The paper passport's days are numbered
wired.com
wired.com
I feel strongly that any future digital travel credentials that are offered by governments should be able to operate entirely offline, and provide records that can be retained by the data subject. That means that revocation is harder, but IMO that’s a tradeoff that is worth making to avoid another Windrush scandal.
This has already become a pain when dealing with countries that don’t stamp passports, because when you need to apply for something that asks for your travel history over the past 10 years, you might not have any records anymore.
I suppose the real trouble comes from needing to install software from the Google Play store in order to travel. If you feel you need to do that you can create a new Google account just for that installation of the Google Play from the phone itself and then never give it any of your personal information such as a payment method. GrapheneOS claims to do a pretty good job of sandboxing Google Play components.
Regardless I agree with others here who think it should always be possible to travel without any electronics on your person.
And like Linux on the desktop: it offers a better experience for everyone who either has the knowledge to step off the beaten path, or has someone who supports them. But that is just a few percent of people. The rest gets what market forces dictate.
https://github.com/chriswoope/resign-android-image?tab=readm...
I just wish there were a supported and easier way of achieving this. Would love any suggestions.
The 2 sentences making up that article don't really live up to that level of useful detail.
However, you already have to buy a passport (often for a lot of money) in most countries, so pragmatically, I don’t know that it’s a hugely different thing to ask. However, there’s a big difference for children, the elderly, and people with disabilities.
Immigration tends to stretch human rights though. It costs >10k gbp in visa fees for a British citizen to return to the UK with a non-UK spouse from arrival to settlement. You also need to be earning a fair bit of money, and not have the British partner as a stay at home spouse. I would say that frustrates article 8 ECHR, but the government disagrees.
There are countless examples of similar issues re international travel and immigration. Smartphone ownership is simply one of many.
A smartphone will not satisfy any of these properties.
Ownership of a device simply is not a guarantee you can rest on - even before you get to those who may not be able to use them.
Governments need to make sure that people can access the services that they’re entitled to through a wide variety of channels, including physically visiting an office if necessary.
Though I will say, at a practical level, you will find that it’s increasingly difficult for people with criminal records to travel internationally (due to entry requirements).
From the government, paying what is more an administration fee than the actual cost of the good, yes.
This is about principles, not economics.
One reason I dislike such digital ID schemes because I can't actually tell what information (or metadata) is being forked over. Even if it does purport to show me, I'm just supposed to trust what it says?
No thank you. A piece of paper provides a common format that's easy for both me and the official inspecting it to understand.
Honestly I don't see any other way. Else it becomes a paradise for forgery.
Like the information on my visa application, or the fingerprints collected at that time, or my travel history, hotel stays, and so on.
Data does not have your be "in the passport" to follow me around.
Note: USA "paper" passports have included an RFID chip since 2007.
Those who control the public opinion know that there's some opposition who confuses the problems with the conflict. They laugh since no one who thinks legislation like in the link would be generally bad can do anything. The ignorant will vote what the Orwellianishly-named "smartphone" will command them.
In the next five years, it's likely the option to stab the kings will be for the first time removed, since robotic militias will mean no insurance CEO can simply be shot. This means there will be zero limits to what cruelty they'll do you, since no matter how torturous it gets you'll be unable to even violently resist this. You'll have no democratic mouth, but you must scream. Completes cyberpunkization well.
---
Aside: US drones + US satellites that enable global connectivity of drones was a rather obvious consequence of Starlink ~4 years ago. If they really want some person, they now can search most of Earth in few hours with the drones + computer vision, and soon with land robots, all connected through Starlink (starshield to use the euphemism). The irony is how this at the same time solves the connectivity problem.
> US drones + US satellites that enable global connectivity of drones was a rather obvious consequence of Starlink ~4 years ago.
One would probaby be safe from the US in Serbia, Transnistria and other non-US friendly places for a while, given enough bribe money. The US won't sneak drones into sovereign airspace without another state's approval even if they're looking for high level targets such as Osama bin Laden, Al Baghdadi, Qassem Soleimani. We are not talking about failed states or states in civil war like Syria, Libya or atates under US assistance like Iraq here.
The only place where you'd stand a serious chance is Russia, if there's political backing. (see Snowden, Marsalek et al.)
In Europe traditional news sources there got economically slaughtered & replaced by few big online 1995-2005. This qas a consequence 1970s & 1980s academic networks working closely with US on web, and US then doing what it did with Google.
If you can influence what ends up in the social media feed of those deciding about university curriculums and/or most politicians, that's quite powerful also.
In Russia & China, there seems to be less hidden, less culture of valuing "free media."
---
That public opinion "matters" but gets shaped is very plausible if you consider that most of history it didn't matter unless the public got very angry.
Century of Self describes the process before Zuboff.
One might argue that control of public opinion was originally more psychoanalytic idea, and then became more Skinnerian with computers.
Then, the digital passport's ship has already sailed for better or for worse, and all these questions are solved in other ways.
> when the Home Office messes up and accidentally deletes your immigration status
You're toast either way, because it will be checked at the airport. You'll have to deal with the immigration officer and have them do something, because you won't go very far with just a paper that will be checked against the backend. In my experience it has already been the case for a while now.
