Google Is Bringing Electronic IDs to Android
venturebeat.com
venturebeat.com
I think that in general embedding legally-empowered digital IDs (in the form of certificates, not pictures of physical ID cards, mind you) in mobile phones is a good idea, but it ceases to be a good idea when your phone and your OS are made by an advertising company with clear incentives to gather data about you, and a solid history of doing so.
I really think that civic engagement and petitioning law makers to protect our privacy is the main tool we have to get out of these impending messes.
Enjoy while you can.
About making the technology reliable and secure, I do trust Google more than my bank.
I understand your concerns, but I believe we should upgrade the Democratic system to give people more direct and more often opportunities to change the law rather than slow down technology progression
The predictable rate of change of laws is actually by design. It doesn't let a single government change everything.
Additionally a part of the Republican strategy is to disenfranchise via selectively reducing access to valid existing IDs while cranking up voting requirements of those IDs.
This combo basically means that both Republicans as a whole and the Blue Dogs see it as politically nonviable, which is more than a majority at the federal level.
Can't the goverment provide the IDs to those who are less well off for free-of-charge?
Republicans claim it's "Common Sense", but see here for how it's entirely fucked up https://www.youtube.com/watch?v=rHFOwlMCdto
https://www.al.com/opinion/2017/01/as_it_turns_out_bentleys_...
A link to the ISO Standard Google is waiting for approval on: https://www.iso.org/standard/69084.html
Examples of organizations working to solve identity problems, rather than compound them:
What is an important distinction, since there exist situations when even hard to follow procedures are better than a centralized option. Those are just not your daily "how do I know if I can show you my credit card" situations.
Sorry, I don't have nearly enough information to accept that.
There might have been some efforts that I'm unaware of but that I haven't heard of them suggests they didn't get far. It doesn't help that there's not yet an elegant, eloquently defined notion of what such a system should be that an advocate could point to and say "see? this will solve all your problems". We got hucksters yelling blockchain but that's a different thing.
It's understandable how it got this way, as from inside the system's paradigm it does look like an "identity was stolen". But the map is not the territory - despite businesses wishing that it were because they can only operate in terms of the map. We are not subjects of the government nor of corporations - free people must resist being cataloged and controlled by database rows that seek to override our actual existence.
Furthermore in regards to the US, it's basically a foregone conclusion that any government-mandated ID system will not include effective restrictions that keep corporations from hooking on to build invasive tracking. Let's hold them to reigning in the ongoing widespread abuse of license plates, driver's license numbers, etc before we go advocating for even more identifying requirements on individuals in this age of surveillance.
But how is it that it's not really a problem in Estonia, where we have strongly e-identity attached to a citizen. Or are you saying our banks, institutions, telecom and other companies are somehow more competent?
You also have SSNs which is a government-mandated ID system that keeps you as rows in a database. Stop the holier-than-thou please.
I have no idea how your dispute process looks in Estonia. What happens if you lose your national ID card, don't realize it for a week, and someone has used it to do a bunch of things in your name? The sensible answer is that anything unauthorized should be rolled back or otherwise not attributed to you. This need is obvious when an "ID" is a plain 10 digit number. But when the average person can't imagine an ID being cloned because it's stored on a "smartcard", then it's a lot easier to sell responsibility as being on the person that lost their card.
> You also have SSNs which is a government-mandated ID system that keeps you as rows in a database. Stop the holier-than-thou please.
I only left off SSN next to license plate and driver's license number for brevity's sake. I was directly referencing ongoing problems here, so I certainly wasn't trying to be "holier-than-thou" in some kind of nationalist cheerleading. My point is that the existing ID systems that exist are being straight up abused (license plates -> ANPR, driver's license -> Retail Equation, SSN -> LexisNexis, for some of the most blatant abuses). The USian political philosophy discourages any sensible regulations that would reign this in, and that needs to be fixed before providing even more raw data for surveillance companies to build on.
In Estonia, how would you deal with a supermarket deciding to make it so that customers wanting a sale discount card have to link their national ID?
If you were stupid enough to attach the PIN codes to the card then you're liable for anything done with it by law. Dispute process is trough the court system.
> so I certainly wasn't trying to be "holier-than-thou" in some kind of nationalist cheerleading.
Then I take back my passive aggressiveness.
> The USian political philosophy discourages any sensible regulations that would reign this in
Right now maybe, but who knows what'll happen in ten years.
> In Estonia, how would you deal with a supermarket deciding to make it so that customers wanting a sale discount card have to link their national ID?
