My first guess would be third-party attestation of identity, with stored credential disposal on a short schedule? Essentially normal-user-verification-as-a-service?
Pick two.
Different companies do different trade-offs. The optimal solution depends on how the internet community weighs each individual axis