Dear World, email addresses are not identity
mailinator.blogspot.com
mailinator.blogspot.com
Why make it harder for me, as you are just pissing me off?
If I like it I'll give you my real details, but the Internet is full of spammers and crooks and by default it seems prudent to assume that all websites are run by those types until proven otherwise.
1. wanting a way to uniquely identify a user that is easy for the user to remember (email works great) 2. wanting a way to prevent users from creating duplicate accounts
Using emails works great for 1 and is a decent low bar for 2. There are no good answers for 2 so using an email address is the best I have seen.
It's easy to create a new email account. It's much harder (though not impossibly so) to create a fake identity with 150 friends.
Also meet my friend: http://www.facebook.com/profile.php?id=622877592
see: http://www.nytimes.com/2008/12/09/technology/09security.html
And yeah; I'd rather the government than facebook, thank you very much.
A. It would be an optional service, so you would only use it if you wanted to. (Unless gov't got involved somehow, but my whole point is that they shouldn't be involved.) If it were a gov't run operation it would probably be impossible to opt out of. A recent example is the Australian filter. That's not working out very well, neither would this.
B. A private company has more to lose if it were to screw up implementation and design than the gov't would. I would trust my privacy to a company before the gov't because I could weigh customer reviews and go to a competitor's service if it was better.
C. A gov't can say screw you guys, work with my standards for verification. A private company would be forced to work with others or fail.
And to go through your objections one by one.
a. Any identity validation system has to be a universally accepted standard with strong penalties for misbehaviour on the part of validators, relying parties, and authenticating individuals. If it's less than universal, it doesn't work nearly as well, a bunch of people can opt out, and the effectiveness drops drastically; and we're back where we are now with a bunch of different standards and competing providers each with their own agenda.
b. Microsoft Hailstorm? Yahoo IDs? Facebook's multiple data wankeries over the years? All the times that people have horked 100s of thousands out of other people's bank accounts by having the bank email a password reset to an email account?
If past is prologue, the cost to businesses of screwing up their identity verification is relatively low. Which is fine if all they control is some crap email and a few digital photos, but rapidly becomes unfine if it's your bank account, or your deed to your vehicle, or your house or your ticket to New Zealand; or (going 15 minutes into the future) your house keys, your medical records, your ownership of businesses, etc.
c. But as mentioned in my response to a. a body that can set standards and enforce them with real teeth is exactly what is needed. The other side of that is that any private party that had the wherewithal to pull off the introduction of a new economic system (weak identity authentication is the foundation that credit cards are built upon) is going to be or be rapidly on the way to being a heavily regulated entity.
I'm not saying I'm necessarily enthusiastic about the prospect of the government holding the root signing keys to everything; I just think it's inevitable. And the thing is we need to be talking about it now, so that over the next 6 months to two years as the economic crisis plays out and the necessity of doing something is brought to the fore; we can push the discussion towards sane alternatives.
We have a window to affect the policy discussion, but that window is closing rapidly, and there are lots of people who would like to close off certain avenues of discussion. You want peer to peer disconnected transactions? You have to convince people that those matter more than law enforcement, garnishments and debt collection. Anonymous transactions are going to be a tough sell; so are pseudonymous transactions. Hell, we're probably going to have to fight to keep J. Random Moral Prude from putting a kill switch in everybody's wallet that will limit purchases to socially acceptable ones (more of a worry in the UK and commonwealth nations).
My guess, based on the nature of the industry is that whatever solution we get will be built on a stack that's already widely deployed (x509 certificates) and that it will be tied to the post office since showing your ID documents to a public official will be part of proving who you are.
I would be curious to know more.
So maybe its not a good idea to have a central identity manager. Maybe we just need to be researching how do we prove that you are indeed YOU when you visit a site again and not worry about figuring out if you are you AND the same person on x,y,z sites.
So thats not bad proof that the person that recieves an email to that address will receive the next one, and thats where all the login info is passed around.
Mailinator however breaks all this, you can use any email address you want, including one that somebody else is using. Maybe this blog is a little biased?
like the Clear security program in airports that lets you skip the lines.