FOIA requests show Apple’s emails pitching state agencies on IDs and Wallet app
muckrock.com
muckrock.com
The information is useful, but the whole framing is very strange and conspiratorial that's not supported by the emails or the facts.
Non-profits supporting investigative journalism like MuckRock are to blame. MuckRock is not selling advertising, but don't be fooled. Investigative journalism will just create more clickbait.
Whereas Big Tech companies have nothing to do with clickbait nor advertising. They are not spreading clickbait like non-profits that submit FOIA requests. Tech companies do not make money from clickbait nor eyeballs. Tech companies have sources of non-advertising revenue and legitimate business purposes that benefit society.
In 2012, EFF filed over 200 FOIA requests through MuckRock, for information about drone usage. EFF should stop participating in these clickbait campaigns. EFF should be protecting Apple from low hanging clickbait.
We should be thanking Big Tech companies not scrutinising them. They mind their own business, they do not try to learn what their users/customers are doing. They respect user/customer privacy. OTOH, these non-profits submitting FOIA requests do not respect the privacy of Apple and governments, who deserve to be left alone, to do their work in private. This is a basic human right.
Why don't people trust Big Tech. Tech companies have done nothing wrong.
And there's this from CA:
> The agreement I've been provided goes beyond a POC and appears to create more of a long term relationship.
I'd assume there's something in there about Apple sharing their product roadmap and planning, so they can get all the ducks in a row for a unified launch rather than support coming in piecemeal.
But the author of the article either a) can't be bothered to do some basic research about the topic she's writing about, or b) is deliberately stirring up (fake) controversy to increase engagement. Either thing is pretty bad.
There are zillions of standards after all, most not implemented by Apple and of the implemented ones, many are results of corporate lobbying or interests. Being a published standard doesn't mean it's somehow in the public interest or there is pressure to implement it.
https://www.apple.com/newsroom/2021/09/apple-announces-first...
Edit for reference: https://www.iso.org/obp/ui/#iso:std:iso-iec:18013:-5:dis:ed-...
Given how politically controversial the issue of voter ID is in some places (especially the US), I'm wondering if this this ISO standard is going to get mixed up in that political controversy.
It honestly isn't that controversial of an idea: a document stating that you're already registered to vote. That's it.
This is how it works in Canada: the address that Elections Canada has on hand for you (if any) is sent a flat piece of paper –not in an envelope either– that simply indicates that you're pre-registered to vote, and includes your home address, your polling location, and your poll number (which poll worker station you go to). The poll worker verifies your information with a second piece of information with your name + address: driver's license, passport, or piece of mail from a utility company, etc.
Personally, it'd be nice if I could opt to not receive and to not have to carry a piece of paper in the mail, and it sounds like this ISO standard + implementation can achieve that. (I'm guessing – I can't actually access the document)
Not only in the United States. See this article about proposals to introduce voter ID laws in Australia – https://thenewdaily.com.au/news/politics/australian-politics... – much like the US situation, the reforms are being proposed by the centre-right federal government, while the centre-left parties are opposed to it, as are progressive-leaning activist groups (such as the Human Rights Law Centre quoted in the article)
In Australia we have compulsory voting. We have an extremely well run elections operated by a highly competent non-partisan commission. And there are exceedingly few citizens which don't have some form of ID, whether that's a driver license, a photo card (voluntary card for people who don't have a driver license) a public healthcare card, or an ID issued by the welfare system.
Personally my problem is that voting laws are handled at the Federal level down, but IDs are run by the States. I guess RealID is supposed to be sort of the solution to that issue, but the requirments for those are annoying to fulfill if you're not a utility-paying tenant.
How so? There's a ton of other choices for how to prove residency. For example, here's your choices if you live in Texas: https://www.dps.texas.gov/section/driver-license/texas-resid...
If you have a car, you're good, since the vehicle registration and insurance count as the two documents you need. If you have a job, you're good, since a W-2 and a pay stub count as the two documents you need. If you don't pay any bills, and you don't have a car or a job, then you're almost certainly living with someone else (probably your parents), so you're good since they can fill out a Residency Affidavit.
Would a "federal takeover" improve things? Have the FEC (or maybe even a new successor agency) actually run presidential and congressional elections?
