Earlier quoted context omitted.
> This will work for a time, but what happens when the next breach occurs? The UUID shouldn't be assumed to be private information - authentication should be built around the assumption that this identifier is a public identifier - like a name, but guaranteed to be unique. > Physical authentication probably means fingerprints, face data, correct? These are already compromised. Worse yet, they cannot be changed. Even…
Careful what you wish for with the low-tech solution. One of the most effective vectors for phone number port-out scams is just showing up to a local cell phone shop and presenting a fake id. Often this is completely free for the attacker since they can just opt to have a new phone added to the account on credit too.
edit: if the value of identity were to be elevated, then the physical security at these locations would be increased to the level of banks or cash-handling facilities to increase the cost of failed attempts at impersonation (to the level similar to attempted cash heists). Infact, the local phone shops should be barred/disincentivized from doing auth badly themselves and should outsource this function, just like they do with creditworthiness.