You still better have the reference paper that will help identify your visa procedure, dates etc. But it's already just a key to the info in the DB.
> you will no longer be in possession of any records
Print out the papers and keep track of the important pieces. It's the same for everything else in your life, including tax documents, birth certificates etc.
Even in the olden days, the papers you had only had value against the agency's record that could prove their validity. If you had to prove residency in some specific period, having a stamp on your passport would mean very little if the agency denied having any records of it. So it's exactly the same weight as if you printed out a certificate while the DB blew out and no data about it are left.
PS: I think in previous time people were also so much more lenient. It wasn't much a question of physical papers or not, and more on how much few people cared if your info was valid or not. I had an error in my name in many official documents, and while people noticed it, a simple "they typed it wrong" explanation was enough in 99% situations.
The home office rather notoriously destroyed/never kept its own records of arrivals of commonwealth citizens, which was one of the steps leading to the Windrush scandal.
Many older records only exist in paper form, and often the receipts are good enough. This is especially true when you’re dealing with 3rd party governments. A foreign government is going to put a lot more stock (rightly or wrongly) on a birth certificate that is printed on fancy paper covered in security features than it is to a printout of an email.
Also yes fancy paper is more valued than junky ones when nothing else remains, but random printouts are also provided everyday, and they're fine with it. At the crux of it, the foreign gov usually doesn't actually care that much about your birth certificate: they want due diligence at most, even if they'll have a more strict public facing facade. It's cross referenced only when it really matters (e.g. you're trying to get citizenship or a background check for security clearance ?)
That's not true. For example, Jews (or people who wouldn't be always considered Jews, but those who would still fall under the Law of Return) have to produce some kind of document which states that their ancestor was Jewish. Often these documents were issued by authorities that no longer exist. And it was up to immigration authorities to decide whether they trust such a paper or not. Basically, anything coming from Western Ukraine prior to Soviet occupation would be issued by such authorities, same with Baltics.
Unrelated to above: a lot of databases are only required to store their records for so long. For instance, the transcripts from most colleges can be produced within 10 or so years after graduation. Then it's like they've never existed. So, if for whatever reason you need to show your grades later, you better have a paper version.
Just to give an example of a document that I know had been submitted in this situation. A graduation certificate from a Jewish girls gymnasium in Vilno. The city has changed name since then, there's no such street address, there aren't any girl schools, definitely not gymnasiums, let alone Jewish. The building that used to be the school was destroyed in WW2. So, there's nobody who can vouch for the document. Maaaybe you could somehow find an index of all such schools that exited in the year of graduation, but even this info might not be available.
During WW2 a lot of civil records have been lost, especially in smaller towns / villages. Sometimes it was deliberate, especially if it was a Jewish settlement. It was common for Jews in the military to try to erase any trace of their ancestry, as regardless of how poorly the Red Army PoWs were treated, Jews and Communists would've been executed immediately. So, destroying records indicating such connections and forging personal documents was a common case. Now that people try to recover any traces tying them to their ancestors, they often have very little to rely on. Like, receipts from donating to a synagogue, or permits to start a particular business (typically associated with being a Jew) etc.
* * *
Another funny memory I have in this respect: in the 90's I was queuing in a bakery in some central part of Lviv. A man behind me overhead me speaking Russian (which wasn't very common at the time, since Lviv citizens frowned upon it, and mostly spoke Ukrainian), and decided to ask me if I know where Adolf Hitler street was.
My jaw dropped. But, the man pulled out from a pocket a triangular letter (the kind soldiers used to send during the war) with the address specifying exactly that. Apparently, the carrier of the letter was looking for his long-lost friend whose last known address was in Lviv, on that unfortunately named street. And since Lviv was seen as being quite radical in their way to dedicate streets to questionable historical figures, the old man believed that they might just have such a street...
Anyways, some locals overheard our conversation, and soon we discovered that the street in question was indeed named after Hitler during the German occupation, after Soviet occupation was renamed the Lenin street, but historically was called Lychakivska (and that was its current name, restored in the recent years).
* * *
Another similar story involves my dad's friend who was born in the 30's when the Soviets and the Nazis had a love affair. So, this guy was named Adolf, yes you guessed it, after the Austrian painter. He was Jewish. So, after the love affair ended, he sought to change his name. But you cannot change the name on the birth certificate. Also, his school graduation papers etc. all had him as Adolf, and that's how his family called him. Sort of. (I knew him as "uncle Dolik".) Not surprisingly, there wasn't much of a record of him changing his name to Alexei :) and he'd routinely get in trouble with all kinds of authorities, police when checking his driver's license, paying electricity bills etc.
Similarly, in Western Ukraine, prior to Soviet occupation, it was customary to give two names to children. Eg. my grandmother was Daria Anna. But the Soviet system didn't acknowledge this, and only one name could go into the passport / city records. So, she became Daria. At first. Then Dariana. And after having all sorts of documents, she was in a very tough spot proving ownership of her apartment, because it wasn't possible to tell (from the authorities perspective) whether Daria Anna, Daria and Dariana were the same person. Add to this that in order to preserve some of the family property she and her remaining relatives tried to mud the waters around these documents. Eg. to avoid partitioning the apartment she'd claim to have a sister Anna, who lived at the same address...
