There is no technical reason it couldn’t be decentralized. It’s a file handed to you by a trusted issuer, like (not American, so guessing:) the dmv. From that point on it should all be local processing to generate the child certs. It doesn’t need to phone home until the credentials expire.
Again, the implementation is the problem
lost_faith@lemmy.ca 9 hours ago
The store won’t keep a copy of your ID on a database to be inevitably hacked