Not as bad as the fallout is going to be. Already some people are calling for mandatory identification when contributing to open source projects. This will, of course, have a chilling effect on FOSS contributions, while it seems unlikely (to me) that this would improve security in any meaningful manner.
Who's going to be on the hook for ID verification? Ah, right...
Just a thought, making open source maintainers do more unpaid work is probably not the answer to the problem of overworked open source maintainers.