I'm quite sure that this wasn't an isolated incident. There would've been a lot of attempts to manipulate the system by creating fake people, trying to wipe out one's own records etc. Paper documents help in detective work to untangle such manipulations. If there was ever a single central source of this information, such manipulations would've been a lot more successful.
It hurts me. Everything going so far backwards.
At least once a week I have to screenshot something on iOS and use the new Photo OCR feature to copy and paste it out of the image. I wish I was joking.
I don't think the UK (Or US, other other European) government are too torn up about the possibility of another Windrush scandal.
But I generally agree with you. A physical passport offers a degree of psychological and real "security" that the promise of some cloud-hosted credential absolutely does not.
As a minor aside, I (US citizen) was once able to able to enter the US (at Toronto Pearson airport) despite having left my passport in some hotel. I just told the stern American guy "Yo soy American." Apparently they have ways of telling.
How offline is the current system today, where officers swipe/scan our paper passports into a machine?
This is the same thing I am against a cashless society where the society no longer accept physical cash. And in 2012, and later 2014 when Apple Pay was introduced all the way to 2017, 99% of HN were in support of getting rid of physical cash.
In times of disaster, the people welding paper along with the people who can trade on their street cred, familiar friends, family, will get stuff, do necessary business.
Everyone else will be essentially panhandling.
Mind you, not a damn thing wrong with panhandling. That is not a crime.
My point is to avoid having to do that where possible and practical.
my passport has been through a washing machine accidentally and i can still present it in the remotest of countries no matter the internet or whatever, and it works
in the US, yes they are switching to face recognition and often they barely even look at the passport anymore. I enjoy the convenience of that, but i don't wish to share this data with all the countries in the world, nor to be on the hook for having a connected device everywhere in the world for basic movements.
So having digital vs physical passports opens no new avenues of private data sharing with regimes you might not trust: they already have a right to demand any kind of data they want about you.
Canada, at least, already uses an ETA system called exactly that (or I guess TAE in French), so that probably had greater influence than the US ESTA.
It’s a part of a wider trend going forward. I will say the UK/EU systems are fairly unique in that they aren’t excluding each other. Canadians don’t need ESTAs nor do Americans need Canadian ETAs
Airport WiFi - people can easily run deauth with aircrack-ng. Email server might be down Phone out of battery Etc
It's digital in the sense that it's electronically stored against your passport number, and the UK Border Force can see it just by scanning your passport.
I strongly believe that a smart-phone should not be a requirement to partake in society.
Something as basic and important as a passport should not be entrusted to these ad-phones. Same with the push for smart-phone fintech / digital currency, or card-only retail. The 'easy option' seems to cost us more and more freedoms.
'This app requires permission to access your passport details. This is only to confirm your date of birth, and thus your eligibility to access the ad infested internet'
Having ranted about all that, I have to say that requesting a new UK passport last month was The best website experience I have had in a very long time. Simple UI, clear process, and worked perfectly without needing the latest nightly build of whatever new browser API / GB framework is the monthly fad. Just a shame it is quite ugly compared to the previous European one.
I'm 40; I stopped using email in 2016 (save temp-burners for a few necessary signups); essentially never do I carry a cellular phone, nor do I app/text.
My bank treats me like a criminal, locking me out of online banking; occassionally they cancel my debit card ("didn't you see our app notification?!"). Jokes on them, though: I live one block away from this bank, so I just walk in constantly to ask them for account balances/transactions, and to poke fun at their ideas of security (e.g. text 2FA, which login.gov specifically declares "bad practice").
It's actually kind of nice, having built rapore with a few of the tellers who already know why I'm visiting their location so often: bad company policies, dependant upon smartphone apps.
Should physical identification ever be legislated out of existance, I'd probably just expatriate (at this point, semi-retired).
Become "unreachable" — from whom is your choice, but I always suggest to start with ignoring work-related calls/texts, except when *on the clock. Certain countries are beginning to implement "right to disconnect" laws, which require your employer to pay you for contacting you outside of your scheduled work hours.
At this point I wouldn't even give a new employer my personal phone number (they'd get a burner for HR docs)... if your employers wants to call/text you, even during work hours, they can provide a phone/number.
None of my banks or credit card companies have any app requirement like that.
The US has passport cards but they only work for land and sea from Canada, Mexico, and Caribbean countries.
But the chip doesn’t contain “everything that matters”. The chips have biometric info (hence the name) like legal name, sex, nationality, photos, and sometimes fingerprints. But the bulk of a passport book is made up of tens of pages where stamps, stickers, and even entire visa documents can be stapled/attached. None of these are present in the chip.
It has all the same fields in one or two lines with "<" field separators.
I've had the chip read, I've also seen the passport being scanned to read those lines.
A passport has two components, one is identification of the holder, the other is the travel (entry/exit stamps) history and potentially the conditions of entry (visas etc).
