binds the principal. Delegated authority is not a modern problem invented by OAuth; chapter 40 covers the modern machinery.
So what does a handwritten signature prove? It proves that a hand executed a practised motor pattern, in a way a trained forensic document examiner can compare against known samples with meaningful but imperfect reliability. It does not bind to content, since the paper above it can be replaced or was never read. It does not bind to time. It does not prove capacity or comprehension. Its casual verification — a clerk glancing at the back of a card — is close to worthless.
| Property | Wax seal | Handwritten signature |
|---|---|---|
| Tied to a person | no, to an office | yes, weakly |
| Tied to the content | no | no |
| Tied to a time | no | no |
| Transferable by theft | yes, trivially | no, not directly |
| Cheap to verify well | no | no |
The signature’s genuine advantage is the fourth row: you cannot steal a person’s hand. That single improvement is why it displaced the seal for personal use, despite being weaker on almost every other axis. Identity technologies are not adopted because they are strong overall; they are adopted because they fix the failure hurting most at the time.
Why identity documents are a nineteenth and twentieth century invention#
Modern readers assume identity documents are ancient. They are not, and the reason is worth stating plainly: a document that says who you are is only useful if there is an authority that keeps a record of who you are, and for most of history no such authority existed.
Look at what a passport requires behind it. Civil registration, so births are recorded systematically. A bureaucracy with files, and a way to find one file among millions. Cheap printing, so millions of copies can be made to a common design. Photography, which only becomes practical for mass documents in the later nineteenth century. And a state that thinks in terms of population rather than of the subjects of a particular lord.
Those preconditions arrive in the nineteenth century, not before. The letters of safe conduct that preceded them were a different object: England’s Safe Conducts Act of 1414, in the reign of Henry V, cited as 2 Henry 5 statute 1 chapter 6, is the earliest English statutory reference, and such letters asked others to let the bearer pass unharmed. They did not record who the bearer was in any checkable way, and they went to a small elite.
Two nineteenth-century developments changed that. The first was systematic identification of individuals by measurement rather than by acquaintance. Alphonse Bertillon’s anthropometric system, adopted by the Paris police in 1883 and known as bertillonage or signaletics, recorded body measurements for each offender and filed them so that a repeat offender could be found; in 1884 Bertillon used it to identify 241 repeat offenders. It was later displaced by fingerprinting, which chapter 19 covers along with the matching problem that chapter 8 addresses.
The second was war. Free movement without documents was substantially the norm across much of Europe by 1900, and the First World War ended it as a security measure. Britain’s British Nationality and Status of Aliens Act 1914 sits at that boundary. From 1915 Britain issued a mass-producible passport: a printed sheet folded into a cloth-covered card, valid for two years, bearing a photograph and a written description of the holder.
That description is the thing to notice. The 1915 British passport recorded profession, place and date of birth, country of residence, height, colour of eyes, colour of hair, special peculiarities, and the holder’s signature. It is a written attempt to do in ink what the baker did by looking, and it is comically inadequate — “height 5 feet 9 inches, eyes blue, hair brown” narrows the population by very little. The photograph is doing nearly all the work, and the photograph is why the format was possible at all.
The 1920 Paris conference and what it actually fixed#
By 1920 every state had documents and no two were alike, which made frontier crossing slow and, in the League of Nations’ framing, an obstacle to economic recovery after the war. The League convened the Conference on Passports, Customs Formalities and Through Tickets in Paris, sitting from 15 to 21 October 1920.
[UNVERIFIED: the exact number of states represented at the 1920 Paris conference; published accounts give both 22 and 42.]
The resolution the conference adopted is the reason passports look the way they do. Its main provisions, as recorded in the conference resolution, were these.
| Element | 1920 resolution |
|---|---|
| Form | booklet, cardboard cover |
| Size | about 15.5 by 10.5 cm |
| Pages | 32 |
| Identity pages | first 4 |
| Visa pages | remaining 28 |
| Language | national plus French |
| Adoption target | 1 July 1921 |
The cover layout was specified too: issuing country’s name at the top, coat of arms in the centre, the word for passport at the bottom. A photograph of the bearer was required. Validity of up to two years for multi-journey use was provided for.
