Interviews
Eran Haggiag – Rebuilding Digital Identity Around SIM Cards for the AI Era

Ben Cejvan
·
·
3 min read

In this episode of The Future of Identity Podcast, I’m joined by Eran Haggiag, founder and CEO of Glide Identity, to explore a bold vision for the future of digital identity. While much of the industry is focused on wallets, passkeys, and government-issued credentials, Eran argues that the foundation for a global, high-assurance identity system has been sitting in our pockets for decades: the SIM card.
Our conversation examines how Glide is leveraging telco infrastructure, hardware-bound cryptographic keys, and verifiable credentials to create a universal identity layer designed for a future shaped by AI agents, quantum threats, and increasingly sophisticated fraud. We also discuss why phone numbers may be one of the most underappreciated public identifiers in the world and how they could serve as the connective tissue between authentication, verification, and reusable identity.
In this episode we explore:
Why SIM cards may be the world’s most widely distributed hardware security tokens and how they can provide a foundation for phishing-resistant authentication.
How Glide’s Magical Auth platform replaces SMS OTP with hardware-bound cryptographic verification tied to mobile networks.
The role of phone numbers as a universal identity anchor for verifiable credentials, digital wallets, and reusable identity.
How telcos, banks, governments, and identity providers can contribute credentials to a shared identity ecosystem.
Why AI agents will need their own identities and how verifiable credentials and delegated authority could power the next generation of agent-to-agent interactions.
This episode is essential listening for anyone thinking about the infrastructure layer of identity in an AI-driven world. Eran offers a fresh perspective on authentication, identity verification, and how existing telecom infrastructure could help accelerate the transition to more secure and interoperable digital identity systems.
Hope you enjoy the conversation and if it resonates, feel free to share it with others interested in where identity is headed.
Learn more about Glide Identity.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.
Listen to the full episode on Apple Podcasts or Spotify, or find all ways to listen at trinsic.id/podcast.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to the Future of Identity podcast, a show that highlights the world’s most innovative digital ID ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we built the first identity acceptance network, which helps businesses accept dozens of digital IDs through one seamless integration. Today, I’m thrilled to be joined by Eran Haggiag, founder and CEO of Glide Identity. Glide has a really compelling vision for how the next generation of identity will play out in a world of super-capable AI. He argues billions of people already have hardware-bound authentication keys that can bootstrap high-assurance reusable identity, and it’s been hidden in plain sight for 20 years. He’s talking about the SIM card that’s in the device that you’re probably using to listen to my voice right now. Glide has made impressive inroads with getting the telco partnerships that are needed to make this universal authentication mechanism happen.
Riley Hughes: And Eran does a great job speaking to how this relates with mDLs, eIDs, and how this convergence with other forms of digital IDs will usher in a new age of digital identity. I think this episode is super relevant to anybody thinking about fraud, account security, and the infrastructure layer of identity, and what that could look like over the next few years. So I hope you enjoy my episode with Eran. Let’s jump in now. Eran, welcome to the show.
Eran Haggiag: Thank you, Riley. Very happy to be here.
Riley Hughes: We’ve known each other for a little while now, and we’ve been talking about doing this for a little while, so I’m happy we finally get to do it. Most guests here are building identity ecosystems that are predicated on software-based things like a wallet app you install on your phone or something. And I’m really excited to talk to you because you’ve got a little different approach. Maybe it’s still software-based, I don’t know. You can tell me. Definitely predicated on a different root of trust, we’ll say. So I would love to just hand it over to you and ask you to introduce our listeners to Glide and explain briefly how you landed on this problem to solve.
Eran Haggiag: Yeah, absolutely. Thank you very much for that. I’m very excited to be here and happy that we managed—
Riley Hughes: To get it happening.