... legal names and nationalities aren't "biometric info" though. Is it fair to say that the chip contains the content of the travel document at the time it was issued (doesn't the chip also include the passport number, issue/expiration dates, etc) but not the stamps/visas that are added after the passport is issued ? I think everyone gets that the chip isn't updated when you get stamped into or out of a country.
Yes to expiration date and number (although afaik it does vary because each country may include or exclude certain information), but in general no, because even if you have a visa issued to you at the time of a passport being issued (like at the time of a passport renewal), the chip will not have that information. The chip information is basically just proving who you are, but doesn’t have any info on where you are permitted to go (other than permissions implied by your characteristics like nationality). That information is stored elsewhere, like in the passport pages or a country’s internal immigration records.
So despite your cynicism, all governments literally are on the same page about passports.
What do people think organizations like ISO, ITU, ICAO etc do other than exactly this sort of standardization process of human activities that are common across national boundaries?
The challenge is how do you revoke a certificate which was used to issue millions of ID cards/passports once it leaks? Does everybody suddenly not have a "valid" ID proof?
Or how do you scale non-digitized operations up on-demand once some of this fails?
When it comes to privacy, government can even not keep any of the PII in a central place: it just needs to get it for signing and never needs to store it.
Basically, you can have a device that wirelessly transmits government-signed data containing your facial data and other PII, and upon validation, that data would be used for facial recognition and ID verification.
(Like JWT tokens for those familiar with them)
Revocations always come with a revocation date. Only passports issued after that date would be invalidated. The issuance dates could be proofed with cryptographic timestamps.
There is a trade-off between false positives and false negatives when choosing the revocation date of the issuer certificate. With OCSP, you could also revoke all the individual IDs that are not known-good (known to have been issued legitimately).
Of course, a world-wide interoperable passport scheme is unlikely to be designed with such an elaborate verification system, and maintaining registries of all legitimate IDs comes with its own risks.
In case of a massive breach, it’s more likely that everyone will have to get a new passport and re-prove their identity for that using separate means.
If you have a big family with the ownership of many assets - a car, house or an apartment, bank accounts, mortgage, various subsidies, and so on, the number of instances that you need to go to change your old passport data to a new one could quickly grow up to one hundred, depending on a country. The biggest problem with reissuing a passport is that its number and issuance date change, forcing you to jump through many hoops to continue life as before.
From my perspective, a passport is just an identity document. It's not a source of identity. When you get a new passport, your identity doesn't change, so you don't have to update your information anywhere. Immigration officials may be the main exception, if you live outside the country of your citizenship. Or maybe there is some hassle if you need to transfer a visa to the new passport.
Lots of countries use ID's serial number as a sort of identity. Like, your bank would literally store "Mr. John Doe, G.I. ID 60-05 123-456-9012, D.o.B. 1985-07-29, etc." in your record, and when the next time you visit a branch and show them your new ID, it better have a "previously issued IDs" section on it with that old ID number there, so they would confirm that it's still you and update their record.
And presumably, you would still have to renew your passport every ten years or so anyway.
You need cutoff date and some kind of public trail log to prevent backdating new certificates. This can be done via short-lived secondary certs derived from a root one, logged publicly
You might be able to do it without a public log by using an RFC 3161 (TSP) secure timestamp facility like the unfortunately named https://www.freetsa.org/. Basically, we want to trust identity attestations ("I am Bill Clinton and this is my face") made by a compromised CA between the time the CA certificate was created and an estimate (hopefully a conservative one) of the date of compromise. We want to distrust any certificates signed outside this time range.
This way, in the event of a CA compromise, we don't have to revoke everyone's certificate after a CA compromise.
I think we can implement this security model by having the CA ask the TSP server to countersign each certificate that the CA issues. The TSP would sign a hash of the whole CSR, including both identity ("I am Bill Clinton") and biometric (bill-clinton.jpg) information. Anyone can use the TSP's attestation to provide that the TSP server witnessed this combination of inputs at a specific time.
Sure, if you've compromised the CA, you can issue a certificate saying "I am Bill Clinton", but to do so, you need to either use a genuine, up-to-date TSP attestation, giving away the game, or you need to use an old TSP attestation, forcing you to use exactly the original inputs to the TSP. Using the exact inputs wouldn't help you: you want to issue a certificate saying "I am Bill Clinton" with attacker.jpg as the face, not bill-clinton.jpg. The latter won't help you do anything: you don't look like Bill Clinton and you don't have his private key.
An attacker would have to compromise both the CA and the TSP server to pull off a passport forgery. And you can make this process even harder by requiring multiple independent TSP servers to countersign certificates.
The examples in the article just store the document data in national database. In both examples (Finland and Singapore) you register online before the trip and then still show up with your passport.
Singaporeans just show up with their face because their face is already linked to their government ID, stored locally. This can be done by any country after pre-registering your regular passport.
All of this is trivial to implement. There's still no mention of full digital validation.
Why introduce new problems? I was bike touring and wasn't carrying a phone. Isn't that allowed?
So these documents can be checked locally without any form of communications to some central authority (which doesn't exist across national boundaries).
They have visible anti forgery like UV printed symbols and information, underprinted background text and patterns, etc etc.
So they are more "meaningful" than an offline smartphone with a passport app in that they do not require anything other than the officer's ability to see, feel and read the documents.
