best solution would be a distributed public key designed for web site auth, but good enough are anon id's based on browser vars, ip's, etc.