Eran Haggiag: So we’ve been looking at this problem of identity from first principles and saying, like, obviously we need to rebuild the identity layer for the AGI era, as we’re seeing AI becoming the best hacker in the world, or at least the best hacking tool in the world, saying everything that can be hacked will be hacked. Then we have also quantum around the corner, and we have all these agents that want to do stuff on our behalf, and they need to have an identity platform. So how do we build the most secure continuous identity platform that is built with AI safety, quantum safety, and agent readiness? That was the goal that we went to solve. And looking at the market as exists today, extremely fragmented. People have so many username and passwords. They have so many different ways to authenticate themselves, social logins, password managers. It’s like an insane amount of friction and fragmentation and fraud that is happening. So how do we solve it?
Eran Haggiag: So we went to think from first principles that you have to have some kind of a hardware root of trust to be able to build everything on top of that, and you need this hardware root of trust to be connected to some kind of a public identifier you uniquely in the world. And trying to think, what is that that exists in the world?
Riley Hughes: A lot of people agree with you and have these grand visions of everyone has a UBI and everyone has a decentralized identifier with hardware-bound keys. And if we could snap our fingers and everybody has all this stuff, that sounds great. I can see why that would be the vision, but the adoption challenge is always there too. So maybe explain what has been your approach to this?
Eran Haggiag: So apparently, humanity have already solved this problem 20 years ago. They basically distributed hardware tokens to more than 5 billion people in the form of SIM cards. This SIM card is actually a separated hardware component with its own CPU and memory that have a cryptographic key. So all these UBIs have distributed. Not only that, they are bound to a public identifier that identifies you uniquely in the world, which is your phone number. Think about it. Nobody else in the world has your phone number, and it’s also acceptable by the entire world. Even if you have now two countries that are not friends of each other, you can still call them, yeah? So this is a universally accepted way of identifying people uniquely without the need of the government-issued number, like a social security number, ID. And not only that this is it, you have a hardware token associated with it, and it’s already allow you to communicate. So you can call somebody, send them a message, or do stuff. So it already exists, this snapping of a finger for more than five billion people.
Eran Haggiag: All you need to do is just to convince a hundred telcos to implement what’s needed and contract with you.
Riley Hughes: Sounds like the easy part, right?
Eran Haggiag: Not really, yeah. Actually, it’s very hard. In my previous startup that I had called ClearX, we were building a settlement system based on a stablecoin that was backed by money market funds, and there was like a seven-year earlier to the regulation and the genius act, so we couldn’t get it scaled as it’s now scaling. But we had the telcos as our main vertical. We settled roaming traffic, fixed line traffic, voice traffic, and this is where I learned about the ecosystem, got some of the telcos to be on our cap table, have the relationship, deploying on-prem staff there, and getting the understanding and the kind of credibility to actually do this kind of thing that was very hard to do and was never executed in the last 20 years.
Riley Hughes: I see. Yeah. One of my questions was going to be, why doesn’t this already exist? Why doesn’t this, how the world already operates? And it sounds like that’s a good reason why, right? The telco market’s fragmented and it’s challenging.
Eran Haggiag: It’s more than that. So you know what’s crazy? The last decade, there were like four serious tries.
Riley Hughes: To make it happen.
Eran Haggiag: And when I say serious, it’s like tens of millions of dollars have been invested in it. The last one that was tried in the US was called ZenKey. I don’t know if you heard about it or remember.
Riley Hughes: Yeah.
Eran Haggiag: So the four telcos back then, including Sprint, tried to do together exactly that. and it didn’t happen. Because you need to get both the telcos, the operating systems, the verifier all together to work, and that’s a very hard problem to orchestrate. So we were very lucky to be able to do that.
Riley Hughes: Well, one follow-up that I wanted to ask you: you’re talking about the phone number as a public identifier, right? It’s connected to the SIM card, which is hardware with keys and everything. Talk to me about, and this is just a question of ignorance, right, like how about eSIM, right? How about voice over IP numbers, right? I can programmatically just generate myself a hundred numbers. How about spoofing, right, where I can download an app from the App Store and use it to spoof my mom’s phone number to call my dad or something, for whatever, right? Like how about these kind of areas where, at least for the layperson who’s thinking about their impression of how the world works today, how could a mobile network be a reliable identity system when these types of things are present?