Be clear about the status of this. It was a recommendation agreed at an international conference, not a treaty binding on signatories and not a standard with a conformance test. States adopted it because it was in their interest to be legible to other states’ border officials, not because they were compelled to. That voluntary-but-universal pattern is how most identity standardization has worked ever since, including the web standards in volume IV.
Follow-up conferences refined it. A second passport conference met in Geneva from 12 to 18 May 1926; the Polish delegate Franciszek Sokal opened it by proposing that passports be abolished altogether, which did not happen, and the uniform booklet survived essentially unchanged. Much later, the United Nations Conference on International Travel and Tourism met in Rome from 21 August to 5 September 1963 and again took up standardization, the thread that leads directly to the modern specification.
Alongside the standard passport came its most humane derivative. On 5 July 1922, at the close of a conference convened by Fridtjof Nansen in Geneva from 3 to 5 July, an agreement created what became known as the Nansen passport: a travel document for stateless people, issued to those whose own state would not or could not vouch for them. By 1942 it was honoured by governments in 52 countries, and roughly 450,000 were issued. Nansen received the Nobel Peace Prize in 1922, and the Nansen International Office for Refugees received it in 1938 for the work.
The Nansen passport makes a point no ordinary passport can: it severs citizenship from credential. Its holders had no state asserting they belonged to it, and the document asserted something much thinner — that a recognized international authority had registered this person and taken responsibility for saying so. That is a claim about a record, not about nationality, and distinguishing those two is exactly what chapter 2 is for.
From Nansen to Doc 9303: the credential becomes machine readable#
The final step in the historical arc is the point at which the credential stops being read by a human at all.
The International Civil Aviation Organization, ICAO, is the United Nations agency for civil aviation. Its passport work has a documented chronology, set out in the foreword to Doc 9303 Part 1.
| Year | ICAO milestone |
|---|---|
| 1968 | Panel on Passport Cards formed |
| 1980 | Doc 9303 first edition |
| 1984 | TAG/MRTD established |
| 1998 | biometrics work begins |
| 2001 | work accelerated after 9/11 |
| 2006 | chip and PKI folded in |
| 2021 | eighth edition published |
In 1968 the Air Transport Committee of the ICAO Council established a Panel on Passport Cards, to develop specifications for a passport a machine could read using optical character recognition. In 1980 the Panel’s work was published as the first edition of Doc 9303, titled A Passport with Machine Readable Capability. That edition became the basis for the first machine readable passports, issued by Australia, Canada and the United States.
In 1984 ICAO set up the Technical Advisory Group on Machine Readable Travel Documents, TAG/MRTD, made up of officials from passport-issuing and border-inspection agencies, later widening its scope to machine readable visas and card-format documents. In 1998 that group’s New Technologies Working Group began work on biometric identification and data storage for electronic travel documents. After the attacks of 11 September 2001 the work was accelerated, and by 2006 the technical reports on biometrics, contactless chips, the Logical Data Structure and public key infrastructure had been folded into Doc 9303.
As of August 2026 the current edition is the eighth, published in 2021, in thirteen parts, with amendments recorded in November 2022 and March 2024. ICAO states that more than 140 States and non-state entities issue electronic passports and that over one billion are in circulation. Which edition is current is a fact about publication schedules and could change at any time.
The physical continuity with 1920 is worth a table.
| Feature | 1920 Paris | Doc 9303 TD3 |
|---|---|---|
| Size | 15.5 by 10.5 cm book | 12.5 by 8.8 cm page |
| Identity data | first 4 pages | one data page |
| Rest of book | visa pages | visa pages |
| Read by | a human official | human and machine |
The TD3 data page is specified in Doc 9303 Part 4 section 2.2 as 125.00 mm wide by 88.00 mm high. Its machine readable zone is two lines of 44 characters each, with the left edge of the first character 6.0 mm plus or minus 1.0 mm from the left edge of the document. Chapter 6 takes that zone apart field by field and works its check digits by hand; here the only point is the shape of the change. A booklet designed in 1920 so that a French-reading official could find the bearer’s name in an unfamiliar document is now designed so that a scanner can find it without a human in the loop. The purpose is identical. The reader changed.