Even when there's no connection, no electricity, you get some modest layer of security out of "it's hard to manufacture a convincing fake passport if you don't have large-scale resources behind you."
What happens then with app-only passports? Do we close the border crossing entirely until the network is back up? Or do we rely on showing a QR code or NFC handshake that can't be properly verified? I'd think creating a fake passport app that reached those hurdles would probably be easier than getting access to specialized papers and printing technology.
I'm not denying that it's security theater or claiming that it's more meaningful; I'm saying solely that there are physical expectations that are going to be very hard to shake once you go off the beaten path.
I've found that money is more meaningful than anything else to those bored officers. Either they don't actually care that much about your documents, or if they do, they're simply looking for a bribe. At least that's been my experience at out of the way border crossings in southern Africa.
The most ridiculous experience I had was crossing into Zimbabwe with my 11 year old son. The officer wanted to see his birth certificate, which was still in the car that had already been driven across the border. So I had to leave the building, walk across the border, which nobody batted an eye at, get the document, walk back across the border, re-enter the building, and then present the document to the officer who didn't even look at it before letting me proceed to leave the building and walk across the border once again.
just playing devil's advocate with the way I see it heading
Expecting always on satellite connections in a lot of these places is asking for a lot.
It might be easier than having reliable power grids or running water supply. Assuming at least some of the satellite-internet projects work out (Starlink, Amazon's thing, Chinese thing, European thing, ...) all you need might be a fairly affordable (comparing to infrastructure for running water) hardware that can run on demand using batteries.
AST Spacemobile and Starlink's user experience will just require mobile phones. No adapters or base station. they'll find a way to power them, or extend signal from them. for the passport holder, that will just be client side and no connectivity necessary.
But as others have noted: assuming satellite cellular access is also a big leap. I once had someone check my papers by taking my passport, writing a copy of the entry visa number on it (itself hand-written), and then finding me hours later after they were able to find a landline to call the border service with.
The last time I did that the TSA scanner was able to read the QR code just fine, but the tablet app that the flight attendant was using at the gate couldn't read it for some reason. After about 10 seconds of fidgeting with the tablet they asked me what my name and seat number was. I told them, and after checking the list they let me through onto the plane. It looked like they tapped around in the app to override the QR code scan or something.
Fast-forward 20 minutes, and we don't push back from the gate when it's time to depart. After another 5 minutes of delay they got on the PA system and said something about the passenger count being off and that the airline's headquarters wouldn't authorize departure until they figured that out. At one point about half an hour into this a flight attendant walked over to my seat and leaned over to adjust the air flow thingy, which I thought was a super weird and random thing to do. In all it took nearly an hour of everyone sitting on the plane at the gate before they figured it out and authorized departure.
I actually have no idea where the breakdown was, because this happened at the gate when I flew earlier and it wasn't at all a problem. I presume the flight attendant scanning QR codes at the gate didn't hit the right buttons on their tablet that time. If we're going to rely on peoples' completely random personal devices to track authorization to travel, our systems need to be a lot better than this. Exceptions to whatever they think should be the "typical" flow should be straightforward and streamlined.
In the meantime since they've gotten rid of kiosks in my local airport I guess I'll be going to the front desk every time and ask for printed boarding passes.
Flight attendants need to adjust airflow when the plane will be sitting on the tarmac longer than expected. On older aircraft those little nozzles are the only way they can control cabin temp while on the ground. They keep an eye on cabin temp readout and adjust nozzles to change it. Again, I’ve had attendants reach in and adjust (usually open) nozzles when we’re stuck on the ground.
> The remote-access computer transponder called the "joymaker" is your most valuable single possession in your new life. If you can imagine a combination of telephone, credit card, alarm clock, pocket bar, reference library, and full-time secretary, you will have sketched some of the functions provided by your joymaker.
The protagonist eventually finds out from personal experience that people who do not have those things (e.g. because they can't afford them) are basically social outcasts, not the least because they can't hold most jobs, or even look for one. But even beyond that, not having the device means that you aren't being tracked means that you can e.g. be murdered without much of a consequence. And so people who can't afford the real thing still shell out money for a mockup of a joymaker to carry on the belt, just so they aren't obvious targets.
The most interesting thing about that novel is that it was published in 1969, long before cellphones or "the cloud" were a thing. A rare case of a sci-fi author taking a contemporary hot bleeding edge tech (remote time-sharing terminals for mainframes) and correctly extrapolating it into the future. Pohl even gave a broadly correct timeframe when he talked about the novel:
> I do not really think it will be that long. Not five centuries. Perhaps not even five decades.
The level of expectation that your phone is a set of handcuffs that you do not own is high. If you own your device and not vice versa, things just don't work in this world. And honestly why would I want a computer that I didn't control anyway?
In some ways it is the opposite of a "burner" phone - sort of a quarantined device that only interacts with your real, official, legal identity.
https://en.wikipedia.org/wiki/Flow_My_Tears,_the_Policeman_S...
You end up there by being born in the wrong family or part of town.
Normally a huge fan of a bigger web platform, but will control, coral, and track users and that's a #rfc8890 violation of very high degree.