Eran Haggiag: Very good question. So let’s organize this into buckets, okay? The voice over IP doesn’t have a SIM. It’s just a number. It’s kind of a landline number. It doesn’t have a SIM, so it’s unrelated. You cannot use this in our system. The spoofing of a phone number, you can spoof a phone number all you want, but you cannot spoof the private key. So whenever you get a challenge, you will not be able to prove it with your spoofed app or whatever. So all of these cases, we solved it. eSIMs are actually acting exactly like SIMs. So they are running inside their own separate execution environment, and they are getting just this private key in a very specific ceremony that is safe, and it’s kept hardware-bound and cannot be moved from this device. So it’s a non-extractable key. Compliant with the AAL3 regulations. Basically, we support it the same way that we support a SIM card.
Riley Hughes: You mentioned AAL3, which is the authentication assurance level framework published by NIST. And there’s other frameworks published around the world in different countries that articulate this thing, which is like, how strong is this authentication, right? So what you’re saying is it’s a stronger authentication to use the key in the SIM card versus using something like two-factor authentication, for example, right? Now, my follow-up to that is, okay, I’m following you this whole time talking about authentication. How about verification? How about the identity behind the phone number? Okay, I know there’s a key, right? I know that that key was used and it can’t be spoofed. But how do I know who that key belongs to? And furthermore, how do I know that the person it belongs to is the one that is actually using it in real time, right?
Eran Haggiag: Yes. So that’s a great question, and that’s our next generation product offering. So that kind of solution that I just mentioned, we call it Magical Auth. This is something that allows you to prove that this is the phone number, and this is a good replacement for SMS OTP and other stuff. But that’s just the first layer. This is creating the hardware binding with the public identifier. What’s nice is that a phone number is a good key for any other identity information in the world. What we created is this verifiable credential marketplace that allows different issuers to issue into this marketplace, and other verifiers to use this information. It’s all based on verifiable digital credentials, and all of them are using the phone number as the primary key. So that allows you to move from authentication into full verification.
Riley Hughes: So what you’re describing here reminds me of this grand vision that we’ve had for years and years in the self-sovereign identity world, where maybe in that world, the central identifier was either a decentralized identifier or like a set of DIDs all kind of consolidated into a wallet. But what you’re describing is like with the centralizing entity, the entity that centralizes all these like credentials from multiple different sources. Could be this sort of phone number or this root of trust that the user has in the form of this hardware that they’re carrying around everywhere, right? And so is this marketplace that you’re describing built out in a way that’s similar to the self-sovereign identity approach of, like, you need to go and convince all the issuers who want to issue this stuff to get on board, and they need to modify their systems and integrate your issuance software to issue to a phone number? Or is this compatible with the sort of existing eID schemes and mobile driver’s license networks and things like that already have a bunch of credentials out there?
Eran Haggiag: So it’s fully compatible. We basically support all the different formats, so from ISO mDoc to SD-JWTs and all the verifiable credentials and OpenID VCI and presentation and everything. We actually created a format, and we’re able to verify all of these things in a Rust runtime that is super fast and knows how to run inside a confidential computing environment to make sure there is hardware attestation for these verifications, and supporting all of these formats as a fundamental layer inside our infrastructure. And then we layer confidential compute options to be able to do these verifications. And then the hardware key is just like YubiKey that was distributed to everybody to allow access, but also have the public identifier to access all of that. So these kind of three things together make it possible to do.
Riley Hughes: Should I think of it as like a cloud wallet that holds the credentials, and the key to get into the cloud wallet is the authentic, the magical auth essentially that you’ve developed?
Eran Haggiag: Yeah, correct.
Riley Hughes: Got it. So if I have a mobile driver’s license in an app on my phone, I guess connect the dots for me. I have this mobile driver’s license in this app on my phone, or the new Samsung digital ID here on my Samsung. How do I connect it to my phone number somehow? How do I connect the dots here?
Eran Haggiag: Yeah. So this is why we have the ability to use Trinsic to access all the different existing schemes of verifiable credentials on the phone. And the nice thing about the digital— Digital credential APIs as they are evolving, you have access to all of these solutions together, and this is being added into your profile, basically, for being able to access this through this primary key of the phone. So we use it as another data source to enrich your identity posture. connected to your phone.
