They could even optionally store one or more profiles that you could use for streamlining your interactions with various private industries: financial services, health care, employment, shopping, and travel could all have separate datasets about you stored for convenience.
Then when you want to do business with a company, you grant them access to the appropriate profile. When you conclude your business, you revoke access.
The same would be great for phone and email networks. Basically instead of giving someone your contact info, you give them a voucher to contact you. They call or email to the service and include the voucher (all automated) and the service either forwards it along or ignores it based on whether the voucher is valid. And you can invalidate any voucher at any time for any reason.
For people that like things simple, they could use a single voucher for everything, but for people who want more control they could do separate vouchers for everyone, or some easier middle-ground like family, friends, professional, commercial, and misc.
Faking DNA; well for that it would depend on how the test was administered. A cheek swab would be reasonably easy to fool, a blood draw less so if administered carefully. This is all assuming no corruption or anything; DNA tests contain no cryptographically attestable proof of match.
Any who knows, with DNA based therapies you might find yourself unable to pass a DNA test for yourself in the future.
In contrast, if you have public-key encryption people are going to build systems on the assumption that your private key is only available to you despite several decades of history showing that's not a safe assumption.
In person the government will have their own redundant and convoluted process to verify you before giving you a message to sign, just like today to reissue a SSN
A leak of lots of non-secret data (eg email addresses) is an integrity problem not a security problem. A leak of passwords or other secret data is s security issue.
People treat your SSN as a password, when really, it just uniquely identifies you. Its basically an Email Address, not a password.
not even. you need other data points, like DOB, to build enough uniqueness, and there are still many stories of collisions.
Try working face-to-face in communities of recent, poor immigrants where five, six, even ten people using the same (likely purchased) SSN is not unusual. I've seen entire families using the same SSN.
Wouldn’t most people’s SSN’s be leaked already so using SSN rather than proper ID isn’t much better than nothing?
Some are finally requiring a PIN or passcode, but very few in my experience.
I'd rather see something like Bitcoin's HD wallets used for identification - your private keys are on a hardware device, but you can generate new "personal identifiers" for use with public services that, if compromised, could be burned through a central registry without requiring a replacement of the private keys.
That said, you may also want to consider that a system design may want to have the ability to re-issue private keys. It's wise to assume that hardware dongles may, in the fullness of time, prove attackable. Certainly many Bitcoin wallets have.
It would be unreasonable to charge people a fee for a basic requirement of being enabled to be verifiable by their government. Especially if the system you're imagining is to be used for things like identification to establish voter eligibility.
Your idea of using income levels is an interesting and intriguing one. Thank you for bringing it forth for discussion! However, have you considered that it may pose some complications, such as how one can document and prove income without a way to prove identity in a system where every such document is tied to identity? Might it not be easier to skip that administrative overhead entirely?
I can well imagine everyone receiving a hardware key generator for personal identification purposes. Some id cards already have something similar and it shouldn't be all too expensive.
How would any of those be feasible with coarse mapping of ID to human?
If I tell you that i am Spooky23, 123 Main St, anytown, AK, spooky23@example.com, what more uniqueness do you need?
Hoarding passport numbers, drivers licenses, ssn, etc usually doesn’t serve a legitimate purpose. When it is required to meet compliance or other requirements (say an payroll processor who needs an SSN to withhold taxes), it needs to be protected and have access controls.
Marriott does not have any need to authoritatively know who I am beyond payment arrangements. I'm not borrowing money from Marriott, so they don't need my SSN. They may need my passport when I check into an international hotel to meet compliance requirements, but they don't need to store it in a reservation system, and don't need to store it beyond the international jurisdiction where I checked in.
Name, address, and email probably isn't fine-grained enough, as multiple people can all share the same information - and name isn't enough because some people name all their kids the same, sometimes the same as the parents (yes, it is crazy insane, perhaps narcissistic - but people). Then there are those who do similar things for fraudulent reasons.
In theory (I'm sure there are ways around it) no two people should have the same passport and passport ID number. Now, not everyone has a passport, but if they do, and they are travelling internationally, Marriott likely would rather have that information, so they can track you as you use their services in multiple places around the world (and offer you various amenities, upgrades, advertising, etc of course)...
That would be my guess.
Less nefariously*, I did a bit of digging and in the UK, hotels are required to record an ID for aliens (ironically, there is no central ID system in the UK, which I assume is why it's for aliens only). If the liability is on the hotel in case of incorrect information, it makes sense they would require the most common form of internationally recognized ID (a passport).Italy has a similar system introduced in the 30's by the fascist govt at the time for keeping track of who was where when. If I were an international business,it would make sense to me to comply with the regulations everywhere rather than try selectively enforce it.
(Nefarious-ness of Marriott. Not necessarily a comment on trusting the people who came up with the law in the first place)
Hoarding numbers serves the very purpose of ensuring a unique assignment. For instance, if "the" department of transportation did not have a "global" database, then it would risk minting the same number twice. That having been said, it is true that knowledge of a "master" identity is not a requirement for making payment arrangements.
For most commerce, I need to be able to tell that you are the same “Spooky23” who was here last time.
If you need to positively and authoritatively identify me, collecting numbers is not sufficient. End of the day, these companies are either overcollecting for convenience or doing a poor job of collecting information for compliance purposes.
Or both. Overxollecting makes sense at a global level (all systems the same everywhere), but even if they only collect what they need they're clearly not treating it correctly
In response to your moved goalposts: how is storing the passport ID different from storing the address or email? Are all three not "externally defined unique IDs"?
I didn't say these things were impossible, just that they are about collecting debts, so I've tried to respond below by showing how they allow parties to collect debts.
- Personalized tracking for marketing and advertising use cases is about changing subject behaviors, so that they spend their time and energy on things that other people want them to spend it on. Grocery store "loyalty" cards are one of many examples of how we cede agency -- in this case, allowing a corporation to assign a debt in the form of coupons that predispose us to buy a particular item. Does the 49 cents off the chocolate treats make the 30g of sugar more healthy? This is textbook predatory behavior.
- Phone numbers are a thing because we rely on centralized communications where the phone number is associated with an account billed monthly for collecting a usage debt. However, with technologies like torrents and WebRTC this is changing. In the future, maybe you provide each of your friends and family with a unique signature that allows them to look you up on the net?
If I could give up my phone number, it would certainly cut down on all of the robocalls and spam I get every day. This isn't novel or weird: many people already hand out email addresses of the form name+safeway@place.com to bucket spam.
- A physical address is a weird example because it identifies a physical location, not a person. I am not my home address; I just sleep there sometimes. Sometimes, I'm sleeping somewhere else.
- Club membership? That's easy - if you're paying for membership, then they need an account id to collect the debt for your membership. If you're not paying for membership, they don't need an ID. There are lots of clubs or meetups that don't require IDs -- the evening tech meetups/bar crawls around Seattle, for example.
- Passports, Customs, and Borders exist as a mechanism for the state to collect taxes on goods crossing international borders. Not the only mechanism, just one of them. Governments are currently struggling with goods and services crossing international borders digitally bypassing these checkpoints. I'm not sure, though, why you think passports are a humane thing -- we put tags on livestock.
(not the op)
My medical history is mine; it's ultimately not yours. If you need my medical history, allow me to give you limited access to it.
Now, if your billing is opaque and you're playing shenanigans with the insurance companies about who owes what, then sure, you need my Passport, SSN, DNA, Real ID, and biometrics -- and you should probably hold my medical history hostage too -- to make sure that you can collect on the debt.
Unless they ended the program, you forgot the word "yet"