It is already being done - national ID as loyalty program. Though it is not considered an issue because both card payments and loyalty programs already have all the same information - except the unique personal identification number which isn't considered a secret (composed of public data). There's also the national and EU privacy laws that give one the right to be forgotten.
Regardless of the stupidity, that's still a pretty poor outcome. I assume the same applies if you were shoulder surfed, or you're an early victim of a newly discovered security bug? Or if you're kidnapped and forced to perform a transaction? It's kind of ridiculous to be made to have an item that creates essentially unbounded liability for you. This is exactly what I mean about "identity theft" morphing to be considered a real thing. This is commercially expedient, but utterly unjustifiable to those caught on the other side of it.
> It is already being done - national ID as loyalty program. Though it is not considered an issue because both card payments and loyalty programs already have all the same information
So you're saying there's no technical aspect that prevents stores from obtaining your identity? That's an outright failure. I've personally moved back to strictly paying cash for groceries [0], so this would certainly not be a welcome development for me.
> There's also the national and EU privacy laws that give one the right to be forgotten.
This is kind of the crux in that you're essentially trusting national laws to police the companies' use of the identifiers, and reign in their worst abuses. This is basically a non-starter in the US - industries basically buy the laws they want, and do whatever they like behind closed doors.
And sure, maybe we'll get to a future where GDPR-style anti-surveillance rights come to the US, are found to be workable, are enforced, actually enter into our culture, and further augmented with laws making it illegal to collect national identifiers in the first place (for anything but a narrow list of purposes) - only then would it make sense to discuss strengthening identifiers. Until then, it carries heavy downsides to the individual person.
[0] For the sale prices, ask the cashier to swipe the store card, enter a random phone number, or periodically sign up for new discount nyms with junk information. Which is all only possible because stores don't clamp down too hard, because requesting eg SSN would scare people away.
All of those are possibly overturned if you can prove it wasn't really you or you were kidnapped. Things like signing away your company or emptying your bank account has the usual countermeasures. The physical aspect of your online identity does mean that you can take clear and simple precautions of it leaving your possession, someone just shoulder-surfing can't do much. It can't just be your SSN (our ID code) leaving your knowledge, it has to be someone near to you in which case no other system protects you either. So it really isn't a downgrade at least in my opinion.
> So you're saying there's no technical aspect that prevents stores from obtaining your identity? That's an outright failure. I've personally moved back to strictly paying cash for groceries [0], so this would certainly not be a welcome development for me.
If you choose to, yes, there's nothing that stops them. If you don't then they can't remotely collect that information. Unlike the CIA or NSA has, there isn't a private-company accessible facial recognition API :P
I like that they're looking for ways to make it so you still have access to ID documents even when the battery is drained to the point that the phone cannot boot, but overall I'd still want to carry a physical card as a backup. And if I'm doing that, I'm just going to use the physical card in most situations where I need it.
Kind of like how you double-tap the power button to turn on the phone camera, but you can't access the phone's photos without unlocking.
I've never seen this type of behavior from a web page before.
in Chrome. Just tried Firefox and didn't see the same.
It's a little strange, a new paradigm-shift for the reader. If I bookmark the URL further down thinking I'm bookmarking the whole scrolled view, it reloads the bookmark to a different view - only the article I was currently scrolled to.
It does work in Firefox exactly the same way.
Just stop scrolling for a while and it's will update URL.
https://blog.pshrmn.com/entry/how-single-page-applications-w...
Any Android announcement that seems useful or valuable is always several years away for most of the Android devices in use.
I read another article about “Project Mainline”, which is about getting security fixes quicker to devices directly from Google. That one also had a similar statement.
If Google spent a little less effort on tracking and advertising, and more on making the platform secure and consistent across more devices, that’d be good for everybody (since low priced phones are mostly Android, and are used by people who cannot or do not want to spend a lot of money).
This [1] is an old talk by Christopher Soghoian that still rings true today (with added privacy goofs by Google revealed in the meantime).
[1]: https://www.ted.com/talks/christopher_soghoian_your_smartpho...
I don't get the concerns about it being mandatory because you can't expect everyone to have the same set of IDs and besides it's just a convenience feature like storing our membership cards or our emergency contact information in a wallet.
There is justifiable concern over the privacy aspect as we don't know if the IDs are stored locally on the device or if it's synced to the cloud. It will be troubling if it's the latter but criticising Google about this even before the feature has been finalized and released seems perplexing to me.
Maybe(most probably) I am completely wrong in this line of thought. But would love to hear the thoughts of HN folks on this.
I'm not sure I understand the concern. Could you give an example?
Google will shrug its shoulders and blame its users for not being responsible and for 'bad actors' who were in no way enabled by the Goog's primary objective of maximizing its stock price.