Riley Hughes: I see. And then how does the phone number, or the fact that the Magical Auth is the authenticator to the wallet, how does that relate to the relying party or the verifier? Does it matter if they know your phone number, or if they know your phone number, do they get to discover something about you that way or something? Or is the phone number primarily related to authenticating into the wallet and consenting to the data release?
Eran Haggiag: So there are basically two layers and two phases here. So in phase one, what we have currently available is you need to know the phone number, and then you use this to verify that this is the phone number, this is authentication. On the second phase with Glide ID, you have the ability to do verification. So you can use your bigger digital identity to do registration, to do account recovery, to do proof of your identity, but you don’t need to use it on an ongoing authentication basis.
Riley Hughes: I see. So maybe one of the assumptions that’s been behind some of my questions is that these are two distinct things. Like normally when I think about a wallet offering, I think about it in a different context than where maybe an SMS OTP would be used. But I think maybe what I’m hearing from you is that in all those scenarios where SMS OTP is used, the verifier could instead use Magical Auth, and then in the same flow incorporate digital credentials to strengthen the identity assurance and trust behind that. That’s pretty awesome.
Eran Haggiag: Thank you. I mean, how many SMS OTPs are sent every year?
Riley Hughes: Yeah, it’s a staggering amount.
Eran Haggiag: Yeah, it’s many, many billions.
Riley Hughes: Yeah, to think that now becomes a surface area or an addressable market for all these digital trust technologies and verifiable credentials that are out there is a pretty amazing idea. Yeah, no wonder you won the award at RSA this year for the pitch contest for the most compelling cybersecurity solution, which, by the way— For our listeners, the pitch that you gave for that is available on YouTube, and I’ve watched it. You are a very good storyteller, a very compelling pitch there.
Eran Haggiag: Thank you.
Riley Hughes: So that is really interesting. So when I think about getting there and bringing on board all the universities and governments and banks and financial institutions and insurance companies and so on and so forth, and bringing them into this new world, maybe one question is just why is SMS OTP still such a massive portion of the market, despite, number one, it being really quite expensive relative to other forms of authentication, right? And number two, it’s not really that high assurance, right? And it’s not recommended anymore, even by the NIST guidance and things like this, right? It’s known as being like the worst form of two-factor authentication, and yet it’s still so prevalent. What is your read on why that’s still so prevalent? And then how do you think These organizations that we’re talking about here will migrate to something like Magical Auth when they haven’t necessarily migrated to some of the other forms of two-factor authentication still in 2026.
Eran Haggiag: Yeah, so that’s a great question. I don’t know if it’s a cool answer I have. What I got is why people are still using Windows when you have Mac. People have a tendency to use whatever they know, and as long as it’s still legal, compliant, and working, they will keep doing this because they have other stuff that is more of a priority for them to do. That’s the general answer. The second thing I want to say is that one of our offerings on the Magical Auth family is something we call Super Paskey, which is basically a solution that is a FIDO2-certified Paskey solution that uses Magical Auth in registration, recovery, and step-up to create a fully end-to-end solution for your authentication. And we think that FIDO in general is a great place. We are very active, we are a sponsor member, and we believe that passwordless cryptography needs to replace all kind of one-time passwords as soon as possible. And we believe that this is happening now.
Eran Haggiag: We can see the momentum on Passkey, and we are fueling the momentum on Magical Auth and on Super Paskey, and we believe that by the end of next year, you will not ask the same question.
Riley Hughes: I hope so, both for your sake, but of course also just for the world’s sake. I think especially as you mentioned, AI is the world’s greatest hacker. And you also, in that RSA pitch that you gave, mentioned that AI is the world’s greatest phishing purveyor or something, right? The world’s greatest phisher, if I can say it that way. And I hadn’t thought of it that way, but certainly you can spin up a thousand agents, each of which is tasked with phishing in a recursive loop of self-improvement and pretty quick. SMS OTP becomes a difficult thing to rely on. I wonder how long until it’s explicitly disallowed. You know what I mean?
