Earlier quoted context omitted.
Everyone working on important open source code should have a real identity associated with them. The fact that "Jia Tan" was able to become a maintainer without anyone ever trying to figure out their real identity shows a huge weakness in our trust model in OSS (everyone real would have something like a Linked In page, Facebook, Twitter, Instagram, or better, their own website with stuff that could be used to ensure…
What is real identity? Anything online can be faked. A state-issued id? How that protects against nation state?
Do you have a passport? That's a real identity in most places. Soon, it may be possible to use that to link your identity to a set of public keys which you can then use to identify yourself.
There's a lot of work to be done to make this a reality, but work is surely going on right now and this is going to be possible one day.
Check this out, as a starting point: https://curity.io/resources/learn/verifiable-credentials/