Of course, I realise it is very unlikely that legislation for such a "federal takeover" would make it through Congress, and if they did, there is a high likelihood that SCOTUS (especially with their current majority) would strike it down as an unconstitutional encroachment on state's rights.
In fact, most Western countries are like New Zealand – lack of compulsory voting (unlike Australia), lack of any major controversies over the integrity of the voting system (unlike the US)
>“How did it happen? Why had I or no one ever heard of it, given I know a lot of folks in the government tech space?”
Apparently this guy doesnt know much ... but enough to waste some peoples time with useless FOIA requests.
UK shows off prototype of digital iPhone driving license using Apple’s Wallet app - May. 13th 2016 11:06 am PT [1]
Louisiana, where I live, was the first state to roll out a digital driver's license on July 3, 2018, and a few other states are working on similar initiatives. The app that you use in Louisiana is called LA Wallet. [2]
[1] https://www.macrumors.com/2016/05/13/uk-digital-driving-lice... [2] https://www.iphonejd.com/iphone_jd/2018/07/review-la-wallet....
I think this is really useful.
Apple and Microsoft have some of the most sophisticated BD/partnership teams in the world.
Many companies who partner with Apple use an internal codeword and don't let others within the company know the client, terms of the deal, or the scope of the work.
Being able to see how Apple is approaching these deals is really interesting and valuable. They are going into 50 states and dealing with the DMV. The DMV has a reputation of being disorganized and not very technical. Apple has the opposite reputation. We are getting a front-row seat into how "disruption" happens.
Even if partnership deals don't get you excited, having transparency into how private companies do business with the government is almost always a good thing.
He would need an FOIA request to each state DMV for documentation on the agencys' responses to Apple and any internal deliberation on the matter.
https://www2.illinois.gov/dnr/FOIA/Documents/FOIA_Frequently...
Why not? What's not to like about it? if it can be implemented in a reasonably foolproof way? Isn't being able to ditch the wallet a huge win?
We're talking 50 individual state governments here. We all know that federal, state, and local govt IT practices are basically troubled at best, disastrously shoddy at worst, the only way I would accept this idea is if it was a completely optional, user-chosen, option for an ID.
I would want at least ten years of first adopters getting their lives shafted and/or stolen and/or stalked and/or breached before I'd ever think of even using the optional service.
Yes, little trust.
As the experience of Estonia shows, a digital ID can be very useful and effective, but does take some work (they had a big revocation effort to manage, which they were able to do so because their country is so small).
Bigger countries such a Germany have basically punted on this issue.
I'm a big fan and disappointed that California isn't in the vanguard.
That's not really the case anymore. The new struggle is contactless. I can count on my hands how many times I've had my current debit card swiped (which is good since its stripe is looking like shit by now).
Gas stations are finally implementing chip transactions (the deadline is Oct 2021 iirc), which fortunately generally includes a contactless reader.
But alas, we'll likely see the same problems with digital ID that we have with REAL ID.
https://adeptpayments.com/blog/2021/05/12/emv-compliance-dea...
What's the problem this actually solves for the average person? Obviating a physical card?
To answer the question though, since Apple Pay now works almost everywhere, my ID is one of the only cards I still need to carry. If I had a digital ID, I don't think I'd need to carry a wallet anymore.
> To answer the question though, since Apple Pay now works almost everywhere, my ID is one of the only cards I still need to carry. If I had a digital ID, I don't think I'd need to carry a wallet anymore.
Where do you live? I currently live in California so only carry ID when driving or (more recently) when planning to enter certain buildings, like federal buildings or airports. Otherwise I don't bother and it hasn't been a problem for me.
Sometimes people do ask for ID (or an SSN) but when I politely say "I'm sorry I don't have one" they typically want to do business with me so magically don't need any info.
I'm clearly over drinking age and don't need controlled prescriptions.
I'm probably more skeptical of technology in everyday life than your average non-technical person.
> Apple Pay now works almost everywhere
I live in a city, and Apple/Google Pay definitely does not work anywhere near everywhere (even after more businesses went contactless due to COVID). I wouldn't think of leaving home without physical credit cards.