Eran Haggiag: It’s already disallowed in some countries, yeah. Like it’s disallowed in Singapore, it’s disallowed in UAE. NIST, in the revision four of the 800, with the AAL, said you have to have a phishing-resistant alternative, taking everybody away from the SMS OTP. But I think a nice visual that I had is many lobsters phishing like in one-time passwords, yeah? So we can get some lobsters, some Hermes, and get them like in an image.
Riley Hughes: I’ll generate this image. I was thinking of the same thing. That’s funny. What’s interesting, just to double-click on what you said, where SMS OTP is already disallowed in Singapore and the UAE, it should be no surprise that these are two modern economies that have very high digital ID adoption, right, with SingPass in Singapore and UAE Pass in the UAE.
Eran Haggiag: Exactly.
Riley Hughes: And it strikes me that, you know, you really need strong phishing-resistant authenticator, and you also need high assurance trusted attributes connected to that, right? So verifiable credentials in order to get there. And SingPass and UAE Pass both do that. So that’s an interesting insight. I didn’t even realize that those two countries had already disallowed that.
Eran Haggiag: Yeah, this is where we are trying to accelerate this for the remaining countries.
Riley Hughes: Yeah. So in many ways, you are building something very similar to what we’re building at Trinsic, where we are building an acceptance network that requires us to convince ID providers around the world to work with us and then contract with us and all this stuff, and then we aggregate it into a product type. productized format that allows people to accept verifiable credentials, essentially. And with Magical Auth, you are doing a similar thing with telcos and consolidating and aggregating the various countries and geographies and things like that. Curious, what percentage of the addressable market have you already tackled on the supply side? So meaning, of the relevant telcos that you would want to be partnered with and integrated, how many are already integrated?
Eran Haggiag: Yeah, I would say that we are on track to have more than one billion users enabled on our platform before the end of this year, including the vast majority of the U.S. markets and the European markets, and expanding into Southeast Asia and South America.
Riley Hughes: Yes. And in the way that I asked the question, you can tell I was thinking about it almost in terms of how I think about it at Trinsic, right? But is that the right way to think about it from your end?
Eran Haggiag: Absolutely. And I want to expand on this. So what we do now on the Glide ID is getting other type of issuers to join the network. And I think the main difference between what we are doing and why I think, like, our partnership and collaboration would grow and be very successful is because you’re basically working with parties that already decided to issue, and you are aggregating them, and we are working with parties that have not decided to issue and convincing them and giving them the tools to issue. And I think we had this conversation long ago when you started. You were also on the issuing side and decided to focus on the verification side, and we saw that you are doing a great job on that. So we said, like, we don’t need to redo what you’re doing. We will just go for whatever is missing, which is the telcos, banks, and some other type of issuers, and make sure that we have them because There are great companies like Trinsic that already aggregate the governments and existing credential schemes.
Riley Hughes: Yeah, that’s an interesting point. I mentioned the SMS OTP market is very big, but there’s also a very big market for using data from telcos as, like, an authoritative data check to verify that you are who you say you are. So, for example, in America, if you are a new user onboarding into Uber, you put in your phone number. Uber will send your phone number to its various data suppliers, partners, and get basically, like, whose phone number is this? Oh, it’s a Verizon number. What does Verizon say about this user? How long have they had the line open? Did they recently change SIM cards, et cetera, et cetera, right? And it’s using, like, the telco data, right, to verify the user. So this idea of using telcos as a root of trust even to verify identity is not new. Tell me, when you say that you’re giving them the tools to issue, one could argue, well, they don’t even issue verifiable credentials, but they do have a business line or a right to win in this sort of, like, supplying data about the user kind of universe. So compare and contrast these for me.
Riley Hughes: If I’m a telco and I say to you, well, why should I issue credentials in the way that you’re describing when I already make $700 million a year selling data about our users via API calls and things like that, right?
