If the proposal had been for the government to issue and control the identities, it may well have passed.
If the proposal had been for the government to issue and control the identities, it may well have passed.
(said by a jealous French citizen)
As you said overwhelming majority, are there any countries that have direct democracy or come close?
EDIT: In practice, larger cities in California seem to have a comparable number of referendums as well. Unfortunately, they're all bundled into an election every 1-2 years rather than the Swiss system of elections every 3-4 months. This has its upsides, mainly in turnout which is still low in much of Switzerland, but also means many "less-notable" issues often aren't discussed in CA to the same degree that they seem to be here.
And of course, CA still has daylight savings time because this proposition required two thirds vote.
Taiwan (the Republic of China) is another jurisdiction with direct democracy elements. Direct democratic rights have been in their constitution since 1940s, but they weren't seriously implemented until 2000s. The exercise of these rights is still relatively new in Taiwan.
I suggest you google the definition.
It's definitely a bad idea, but just because something is a bad idea does not magically make it facism.
If you think stuff like this being okay in the hands of a government then you might want to reexamine that line of reasoning, given that most governments are barely any better than corporations at the end of the day...
Ironically, there's a >50% chance that the solution will entail 1) privately hosted platforms like AWS and 2) privately hosted support services and 3) privately written core modules (McKinsey business strategy, Accenture implemented etc.) and 4) at least some privately contracted IT people to manage the solution.
There's no reason to believe the gov. will make a more robust, scalable and secure solution that other entities.
A better approach might even be to mandate very specific identity protocols, and then allow citizens to chose their own identity provider among those that fit the regulatory requirements and oversight.
For example: https://en.wikipedia.org/wiki/Swiss_Post
It's owned by gov. and effectively independent. They could be an identity provider. They are already close to being able to do whatever need be done.
Having to create new government bureaucracies to do things is hard.
That would be in the US, with it's shit managment and governance culture of no expertise being required. The Wwiss are explicitly rejecting such willy-nilly privatization; did you read the article?
> There's no reason to believe the gov. will make a more robust, scalable and secure solution that other entities.
Again this is US ideology about US government. In another places they have something closer to actual democracy, a robust civil service, and an awareness that some things are too important to risk the profit motive sliding to rent-seeking.
> A better approach might even be...
I actually agree with you here. The next step after centrally planning how electronic identity should work is to realize many things don't need to require an "official one true personhood" surrogate key, and can make due with something weaker and more friendly to anonymity. The same functioning society that can figure out devolved cantons and federated cooperatives would be excellently prepared to figure that out.
It improves security through the reduction in the scope of harm and eliminating single points of failure. If someone compromises your Candy Crush login they can't drain your bank account.
> and raises the thirst for more intensive surveillance to counter the inefficiency with which the data is used. (Consider the talk after 9/11 on the FBI and CIA not sharing info, and then we get the Patriot Act.)
Your argument in favor of centralized ID is that otherwise nefarious spies will lobby in favor of something equivalent to centralized ID so they can correlate everything? That's the argument against it.
"Security through ad-hoc redundancy" is going to replace one possible-good auth systems with a gazillion shity ones that no one has the budget or interest to secure. It's a greater attack service.
> It improves security through the reduction in the scope of harm and eliminating single points of failure. If someone compromises your Candy Crush login they can't drain your bank account.
No, by all accounts FBI and CIA still hate each other and keep secrets. What we got is more surveillance (NSA dragnets), not more efficient use of the data they already have.
Or we could just not do that anymore and still not have centralized authentication.
> "Security through ad-hoc redundancy" is going to replace one possible-good auth systems with a gazillion shity ones that no one has the budget or interest to secure. It's a greater attack service.
You mean attack surface. But that's the trade off.
Because none of them are actually secure. Even when you have a full time security team, there are still vulnerabilities. Before the attacker had to find a vulnerability at the DMV, then start over at the bank, then start over at every company's file server. Now instead the attacker only has to find one in the central authentication system and they get everything at once. Even if there aren't as many vulnerabilities, if there is even one, you're screwed beyond comprehension across all systems everywhere.
On top of that, widespread use cuts the other way. Suppose the system was originally deployed using sha1. That starts looking pretty weak so you begin the decade-long process of transitioning literally everyone to a system using something else. Then suddenly sha1 gets completely broken beyond all hope, but you can't stop using it because 15% of people haven't migrated away yet and that's too much of the world to abruptly cut off.
Whereas in the decentralized system only 15% of things would be vulnerable because the other 85% had already migrated and disabled sha1, and the important stuff like banks who have their own security teams would be in the 85%.
More to the point, there are other ways to reduce vulnerabilities without centralization. Use simpler, more stable software from vendors who spend more time on security and less time on feature bloat. Restrict local services to local users so they're not exposed to the internet. Use defense in depth so that a single vulnerability is not enough but the expense of finding five stackable vulnerabilities is uneconomically large relative to the value of compromising an individual system.