Digital Credentials API: https://developer.chrome.com/blog/digital-credentials-api-or...
I imagine that the issues for making, deploying and integrating a digital-only passport on a global scale would be much harder.
Can’t tell if the stamper has a plum job or if it’s a punishment.
The problem you'll have is that the stamps may not carry the force of law, so not much help in a pinch.
Hopefully this will be fully automated at check in though. They already have all the info there, don't ask me twice. Send me an email if you won't accept me into your country. It can have its upsides.
ok, do you want that, or are you required to have that..
Uniform servicemen already have made agreements about their data, locations, records, check-ins ad infinitum.. but citizens have not made those agreements.. So uniform services will just make those agreements mandatory.. there is no end to this.
especially irksome is piling on requirements for constant check-in among law abiding people who own property and pay taxes.. while somehow hundreds of thousands can walk around living in parks in the South ? I am not even extreme on this topic .. it just defies common sense and says Slippery Slope in giant letters
When you cross the border on the water, you aren't required to report until you go to land (if you never set foot in Canada, but only sail through territorial waters, there is no requirement to report), at which point you must go to a specified customs dock, and present your paperwork.
Don’t really see what a bunch of people wondering around parks all located in the same country has to do with boaters moving between a smorgasbord of islands belonging to two different countries, and thus randomly crossing the boarder back and forth multiple times in a single trip.
People want it because it lets them do what they want with less hassle and it makes many trips possible that are impossible if you have to cross the border at a manned border crossing.
But of course, there is a slippery slope danger.
If so I'm going to be the one asshole who presents the document on my laptop just because I don't believe that people have the right to invite themselves onto my phone.
> Address the massive amount of data from passenger digital devices
> Collect all relevant data from every available data source uncovered at the border
It’s a little disconcerting because you’re literally one „computer says no“ incident away from not being able to return to your own bed.
Literally zero paperwork was issued to fall back on so you’re entirely dependent on a DB server somewhere
Probably going to get a UK passport too just to manage risk. (Already qualify)
Travel to the UK is going to be really chaotic from 1st Jan when all BRPs expire, and 8th Jan when US citizens and other non-EU nationals require ETAs.
From HO website: "You may be able to use your expired BRP to travel to the UK until 31 March 2025 if both: your BRP expires on or after 31 December 2024. you still have permission to stay in the UK."
You might be able to bully them into accepting them because it’s in Timatic but there will be British residents who are blocked at least temporarily because of this.
Russian visas are machine-readable since 1997 to ease the DB request.
I appreciated the complete lack of a passport line (going and coming), but got squicked out about the heuristics the system (might) run through before it let me through.
That's where all of this is headed, though.
I think you're overestimating how sophisticated the system is. Most online check-in processes require you to input your passport details. In-person check-in probably results in the gate agent doing something similar. If the arrival airport has this information, it's pretty easy to look up the corresponding face on file (that you provided when you applied for a passport), and use that to generate a list of faces you need to match against. From there, it's only a matter of matching a given face to a face in that set. Moreover, given that arrivals are staggered, that set is going to be relatively small. A wide-body aircraft holds around 300 passengers. If 3 of them arrive at the same time, to the same passport control point, that's only around 1000 faces to match against. That's far easier to do than trying to match against all faces in the entire country, for instance.
It's not inconceivable, however, that the system connects to whatever other dossier(s) have been built against my identity. Even before we consider ML facial recognition by public cameras (probably not yet possible at scale?), the Singaporean SIM card I bought was connected to my passport, which gives them my location: both absolute and relative to anyone I might have spent time around.
I mean, I was a normal tourist, and not doing anything shady whilst I was there, but... False positives exist, and I wouldn't have wanted to have been pulled out of the queue for questioning about something I couldn't possibly have explained.
Singaporeans seem to have a different point of view about surveillance, however. Even the (fairly low-key) human rights activist I chatted with thought it was all great, and said something along the lines of "the cameras keep us safe". "Privacy" as we tend to think about it on this board may be a mainly Anglo-Saxon concern, for what that's worth.
Why do they need a dossier on you when the passenger manifest has your exact identity? Or are you talking about them tracking you in the country after you left customs? Given that passport control is already plastered with cameras, and you need to present an identity document containing your face to enter the country, I'm not sure why people feel extra creeped out by an automated passport control gate. If they wanted to track you they already have all they need.
https://www.ica.gov.sg/news-and-publications/newsroom/media-...
1. There is very little to no chance that all the governments in the world are going to cooperate to create a centralized database about their citizens. Most countries don't want to do it and I don't see China or the US doing it anytime soon.
2. The biometric passport is not a paper passport already. The same way the SIM chip disappeared, your "passport" can disappear too.
3. The non-biometric passport will remain valid for at least 20-30 more years. I am talking about these very old passport that only a few handful of countries still issue including the USA (for particular situations). This backward compatibility will mean that the paper passports (even non-biometric!) will remain supported for a very long time.