From “do I know you” to “can you produce a credential”#
We can now state the transition this chapter has been circling, exactly.
In the recognition model, the verifier holds the evidence. The evidence is a memory, it was accumulated by the verifier personally, it is not transferable, and there is no issuer. The check is a comparison between a present perception and a stored memory, and its output is a feeling of familiarity with no stated confidence level.
In the credential model, the holder carries the evidence. It was produced by an issuer, at some past time, through an enrolment process the verifier did not witness. The check compares the credential presented against the properties a genuine credential from that issuer would have, and its output is a decision about the credential.
| Property | Recognition | Credential |
|---|---|---|
| Who holds the evidence | verifier | holder |
| Parties involved | two | three |
| Works between strangers | no | yes |
| Fails when | rarely, silently | issuer is wrong |
| Can be stolen | no | yes |
| Can be revoked | no | yes |
Read that table honestly and the trade is not one-sided. The credential model buys dealings with strangers at unlimited scale, and it buys revocation, which recognition cannot offer — there is no way to un-know a face. It pays with two new liabilities. The credential can be stolen and used by someone else, which a memory cannot. And the verifier’s decision is only as good as the issuer’s enrolment process, which the verifier cannot see and usually cannot audit.
That last liability keeps recurring. When you accept a passport you are not learning who the person is. You are learning that an issuing authority once wrote something down, that the writing-down produced this document, and that the document is unaltered. Whether the authority got it right is a separate question, settled at enrolment, which chapter 7 covers, and it is where the largest identity failures originate.
The final observation is the one to carry into chapter 2. Nothing in this history ever answered the question “who is this person”. Every mechanism in it answered a narrower question and let the answer stand in for the broader one. The seal answered “was this impressed by that cylinder”. The tally answered “do these two halves match”. The watchword answered “were you told today’s word”. The shibboleth answered “where did you learn to speak”. The signature answered “did a hand make this practised mark”. The passport answers “did an authority record this, and is this document unaltered”. Six mechanisms, six different questions, and not one of them is “who are you”.
That is not a failure of imagination on the part of five thousand years of engineers. It is the discovery that “who are you” is not a single question at all, which is exactly what the next chapter takes apart.
1.98 Common wrong ideas#
Wrong: Identity documents are an ancient institution. Right: Letters of safe conduct are old — England has a statutory reference in the Safe Conducts Act 1414 — but they asked others to let a bearer pass, did not record who the bearer was in any checkable way, and went to a small elite. Documents that identify ordinary people require civil registration, mass printing, filing systems and photography, all nineteenth-century arrivals; the passport in your drawer takes its shape from a League of Nations conference held in Paris from 15 to 21 October 1920.
Wrong: A seal or a signet ring proved who wrote a document. Right: It proved that whoever made the impression physically held the seal at that moment. It said nothing about consent, presence, or whether the holder was even alive, which is why seals were worn on the body, buried with their owners, and why the matrix of England’s Great Seal was destroyed when a monarch died.
Wrong: A split tally stick proved the identity of the person presenting it. Right: It proved that the stock in the claimant’s hand was the mate of the foil in the Exchequer’s chest. Any holder of a genuine stock passed the test, which is exactly why tallies could be bought and sold as financial instruments and why the longer half gave English the financial sense of the word “stock”.
Wrong: A handwritten signature binds a person to the content of the document above it. Right: It records that a hand executed a practised motor pattern. It does not prove the document was read, understood, unaltered, or signed at any particular time, and you can sign a blank page. Its real strength is ceremonial and evidential, not technical, which is why chapter 32 needs digital signatures to fix the technical half and chapter 33 needs law to handle the rest.
