> key makers like YubiKey did I.D. verification on purchase?
I think that would require that every key maker would have staff in every city in the world who were trained to inspect your identity documents, check for forgeries, and not be susceptible to bribes or coercion.
Or at the very least every city would have to contain at least one location where someone from some organisation (possibly the government) could carry out this process.
The "authority" concern would require that the verifying organisation could be blacklisted if they started giving out too many IDs to the wrong people, or refusing to give IDs to the right people. (Perhaps you've played the game "Papers, Please".)
It's the "privacy" concern that worries me more. What happens if someone tries to buy a second key? Presumably there is a limit to how many each person can buy, so if someone says they lost their previous key, the issuer needs a way of revoking it. But how do they do that without creating a valuable list somewhere of which key belongs to which real world ID?
To make matters worse, because people can move between cities and jurisdictions, this database of online IDs would need to be globally shared between all verifiers, otherwise you could just buy multiple IDs from multiple vendors. That means the database that ties your browsing history to your legal identity will be accessible to basically everyone in the world, because the access to that database will only be as secure as its weakest link.
If we're going down this route, we might as well put everyone's identity onto a blockchain and let people vouch for each other in order to establish trust/reputation. In fact, that sort of system has actually been implemented; it's called BrightID, and it "requires no personal information, letting you prove your humanness without risking your privacy".
https://www.brightid.org/