Whereas the only way to avoid the ominously large scope of compromise of centralized authentication is to decentralize it.
https://en.wikipedia.org/wiki/Identity_Documents_Act_2010
I've been formulating my thinking around it and I'm starting to think that this is some sort of new-age "luddism" at play, coupled with some odd distrust of government for this particular problem, as if government is trustable elsewhere.
Verification is done by third-parties in conjunction with government data. At the moment it’s only used for government services, but there has been talk for half a decade about expanding it to the private sector.
Indeed as you say, a subgroup of the largest Swedish private banks own the ID system in Sweden - for profit, and without any serious democratic oversight.
Edit: I forgot to add that the system allows these private banks to see into almost every aspect of a person’s life: where they shop, where they are, who shares their household and so on. Almost every aspect of a Swede’s life can and is tracked by this system.
Every time someone identifies themselves with this system, it costs the retail merchant or service a non-trivial amount of money. Because it’s effectively a private monopoly, that price is set by the banks, and often involves a lot of secret horse-trading behind closed doors (I’ve been involved with some aspects of this in the past).
The secret negotiations also include terms that are not open to public scrutiny. One example, is that the merchant or service isn’t allowed to blame BankID for any problems such as downtime or any other technical problems.
btw I’m curious how you get all your receipts digitally. There are some services such as Kivra in Sweden, but they definitely don’t cover all stores.
BankID doesn't store any information, and I have no problem that the stores I'm a member in store my shipping history.
I think you are overstating the scale of the surveillance. I don't think the different entities share data with each other.
Edit: try live in a country like Switzerland once you have gotten use to all interaction being online. It's horrible.
Edit2: actually other stores provide digital receipts without Kivra. You just have to be a member.
Edit3: This has nothing to do with patriotism, there are many things that I don't like about Sweden. But the fact that we have taken digitalisation seriously since the 90s is something I think is great.
I work with systems that use BankID identification, and know for a fact that you are wrong, because many (though not all) of the data-points collected by the banks can be retrieved for payment.
For instance, if you just logged-in with the service I work with, I can retrieve your full-name, birthdate, your marital status, name of your spouse, their birthdate, any children and their IDs and names, where you live, your home and cellphone number, and many many other data points.
From a service owned by a small group of private banks.
Remember that personal ID numbers are not a big secret in Sweden as well, and still we don't see any big problem with that.
Those things have nothing to do with BankID and everything to do with the government person-number database. They were available as open data before BankID existed
i think the state of things is just already quite efficient without such an id. thus people are not willing to give that data away to a private monopoly. imo for good reason.
Once these systems are in place they will be under the control of the great unelected, the civil servants, it will not be the subject of any political party policy again and so how exactly will you assert the voting based democratic control upon it?
'Cost' is going to be a part of the equation, there is no avoiding that, but access can be regulated, as can oversight (i.e. transparency) with respect to transactions.
And: "merchant or service isn’t allowed to blame BankID for any problems such as downtime or any other technical problems"
Will Swiss private individuals or businesses be able to 'sue' the Swiss government for downtime? Like late trains? Invariably not. They'll just get the service they get and that's it.
Sweden provides a pragmatic demonstrable example of what can work, it shouldn't be dismissed.
My gripe with BankID is that it's a monopoly and it's tied to having a bank account. It's easy to fall into the cracks. For example, I know first hand more than one foreigner that moved to Sweden and couldn't do basically anything online because they didn't have BankID and couldn't get one because they needed to visit a bank branch and have an appointment, and they couldn't get one without having to wait for 2 months or more (partly due to COVID-19).
The system could be much better if there were many accredited providers of digital ID (this is somewhat already the case, there's Freja now) and there was a mandated standard protocol that the accredited providers implement, so you could have the ID from any provider and that ID would work on any site. The latter is not the case to the best of my knowledge: although many government websites are supporting Freja, most private ones like Kivra or Klarna and of course the banks only support BankID. This is not great.
It also forces you to have an Android or iPhone, and basically have a relationship with these foreign tech giants and accept their policies in order to be a "digital citizen" in your own country. If they ban your account for any reason, and you lose access to the store without any recourse, and you can't install the app, you are basically SOL. This is a trickier problem to solve, and it's not exclusive to BankID by any means, but if there was competition it would be more likely (at least on paper) that somebody might provide an alternative.
My take is that indeed: the system mostly works, it is convenient, but it's not perfect by any means. There's plenty of room for improvement. Just having real competition instead of a de facto monopoly would fix most issues.