Wrong: The shibboleth in Judges 12:5-6 was an early password. Right: A password works because the challenger keeps it secret; the guards at the Jordan said the word out loud to the man being tested and it still did not help him. It tested an unfakeable physical habit, not knowledge, which makes it the ancestor of biometrics rather than of passwords — with biometrics’ worst property already present, since it actually measures where you grew up.
Wrong: The number of people you can recognize is 150, and this is a settled scientific fact. Right: The figure comes from Robin Dunbar’s extrapolation in the Journal of Human Evolution, volume 22, pages 469 to 493, in 1992, and it is contested. Lindenfors, Wartel and Lind, in Biology Letters volume 17 article 20210158 in 2021, reproduced the analysis and found 95 per cent confidence intervals as wide as 3.8 to 520. Some ceiling exists; its precise value is not established, and the argument in this chapter does not need one.
Wrong: Checking a credential tells you who someone is. Right: It tells you that an issuer once recorded something, that this document came from that recording, and that it has not been altered since. Whether the issuer got it right is decided at enrolment, which the verifier did not witness and usually cannot audit, and that is where the largest identity failures originate.
Wrong: Modern systems replaced “do I know you” with “can you produce a credential”. Right: They added the second question without deleting the first. Device fingerprints, location history, typing rhythm and behavioural scoring are recognition, computed and automated, and in most production systems they silently override a valid credential when the pattern looks wrong.
Wrong: A shared password identifies the person who used it. Right: A secret known to a group authenticates membership of that group and draws no distinction inside it. The Roman watchword had this property in the second century BC, and a departmental login has it in 2026: it can let people in, but it can never afterwards say who came in.
Wrong: The tally system was primitive because it used wood. Right: Its security lay not in the notches, which any forger could copy from the code published in the Dialogus de Scaccario, but in the unrepeatable way a particular stick splits along its own grain, which made it unclonable.
1.99 Chapter summary in 20 lines#
- Every identity system in history exists to answer one question: is this person the one I think they are, when I cannot simply recognize them.
- Recognition is free, fast, needs no equipment and cannot be stolen, but it lives inside one head and therefore has a hard ceiling.
- That ceiling was passed permanently when settlements grew past the number of people any individual could hold in memory, and cannot be engineered around.
- Uruk in southern Mesopotamia covered about 250 hectares and held perhaps 40,000 people around 3100 BC, which is far past any recognition ceiling.
- The first substitute was a portable object: the cylinder seal, two to three centimetres of carved stone, in use from about 3400 BC to the fifth century BC.
- A seal impression proves that the seal was in someone’s hand at that moment, and proves nothing about who that someone was or whether they were entitled.
- Ancient administrations answered that with physical custody, hard-to-cut devices and destruction of the matrix when authority ended, which are custody, anti-forgery and revocation under older names.
- The English Exchequer tally, in use from around 1100 to 1826, recorded a sum in notches cut right across a stick, using widths specified in the twelfth century Dialogus de Scaccario.
- Splitting that stick lengthwise produced the stock and the foil, two halves whose match, including the unrepeatable grain, was the actual security.
- A tally authenticates a debt, not a creditor, which made tallies tradeable and makes them a clean example of authenticating a thing rather than a person.
- The same split-token idea appears as the chirograph and the indenture on parchment, and earlier as the Greek symbolon and the Roman tessera hospitalis.
- The Roman watchword, described by Polybius in Histories book 6 chapter 34, combined distribution with an audit loop that localized any failure to a single unit.
- A watchword is a group secret, so it can control access but can never say afterwards which individual passed the check.
- The shibboleth in Judges 12:5-6 tested an unfakeable speech habit rather than a secret, and is the ancestor of biometrics, with the same failure of measuring the wrong thing.
- Handwritten signatures displaced seals not because they were stronger overall but because a hand cannot be stolen, and English law made them load-bearing in the Statute of Frauds 1677.