(I was at a bar this weekend. Ironically I could not pay my tab with my phone, but their photobooth took Apple & Google Pay.)
This isn't the case in some parts of the world.
In Australia, even before COVID, I could make 2-3 day interstate business trips with flight tickets, credit cards, public transport all my phone.
I rarely carry cash or even my physical credit cards, and haven't needed to for years now.
With my wallet, I run the risk of losing my ID or having it get stolen.
With an ID on my phone, I still have those risks, but now I also have the risk of dropping the phone and breaking it, as well as the battery dying. Not to mention just some random software glitch breaking things.
> Isn't being able to ditch the wallet a huge win?
For all but the most trivial of trips outside my home (where I expect to need ID), I doubt I would leave my physical ID at home, ever. And if I have to carry it as a backup, why have the digital ID at all?
This seems like a great physical ID replacement. If it were available in California I would 100% use it immediately and leave my physical ID in a filing cabinet at home forever.
Still not planning to replace it until the battery is so bad that it dies on me nearly every time I leave the house, instead of occasionally.
I had a good LOL at that too. I remember people in uni were even talking about this in a business course like 10 years ago. This is not like a groundbreaking idea to digitize an ID.
The quotes from the technologist in the article just seem kinda random. I feel like those would be the basis for an article ... once you know them, but nothing in that article answers any of them or tell me that any of them are a problem.
Working in schools, I can assure you, google classroom and all the accompanying apps are not some cabal from the schools. They're free. That's the incentive.
Also, I would ask, what is the other option? That the government builds and maintains specific programs for every function? How okay are you with taxes going up quite a bit? Because they will need to in order for the public sector to compete for talent with the private sector.
My opinion is that these sorts of things don't need to be electronic, as paper is more secure anyway. But maybe I'm a Luddite. At the very least, I am privileged enough to have a career that allows me the flexibility to interact with government agencies if I need to. If I was still working retail, I could see how online services would definitely be a plus in time saved.
also, "taxes will go up" arguments are at best naive. taxes (amounts/rates) have little correlation with supporting the essential needs of government. they're primarily employed to generate leverage, (unfair) economic gain, and power. public sector pay is uncompetitive because politicians and bureaucrats don't find competitive pay to serve those purposes.
but yes, paper is perfectly fine technology for most educational purposes, relatively secure and private intrinsically.
Charter schools as the developers or consumers of such software, as well as homeschoolers, would see better outcomes imho. Retooling public schooling apparatus is a lost cause (although there is likely some small impact to be realized if you're a technologist in a position where you can deliver disproportionate impact to your local institution).
the main point is that a key (hopefully self-evident) principle is that our liberties shouldn't be for sale at any price. if that means states/localities need to develop software (and software development as a competency), so be it. political winds can change.
but as has been pointed out, it's not even clear that we really need much new technology, when existing tech seems to be perfectly satisfactory, if unexciting. the mass distance-learning experiment we just experienced seems largely a failure. turns out learning, while central, is only one of many educational concerns, and computer-based learning is at best augmentative, not primary (unlike, say, school administration systems).
As schools attach themselves to these incredibly abusive products, I sincerely hope the publics' opinion of schools drops with exponential relation.
I'd love to see a wholesale turnover in all establishments that cozy up to the likes of Google and Microsoft.
I'm 100% in favor of people going directly to teachers, principals, counselors, on and on up until enough additional busywork is piled on top of these civil servants that their choice is a perpetual drowning in outrage or a removal of abusive technology.
It shouldn't be that hard to accomplish; possibly even just ten to fifteen people per school, applying pressure wisely, ought to make for effective burnout.
Of course the phone OS people are going to do this. Judging from a few years of Live PD, every single person getting pulled over never ever has a valid ID, but always always has a cell phone that they clutch like their life depended on it.
Anything in the article is just a detail that is being hashed out.
Baby steps...
> Apple’s mobile ID implementation supports the ISO 18013-5 mDL (mobile driver’s license) standard which Apple has played an active role in the development of, and which sets clear guidelines for the industry around protecting consumers’ privacy when presenting an ID or driver’s license through a mobile device.
https://www.apple.com/newsroom/2021/09/apple-announces-first...