For me this is mind-boggling. Could you please elaborate or link to a resource on that? Do the respective apps work on rooted phones? Regarding the Bank ID: I worked as an intern in Sweden in the 2002 and this sucked already then. As a foreigner you got an ID that somehow "almost" matched the normal way the number was generated (an offset on the YOB if I remember correctly). It was always an interesting experience to find out if an office/application supported such foreigner ID or not. Hopefully this got fixed in the meantime. After all my yearly letter from pensionsmyndigheten is at least partially translated in multiple languages. Good for me as I lost almost all my Swedish.
> Could you please elaborate or link to a resource on that?
Not sure what exactly you're looking for. There are 3 types of BankID: "on file", "on card" and "mobile". The first two are seldomly used and not all banks offer it (mine doesn't). I believe that most sites only support the mobile version. The mobile app cannot be sideloaded on iOS, and requires Google Play Services on Android. (For now it works on rooted phones. For now.)
Although technically minded people can still find a way to sideload the Android app without having to have a Google account, this is far from being mainstream. For most people you have to agree with Apple or Google's terms and have an account with them. If you're banned and lose access to the store, you can't install BankID any longer. It's not fun to live in Sweden and not have access to BankID.
I don't like the idea that you have to establish an asymmetrical relationship with a foreign conglomerate to be able to identify yourself in your own country and use digital services.
I think that having competition at least opens up the possibility that one of the players will introduce a mechanism that does not rely (solely) on Apple/Google technology. For example, a simple hardware token could work.
Regarding IDs for foreigners, I believe that the EU cracked down on Sweden and at least the government websites allow other European digital IDs nowadays. At least the option shows up in the list of authentication choices, but since I can't use that flow I cannot state how well it works in practice.
>I don't like the idea that you have to establish an asymmetrical relationship with a foreign conglomerate to be able to identify yourself in your own country and use digital services.
The general acceptance of this in Swedish society boggles my mind. But hey, I am not a Swedish citizen, so it's not my job to tell people what to do.
I love my country but the continuing parceling out of everything to private companies has been greatly negative to many public services. See, as an example, the DOT syndicate, which has made it prohibitively expensive to commute via public transit (why in God's name is it cheaper to travel to Germany than take a train from Copenhagen to Odense?) or the bridge to Sweden we're still paying truly insane toll fees for despite having paid for its construction years ago.
In Sweden, you are absolutely reliant on private banks. This gives those select few banks a position of power which they can - and do - abuse.
It's convenient, but it's an absolute travesty that we've left such an essential part of digital infrastructure to big banks.
So do I. In Switzerland.
Yeah, it really works fine. Fortunately, it wasn't too difficult to find another bank that didn't want to blackmail me, but the system has such obvious flaws that it shouldn't exist.
To make matters worse, the current chairman of Swedbank is Göran Persson, a previous prime minister. I fear that there is some ugly corruption involved here.
Try to have anything to do with the government without a bank account. The processes and system are today so integrated that many aspect of being a citizen are today impossible beyond giving the power of attorney to someone who do have a bank account and then let them do it. (Not hypothetical as this was the recommendation given by försäkringskassan).
I would be much more happy with the system if the government operated a customer facing bank as a fallback, one which laws dictate so that all citizen critical functions are guarantied without a customer contract between a profit seeking company and a customer. It does not need to deal with loans, or give people interests, or handle stocks or any other aspects usually associated with banks. It just need to do basic banking for which everything else depend on in a cashless and internet based society.
Until then, what we have is the merge of private banks, beholden to non-elected owners, and government. It is very hassle free as long one don't mind the soft version corporatocracy.
The US has an incoherent assemblage of spare parts for an ID system and it's been years since I've seen the inside of a physical bank.
You have bank credentials and use them with with the bank. You have post office credentials and use them with the post office. This is far better from a security and privacy standpoint that any kind of centralized ID. If someone steals your post office credentials they can't drain your brokerage account, ransomware your employer's cloud services in your name and take out a home equity loan against your house and convert it into Bitcoin.
Centralized identity is a bug, not a feature.
The payment processor, in turn, just needs to know that you're authorized to draw on that account, which they know because you have the credentials established when it was opened.
Functionally none of this actually uses your name for anything useful. Even giving it to them at all is, at best, a password reset method, and there are a million other ways to do that which don't require a centralized ID.
The companies (mostly banks and insurances) lobbying for the e-ID have already implemented a similar project called "Swiss-ID" which was supposed to be used across a majority of service providers. From the point of view of the user, it looked and behaved a lot like OAuth.
What I am afraid of is that the e-ID will be implemented in a similar way, and data will be stored centrally. That's a big difference to the classic physical ID we have, because while the government controlled some data centrally (name, year of birth etc), no information about banking or illnesses was ever stored in a central place.
If there was an indication about how the e-ID was going to be implemented, and if there was a reasonable effort to make sure data is being kept isolated (e.g. by issuing a physical tokens and encrypting the data with them) I might have voted yes. But there was no such information, and I expected the worst.