AB 1637 requires all cities and counties to transition to a .gov domain
californiacitynews.org
californiacitynews.org
Do you live in San Francisco and have a child age 7 or younger? Take a 10 minute survey to share your voice! The first 300 participants will get a $10 gift card! https://tinyurl.com/bdzxjsvu
The message didn't have any information about who it was from, or how they got my number.Also, the link was to a URL shortener, which is often used for scams. I was curious, so I clicked anyway.
The link redirected to a form on another web site:
https://survey.communityvoicecommunitychoice.com/jfe/form/SV...
That website said it was an SF government department. But the web site domain did not end in sf.gov, which made me more suspicious.
I was curious about the questions, though, so kept clicking through.
But then just before the end or the survey, it wouldn't let me continue without entering my full name and email address.
I decided to alert someone at the department which allegedly hosted the survey. When I Googled the department name, the first result had the domain sfdec.org
Now, if SFDEC actually exists, then there's a good chance that sfdec.org, being the first link, is legit.
But I had never heard of that department before, so how could I know it was legit? It would take a bunch of time to look at .gov sites and see if they refer to sfdec.org
I emailed someone listed on the sfdec.org site, and they replied saying the survey was legit. But to this day I'm not sure whether the sfdec.org site is a legit government site.
It seems like it would be easy to create a fake department and fake web site.
[1]: https://www.sf.gov/news/san-francisco-launches-new-departmen...
[2]: https://www.sf.gov/departments/child-care-health-program-cch...
[3]: https://provider.sfdec.org/ (linked as "Department of Early Childhood Provider Portal" in [2])
(This was almost a year ago and I don't recall whether I did the checking you did. The other details, the ones I shared above, are from an email I wrote at the time, which is why I'm certain of those.)
Most people won't do that sleuthing, and will instead just shrug and permanently drop their guard.
?? Go back to Instagram cat videos — ignore, disengage…
Edit: Think I got us a Class C too, although we had no way to route it.
I think this change is great, because when you are looking for official information for a city or county and all you find is a .com, there's no way to be sure it's legit. Using .gov signals it's official, but .us does not.
Login.gov could also be made available to private businesses, but requires Congressional action to do so (allowing OMB to publish a circular or a memo that would allow GSA to sell Login.gov services to business customers) [2].
[1] https://web.archive.org/web/20220218215902/https://gcn.com/c...
[2] https://beeckcenter.georgetown.edu/wp-content/uploads/2021/1...
The e-commerce site asks hey is this person (1) a resident of region X and (2) at least Y years old? The e-commerce site is responsible for knowing what ages to check for what regions. ID service is responsible for validating the facts you want to share. You get the age controlled service and no third parties get more info than they need. Better.
Privacy must always be a first class citizen as it relates to digital identity solutions, and any compromise must be as minimal as possible. Trust alone is not enough, the stakes are too high, and the history of breaches and data loss (both public and private) speak for themselves. I would argue that Login.gov, GSA, and the federal government aren't attempting to control state business, but are acting in service of it. They are a vendor, and if states and local govermnet choose to implement in a manner that allows for pluggability (in order to prevent vendor lock in to Login.gov), that would be reasonable (encouraged even). Login.gov should be chosen because it is the best solution, not the default solution because of .gov. If states and local governments wish to fallback or opt to other solution providers who meet digital identity regulations, they should be able to do so. It is above all, a partnership, not a power hierarchy.
I would also say that governance and transparency are non negotiable, and should be enumerated both contractually and in statute. What Login.gov stores, how long it stores it, how data privacy and security are addressed should be documented and attested to. And most importantly, Login.gov should not have the ability to deny service once onboarded without exceptional cause (codified in statute). It should be treated like a utility: inexpensive, reliable, trustworthy, to the point you forget it even exists. It should Just Work.
If we end up with multiple pluggable third parties, what happens when they disagree? There's inevitably going to be data sync issues, and the risk of having an "extra" ID provider lying around that contains bad data, or is simply compromised at the authentication level, is enormous.
So we really want to pick one standard. Given that, a federally backed service has the least hostile incentive structure:
* It would be subject to very strict rules about universal service. I suspect there are going to be private players, and even some more reactionary states, who might try to sabotage industries by denying them identity data. (We see this in payments already, where a lot of firms really don't want to go near porn and guns)
* It doesn't have any reason to look for auxillary revenue. Having it store more data than necessary, or sell it to third parties, becomes politically radioactive rather than good business.
did this law codify any penalties?
I propose CalPERS pension invalidation for everyone thats ever been employed in that municipality, I think this is the trick that can change departments from the inside when the old guard gets affected
It did play a pivotal role in its development, but CERN also was there at the beginning!
The US arguably just deployed it widely first.
The US Government (specifically DARPA) started funding research into packet-switched networks in 1960, and funding by the USG for the internet continued uninterrupted until it was clear that the internet no longer needed outside funding in 1992 or 1993. Internet email dates back to 1972. Multiplayer online games began on the internet in 1979 (but they were text-only). Richard Stallman started using the internet to distribute free software in 1984.
Just to defend myself from the pedants out there: it was not called the internet till 1983. Before then the name alternated between ARPAnet and DARPAnet, but the userbase remained mostly the same across the transition to the name "Internet", and email, multiplayer games and other services (FTP, telnet) continued with only minor interruptions.