Eran Haggiag: Yeah. I won’t be able to get to all of the details around that. Some of them are bound in commercial relationships that has some confidentiality. But I would say that we leverage all data available, plus enable new data to be available, and make sure that the trust architecture, which is very key here, is remain end to end, where previous generation solutions were not handling this properly. And there is, when registering to an Uber, if you’re wrong, it’s okay. When you’re opening a bank account with potentially a synthetic ID, sanction issue, other stuff, the risk is very big. When you do account recovery, the risk is even… is even bigger. So we are handling the stuff that has the real sensitivity, and we are not in the business of statistical identity verification. We are only in the business of guaranteed identity verification, and this is a big differentiation. I know that in your platform, you have, like, different levels, right, of the scheme. Would you like to say what are the levels and how you get to the highest level?
Riley Hughes: Yeah, the assurance level framework that we have, you’ve got to have basically the equivalent of AAL3 authentication, right? For the verification step, you need to either have gone in person with two forms of ID with a trained human who’s checking everything out, and then you need to authenticate with hardware-bound keys such as unsinkable passkeys, which I don’t even know if those really exist at this point or something, right, or some other multiple-step process to get to that level of assurance.
Eran Haggiag: Yeah. So what we have is that we know of which of our supported users have authenticating with two government-issued IDs in a telco, and we have a hardware-bound private key, which is like a non-sinkable passkey. So we got that AAL3 stuff, and we only handle this high level of assurance stuff. So for us, if you want to get maybe this is the person, you can go to all the other providers. If you want to get a guaranteed person, this is the business we are in. And we believe that the maybe, because of the attack vector of AI, is becoming useless for anything serious.
Riley Hughes: Yeah. I know that when using data from a telco, oftentimes they have data about the user or the person who owns the line, right? But if it’s like a family account or something like this, right, I’ve heard of these edge case scenarios, for example, where it’s like, oh, this is a family account.
Eran Haggiag: They are not edge cases. They are the majority of cases. The edge cases is the primary account holder action.
Riley Hughes: Okay. Yeah, that could be, right? So, yeah, given that, imagining that your solution being a more modern, sophisticated approach that has proper issuance to the parties—well, the way you’re talking about it, clearly you account for this, but I wonder because we—
Eran Haggiag: Because we only account for primary account holders on the telco side, and we use other issuers for the ones that are not.
Riley Hughes: Ah, I see. Interesting. I’m sure the telcos have heard this objection before, right? I guess maybe they’re not legally required to do KYC on the non-account holders, but is that really the reason that they don’t have identity offering for the remainder of the…?
Eran Haggiag: Yeah.
Riley Hughes: You mentioned an identity platform for agents, and you can’t be a tech podcast in 2026 and not be talking about agents or whatever, right? So agents are unlikely to walk into a telco branch with two forms of ID and get themselves a SIM card or whatever. So how does what you’re building relate to the billions and billions of agents that are coming online in the next handful of years?
Eran Haggiag: Yeah. So we like to look at agents like in two families, right? There is like the long-term agents that are like humans. We have Hermes. She lives on a MacBook Pro. We got her here in SF, and she’s with us. She has character. She knows stuff. She is very helpful, and we like her. She’s part of the team. So we got her a SIM, and she has her own SIM, her own phone, her own identity, her own Gmail, and this is one form of an agent.
Riley Hughes: So just to double-click on that, going to that question I asked, the reason that a telco would have data about the primary account holder and be able to issue them a SIM in the first place, presumably, is because they have some KYC on them, right? So—
Eran Haggiag: Yeah, but she’s not a primary account holder, obviously.
Riley Hughes: Yeah. So this is what I said, like most lines are not primary account holders, but we do have a private key.
Eran Haggiag: But it doesn’t have a private key.
Riley Hughes: Yes, I see. Yes.
Eran Haggiag: Now I can now issue a verifiable credential signed by my strong identity and give it to her to delegate stuff. You can know that she is doing it, and you can know that she is doing something on my behalf that she has permission to do, all with cryptographic provenance. Now you have the other type of agents that are ephemeral agents. They are just launching and going and whatever. This is most agents. And for them, they will just hold that private verifiable credential that delegates something, time scope, action scope, and with relevant limits. And then we have our guardian, we call it, to basically make sure that the agents are only doing whatever they are allowed to, because agents are non-deterministic. So our guardian is deterministic, and combined with this delegated verifiable credential, we are able to guarantee that they do only what they are allowed to do. Then we don’t care about how crazy the agent is.
