>it will be implemented by chips-on-camera, that will tie you to a picture.
You can mitigate this by having a pool of devices (eg. 1000) share keys. AFAIK TPM chips and U2F/FIDO keys do this to provide some anonymity while limiting the blast radius if a key does get leaked.