Sites will use such a service to invade your privacy even further, and the government has a record of every site you've logged into and when.
Sites will use such a service to invade your privacy even further, and the government has a record of every site you've logged into and when.
That's not how OAuth works. https://en.wikipedia.org/wiki/OAuth
> the government has a record of every site you've logged into
Only the ones where you chose to use their service. Or are we imaginging a future where this service has been made mandatory, and logins and passwords have been abolished?
Honestly, the amount of FUD in this thread is absurd. The government already has an enormous amount of information about your online activity! If they want more, their strategy will probably not be writing open source software and hoping you opt in to it!
> Only the ones where you chose to use their service.
There are hundreds of websites that require you to use Facebook to log in. With government-sanctioned ID, it will be worse.
> Or are we imaginging a future where this service has been made mandatory, and logins and passwords have been abolished?
This already exists in several countries, including Korea. https://en.m.wikipedia.org/wiki/Resident_registration_number
Hopefully this serves as an indicator that your skepticism on this topic is wildly miscalibrated. There's no "imagination" involved, this is how it is right now in places where this exists.
> their strategy will probably not be writing open source software and hoping you opt in to it!
That is the exact strategy I would use if my goal was to help the government gain more control over the internet. Letting people give their freedom away in exchange for a bit of convenience is one of the oldest tricks in the book.
The reason I'm not worried about the government finding out which websites I visit is because they already know, from traffic inspection at the ISP level. Don't think I'm the one miscalibrated here.
Beyond that, the problem with this "but they might do something bad!" argument is not that it's false, it's that it's always true in every case. Literally every government policy could be the precursor to something terrible. Sure, they could introduce an optional OAuth to try to stop identity theft and then later use it to censor the internet, but they could also just censor the internet straightaway.
Yes, this is true. If all websites start requiring their visitors to do something their visitors overwhelmingly don't want, the result would be something their visitors don't want. Kind of suggests that they won't do that, yes?
We will probably have to agree to disagree here; you're imagining a world where oauth.fed.gov slowly becomes more and more widespread until it's ubiquitous and we have no other options, and that just doesn't sound realistic to me. (I think it would struggle for adoption even if it were implemented perfectly and had the best privacy controls possible, due to exactly the fears you're enumerating in this discussion) But we are talking about something hypothetical, so either of us could be right.
At any rate thanks for arguing forcefully but staying respectful and on topic!
Again, please look at what's happening in South Korea. I think you're vastly underestimating how likely businesses are to adopt such a thing and how likely the government is to gradually incentivize (and eventually force) businesses into using it.