Riley Hughes: Yeah, interesting. So I wonder, do you envision that these long-term persistent agents will get a SIM card? Do you think that the number of SIM cards opening for these types of agents is going to increase over the next few years?
Eran Haggiag: Absolutely. We have a business plan for a telco for agents. We didn’t yet click play, but we believe that the ability to get a CLI to issue eSIMs based on a verifiable credential or verification of a human minting an agent in an agent birth ceremony is something we’ve been talking about for the last almost two years. And yeah, we believe that this is a valid thing because now this agent has a phone number, so they have a wallet, they have an identity, you can transfer them money, you can give them permissions, they can communicate with others, they have an address. So again, it’s the DID concept just implemented in a way that is already compatible with everything that is happening.
Riley Hughes: Very cool. This has been an awesome conversation, Eran. Is there anything that you wished I would have asked you, or anything we should have talked about that we haven’t touched on?
Eran Haggiag: Just how do we work together to accelerate this process.
Riley Hughes: Yeah, that’s really the name of the game, I think, right? Is the rallying cry that I’ve been trying to get out there as much as I can is that we need to accelerate, because the large AI labs are certainly not decelerating. The better the AI models get—I mean, I know you were a fan of Opus 4.6 over 4.7. I don’t know what your take is on Fable 5.
Eran Haggiag: Yeah, and the last few days with Fable has been… in not less than astonishing.
Riley Hughes: Yes.
Eran Haggiag: Yeah, I’m enjoying this and producing insane amount of artifacts out of that. So, yeah, it’s not slowing down, and we believe that we have about 18 months to fix this problem. So I’ll finish by something that we had as a concept that we didn’t publish. Maybe we should. It’s called 2 Sigma to 7, and that’s the movement that we wanted to launch to say that by the end of 2027, we want SMS OTP to be a two standard deviation phenomena. Yeah, yeah. So, yeah, maybe Identityverse is a good time to launch something like this.
Riley Hughes: Yeah, well, it’s certainly a catchy moniker to use, but also is certainly a worthwhile goal to have. Let’s see what we can do together to bring the world a little closer to the Singapores and the UAEs of the world that are very low fraud rates, very high convenience, very low friction, and bring what’s needed to address the forthcoming challenges that super capable AI in the hands of billions of people is about to unleash onto the world.
Eran Haggiag: Absolutely.
Riley Hughes: Great. All right, Eran. Well, I appreciate the conversation. This was a lot of fun. If people want to get in touch with you or they want to work with Glide or be an issuer or be a partner of some kind or whatever, how should they get in touch with you?
Eran Haggiag: Or forward deployed engineers also.
Riley Hughes: There you go.
Eran Haggiag: Them across the U.S. now. Yeah, yeah, yeah. Yeah, just ping me on Eran at Glide. Agents will get it from there.
Riley Hughes: Yeah, great. Awesome. Well, thanks a lot, Eran.
Eran Haggiag: Okay. Thank you so much, and hope to stay in touch and see you next week in Identityverse.
Riley Hughes: All right. We’ll see you next week. Cheers.
Eran Haggiag: Cheers. Bye-bye.
Riley Hughes: Bye-bye. Thanks so much for listening. If you enjoyed this content, the best way to signal to us that the content is valuable is to share it with others who will benefit from it. Meanwhile, if your organization is interested in accepting digital IDs, you can find me or Trinsic on LinkedIn or X, or on our website at trinsic.id. And if you haven’t already, visit trinsic.id/podcast to subscribe to the Future of Identity newsletter and listen to any of our prior episodes. Thanks so much for listening.

Ben Cejvan
Marketing @ Trinsic
Ben Cejvan leads marketing and content at Trinsic, where he writes about digital identity and the shift toward a global identity acceptance network. He is focused on making the case for why businesses should start accepting digital IDs today.
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
