When I finally do add registration and access control, it'll be based on a fixed user ID, with one or more handles. This would preserve the flexibility to play with handles that some of us occasionally enjoy, while allowing the system to know who's who.
The challenge is transitioning to the new system, and retroactively matching user IDs with old handles. If the process is 90% effective, that leaves tens of thousands of posts with an ambiguous author. This matters more to the system than to people, of course, since people have an easier time recognizing misspellings and other inconsistencies. It'll probably have a catch-all ID for unmatched posters, probably #2, since of course #1 will by my ID (it's good to be sysadmin, in some very small ways).