It doesn't appear to be an attempt at plural (obviously that'd be wrong in any case), and possessive doesn't make any sense in either this, or the common use, context.
Based on https://www.insider.com/what-drivers-license-looks-like-in-e...:
17 states say "Driver's License". Arkansas, Georgia, Idaho, Illinois, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Minnesota, New Mexico, Pennsylvania, South Carolina, Vermont, Virginia, West Virginia.
Indiana and South Dakota actually call it an "Operator License", rather than "Driver" or "Driver's".
Did you count the other 33 as all having 'Driver license'?
Not that that's terribly conclusive -- it looks like each licence design is performed without the benefits of an experienced sub-editor.
I always assumed that the possessive form was to indicate that it was a license possessed by a driver. In fact “Driver License” makes less sense in my head, as I can’t make heads or tails of what role each word is supposed to make in that clause.
Also, Apple seems to have this backwards: The states don't operate on their product schedule. Nor should they.
Not only is there nothing to support your claim, there's no reason to believe this would be the next step if your claim was accurate. Instead, they'd just...require ID on the internet, it's not like that's not currently possible.
It may be a big leap to say that implementing a Digital ID standard means that an ID-locked internet is the end goal, but it is a necessary step to reach that goal.
A much bigger flaw in their reasoning is that it's unclear who "they" is. Apple? Why would they care beyond maybe locking their own services behind ID? Government? Because they don't seem to be even making a uniform push to get things implemented.
You should be able to prove your age to buy liquor, without disclosing any other information (including your name or birth date). That should work without the government or any other party knowing you. But we are still on the road to get there.
There are numerous other efforts for decentralized identity systems where the user 'holds' digitally signed credentials and presents them under consent. While most parties realize that reducing data release and supporting anonymity are important objectives, the different efforts (and participants) have different priorities.
Some efforts, like Smart Health Cards, do not support selective disclosure of information, instead just supporting digital medical documents as signed data. This was a scope reduction to get a system out more quickly for COVID vaccination credentials.
Mobile drivers licenses support selective disclosure, but many privacy controls are really being implemented via certification, where compatible reader devices are being limited to those who certify that they discard data after use.
There are stronger primitives like Anonymous Credentials [1] , which also make the cryptography itself unlinkable, and predicate proofs which let you present answers to questions without presenting the underlying information. However, standardizing and deploying such crypto at scale takes years.
Edit:
How the technical implementation works is irrelevant to how the "boots on the ground" will use it. "We can't accept this until the device is unlocked." will be a common refrain. Or "I need the device to verify" while they eliminate your video record of the encounter.
We just recently saw how Apple bends over for government demands.
> Only after authorizing with Face ID or Touch ID is the requested identity information released from their device, which ensures that just the required information is shared and only the person who added the driver’s license or state ID to the device can present it. Users do not need to unlock, show, or hand over their device to present their ID.
https://www.apple.com/newsroom/2021/09/apple-announces-first...
I rather suspect we'll see begin to see stories of substituting phone possession if this becomes widespread.
Related... do "I've been pulled over" recorder apps continue to run while this is active?
Unlike a state-issued ID, the understanding is solidly that the phone is the citizen's property.
There's the problem. Cops do plenty of illegal things all the time.
That's before even getting into how civil forfeiture exists as a massively profitable and federally-approved end-run around the Constitution.
Wonder what kids are going to do for fake ID when you have to tap to get into the club...
Signed, someone who definitely did but shouldn’t have been clubbing at 14.
In a perfect world, parents would teach their kids about how to party responsibly, but we don't live in a perfect world. At the very least, when kids get older they can arguably make slightly better decisions (e.g. think more clearly) sometimes.
Without the picture? My understanding is that release does require authentication, and the message could disclose whether that was done with say the fingerprint used when the license was added to the phone.
The use of cryptographic signatures means the weakest link would likely be the identity verification process of the issuing DMV (or their app).
And it's not like there isn't already a black market of stolen IDs already. Get a photo of your client, run it against a database of stolen info, get a match. I understand I'm simplifying this immensely, but if the system can be broken, then it will be exploited. And really it's not if, but when.
I can see this being a useful technology in the case of law enforcement, pharmacies, doctors offices, or anywhere you would need to check in with your driver's license.