- Identity documents for ordinary people required civil registration, mass printing, filing systems and photography, so they are a nineteenth and twentieth century invention.
- The League of Nations Conference on Passports, Customs Formalities and Through Tickets, in Paris from 15 to 21 October 1920, fixed the booklet shape still in use.
- The Nansen passport, from the Geneva agreement of 5 July 1922, showed that a travel credential can assert a record without asserting a nationality.
- ICAO’s Doc 9303, first published in 1980 and in its eighth edition of 2021 as of August 2026, completed the shift by making the credential machine readable.
- Not one mechanism in this history answers “who are you”; each answers a narrower question and lets the answer stand in, which is why the next chapter separates identifier, attribute and claim.
Chapter sources: ICAO Doc 9303, Machine Readable Travel Documents, Eighth Edition 2021, Part 1 Introduction, foreword, for the 1968 Panel on Passport Cards, the 1980 first edition, the first machine readable passports issued by Australia, Canada and the United States, the 1984 establishment of TAG/MRTD, the 1998 New Technologies Working Group and the 2006 incorporation of biometrics, chip and PKI material, with Part 4 section 2.2 for the TD3 data page of 125.00 mm by 88.00 mm and section 4.2.2 for the two-line 44-character machine readable zone; the League of Nations Conference on Passports, Customs Formalities and Through Tickets, Paris, 15 to 21 October 1920, and its resolution specifying a 32-page cardboard-covered booklet of about 15.5 by 10.5 centimetres in the national language plus French, adoption sought by 1 July 1921, with the Geneva passport conference of 12 to 18 May 1926 and the United Nations Conference on International Travel and Tourism, Rome, 21 August to 5 September 1963; the Geneva agreement of 3 to 5 July 1922 creating the Nansen passport, honoured by 52 governments by 1942 with roughly 450,000 issued, and the Nobel Peace Prizes of 1922 and 1938; the British Museum collection of Mesopotamian cylinder seals, catalogued by Dominique Collon, for form, material and dating from about 3500 to 3400 BC; Judges chapter 12 verses 5 and 6, with Gary A. Rendsburg’s entry “Shibboleth” in the Encyclopedia of Hebrew Language and Linguistics volume 3, 2013, for the Speiser and Swiggers reconstruction and the objections of Faber, Hendel and Woodhouse; Polybius, Histories, book 6 chapters 34 and 35, for the watchword tessera and its return-and-count audit; the Dialogus de Scaccario, late twelfth century, for the Exchequer notch widths; the UK Parliament’s account of the tally sticks and the fire of 16 October 1834, with the 1782 Act whose operation was delayed until the death of the last sinecure holder in 1826; the Statute of Frauds 1677, 29 Charles II chapter 3, section IV, as printed on legislation.gov.uk; the Safe Conducts Act 1414, 2 Henry 5 statute 1 chapter 6; the British Nationality and Status of Aliens Act 1914 and the British passport format of 1915; the National Archives on the Great Seal, including Nicholas Hilliard’s Second Great Seal of Elizabeth I completed in 1586 and destruction of the matrix on a sovereign’s death, and the Order in Council of 6 May 2025 approving Charles III’s Great Seal; the United States National Library of Medicine’s Visible Proofs exhibition for Bertillon’s system adopted by the Paris police in 1883 and his identification of 241 repeat offenders in 1884; Robin Dunbar, “Neocortex size as a constraint on group size in primates”, Journal of Human Evolution volume 22, pages 469 to 493, 1992, set against Lindenfors, Wartel and Lind, “Dunbar’s number deconstructed”, Biology Letters volume 17, article 20210158, 2021; the World Bank ID4D and Global Findex 2025 estimate of about 800 million people without official proof of identity, revised from about 850 million in 2021; and, for the Parsley Massacre of 2 to 8 October 1937 and the scholarly doubt about the perejil test, Lauren Derby’s work as summarized in the general literature.