Agree that a 100% rollout is unlikely. However the UN, WEF and associated groups have been seeking global Digital ID for awhile now. Apparently it will help them protect us all from Climate Change.
https://www.undp.org/blog/why-legal-identity-crucial-tacklin...
https://www.id2020.org/1. I get a Free Smart Phone for use for this
2. The service is Free
Passport books have a 1 time fee and for 10 years in the country I live in. I expect the same for Phone use.
That’s more than enough for a cheap android phone.
1. https://travel.state.gov/content/travel/en/passports/how-app...
Not much above emotional attachment is free here under the sun.
It is not a good idea to have keys, documents, passes, ... all on a smartphone: it can break if dropped, it can be stolen anytime, it can have no battery. Those devices are not good for such important elements of a travel.
And thus: Gregoriol's Law is born.
I have to say though that the guy I spoke to at the Passport Office (a civil servant!) was very nice, and they did git it to me quickly. Never used it again 4 years later, though.
Presumably the 15% of UK residents who have no passport are still able to identify themselves somehow...
Depending on the legal process in question, another photo ID (e.g. driving licence) may still be needed.
When I was traveling in London in 2018 I was barely able to pay for the groceries I needed in order to eat that night because I was checking out just as the global VISA outage started happening.
https://www.theguardian.com/world/live/2018/jun/01/visa-outa...
The machine took a long time to process my payment, but after a couple of attempts it managed to go through. As I left the store I noticed a long line forming for the self-checkout registers, and nobody else was able to get their payments to go through. There was apparently no option to fall back to cash at that store.
Whenever I travel now one of the bits of research I do now is to make sure I have a plan for getting basic necessities like food and shelter should an electronic payment system outage like that happen again.
Until then, I'll continue to print such things out on paper.
Additionally, passports don't need to be charged.
I know my boycott won't mean much to those who are willing to put their entire lives onto their personal tracking devices. Maybe it even seems unreasonable to those who are accustomed to complying with testicular exams at the airport. That's totally fine. I'm not here to convince them of my principles. We all have different values.
The point is I can leave the house without a device or ID and live a perfectly normal life.
https://www.cbp.gov/travel/us-citizens/mobile-passport-contr...
But you still need to carry the paper passport as backup.
Yeah, sounds good. Again, I hope those days are numbered higher than mine.
The answer: nope, it's almost certainly time for round 2. Plus some forced facial recognition for good measure.
Like I said, I hope the number on those days starts pretty high.
if this really does somehow become the only option, I'd imagine the best you could do is just carry a cheap android phone for this sole purpose.
I think many men will keep their paper passports with 10 year expiration date. And renew it every year "just in case".
1. How would it work in case of dual citizenship? Would one be able to choose under which nationality they want to cross the border?
2. "(...) no fallback systems in place." This is worrying. Do we just send people back (at their own cost, I presume), because they were rejected by the system? This seems like a pile of lawsuits for unlawfully preventing family members to visit each other or generally restricting freedom to travel with no accountability.
Revelation 13:17 And that no man might buy or sell, save he that had the mark, or the name of the beast, or the number of his name.
I'm all for digitalizing documents as an option, but not if it means losing physical copies. So far the government has been on the side of not discarding them - we still get paper social security cards.
Sure, you can have a digital passport for purposes of authenticating yourself, which is operated by your national government. Will this government allow the same level of access to the embassy of North Korea or some other geopolitical adversary or just to a random sim card issuing shop in a mall oh the other side of the globe? Maybe they will in the same way corona certificates were implemented. Now will every single place that legitimately needs to have a copy of your id on file be bothered to interface with this system and all slightly incompatible versions of it provided by other governments? Probably not.
And passports are kinda sorta simple to begin with.
Credit cards are just chip carriers now. Mag stripe is being phased out. So either you use the chip connection or use contactless. The cards issued by my bank (Australia) aren't embossed and the mag stripes will probably disappear once the banking 3rd world (US + some of Asia) catches up with the rest of the world.
Oh and contactless is literally the same protocol as the contact connections, so "just tapping their phone around" is exactly the same (to the terminal) as "just tapping their card around" or "just inserting their card to read".
Government ID could be done in a privacy enhanced way that only provides the requestor attestation of the required information and nothing else.
eg * "Is this person that just provided an encrypted and unreadable blob from their ID card over 18?" "Yes".
* "Is the person that just provided an encrypted and unreadable blob called John Doe?" "Yes".
The government already has all of your identification from birth to death.
By (mostly) definition, your identification is what your local government says it is.
Unfortunately we're losing cash. There is one of those modern "chic" mixed-business-and-apartments developments not far from my house. Shortly after they completed construction my 12-year-old daughter visited the ice cream store there with her friends, but she couldn't pay for her ice cream when she got to the register because they didn't accept cash. They ended up just giving her the ice cream.
Most of the restaurants there have a "no cash" policy posted in their windows and at the till. No skin off my back. They're overpriced for what they are anyway, so I'm happy to give my business to other local restaurants not in the fancy mixed-use development.
Paper passports shouldn’t go away. The USA should, though, stop issuing 50 page passports by default. Way too many pages for how less frequent passport stamps have become for the average traveler.
On the other hand if my phone is gone I am prety much dead no money no papers just another john doe...
The current experiments seem to be fractured across governments and I would be very surprised to see a centralized system (as your response seems to imply) come into play until well after various governments introduce their own digital systems.
Ok so it's not a passport. What is being described by the article are just national identities based on physical cards. Estonia has been doing that for a very long time as well.
Without a paper passport I’m not sure how that would work. They could code it to another piece of identity I guess (like your ID card), but there would still be something unless biometrics become advanced enough.
Everyone is quite keen on maintaining sovereignty on matters like this aside from tightly integrated blocs like EU
I’m not sure what you’re referring to. Where are you traveling from? I never had my EU passport inked when traveling to the UK or US. Within the Schengen Area I never needed a passport.
Common in/out the Schengen with my UK passport post Brexit - got lots of stamps. Though it varies by country
As an AU passport holder it's been like that for at least 30 years.
The problem was when I caught COVID while on a trip to Vancouver. I was getting very sick and needed to get back home ASAP, but since I took the train I couldn't drive. All the car rental companies in the area were completely booked out. I thought, "Great, I guess I'll just go to the airport and catch a flight," except since I had crossed by land on the way in I didn't have the document I needed to fly out.
Fortunately I was able to find a bus early the next morning, but it was looking pretty sketchy for a few hours until I could figure out how to get back home. After that experience I'll never travel out of the country again without my actual passport.
> The booklets and stickers should be done away with.
I would prefer that stickers continue to be used, but have cryptographic information in them and partially derived from information on the passport book itself.
No guarantee, etc - but theoretically still possible as of 2024.
I understand the need to identify people people crossing borders etc, but it's not, never has been and should never be a binary or digital thing. I'm not a religious person whatsoever but the identity of a human is not a stamp.
No-one should have this right to such centralized control of human interaction, whether it be facebook or globally linked digital passports. We desperately need more local and subjective methods of reputation that are not tied to big centralized corporations or governments (one in the same).
And yes, subjectively is a feature. I don't know how we can solve it but current path does not look good and is incredibly anti-life.
It would be great if we had a universal ID program. Even better if that program also replaced Social Security numbers.
Alas, it'll likely never happen in my life time.
They've been trying to do this, with "Real IDs"
Not exactly what you're asking for, but it's more akin to making Drivers licenses like passport cards
What do you if your phone is stolen or broken?
I have plenty of left-wing friends who refuse to get realids due to something about illegal immigrants and right-wing people hate it because they view it as central govt overreach.
Are we all getting bar code tattoos and will be prosecuted for not having a barcode tattoo?
from a weak passport owner's perspective, our biometrics are already taken away whenever you apply for a visa. as shown in the article, for domestic purposes too this is done, so this is just a matter of convenience to nudge everyone to give it up now.
with the above fallacy, one would be ok to adopt this system for international travel. but i wonder if adopting this system in all air travel would be the additional notch up in the temperature of digital privacy.
The author seems to lack the capacity (or experience!) to imagine other ways of moving around the world that are not flying.
It basically is a prison planet already, the remaining aspects of the humanity of it are just being automated out slowly but surely. The worst tyrannical dictatorships in history could not have even dreamt of the current state of things in their wildest dreams, and we are all racing at breakneck speed towards a hell of total domination by sadistic tyrants.
> A DTC, according to the United Nations’ International Civil Aviation Organization (ICAO), which is behind the approach, is made up of two parts: a virtual element, which represents the information stored on passports, and a physical part, the bit on your phone. The two are cryptographically linked to ensure they’re not forgeries.
Your phone, apparently, can't simply carry this data and provide that at your choice to the passport checkpoint for it to verify by taking a picture of you and comparing it against their database. No, it needs to be locked down. If you are the admin on your device, you could make a copy, so it sounds like this will never be allowed to run on a phone that isn't locked
Smartphones are supplanting computers for a lot of people but manufacturers lock it down in a way that you can't fully see (let alone control) what it does. Some manufacturers let you flip a switch and get this access, but then big corps and governments try to counteract that and refuse to provide their service on your unlocked device
For a smartcard (bank chip, SIM card, yubikey, passport, oyster card, etc.) this isn't a problem because the device is dedicated. I don't need access to the private key on a SIM card because I've got no intention of forging it. Would be cool to see its internals but it doesn't have a microphone or its own uplink. However, I do want access to my smartphone because I use it for all sorts of things (including making a full backup instead of dealing with individual apps' manual or adb export functionality) and it processes all sorts of personal data about me that I want to be in control of (I often open an app's data folder to see what is stored, queued for uploading when I don't give it network access (SwiftKey has telemetry reports queued for years and years), or to modify some setting that the GUI doesn't expose). One of my primary devices wouldn't really be mine if I need it to carry these things requiring DRM
These applications have legitimate reasons to want to be on a smartcard, for it would require an always-online database who the counterparty (such as border control) can trust if they can't trust me or my device. It just doesn't belong on a smartphone, like get your own secure storage if that's what you want me to carry. Payment, passports, and public transport can all bundle their thingies onto one smartcard just fine (if they can standardise on phones, they can also standardise on a much simpler device with more uniform functionality). It could even be a smartcard chip inside my phone, but it shouldn't be my phone with my data on it that needs to be locked down for this unrelated purpose