I’m against “let’s hold all progress because a few states can go backwards faster than they’ve been” perspective.
Yes, I realise governments already have some powers to view private data, but they have to do a lot of legwork to link data to specific people. They'll always get false positives, false negatives, duplicates, etc. And they'll miss a number of platforms that have data on the person of interest. Digital ID combined with a mandatory identity platform and data retention requirements will make law enforcement far more efficient and give governments unprecedented power over what we see, hear and say online. The government will have a complete list of all the platforms on which you authenticated with their Digital ID.
We're already sleepwalking into this. In Australia, we have the under-16 social media ban taking effect next month. We're also in the process of rolling out our Digital ID, which has an OAuth/OIDC-based identity system. Numerous government departments have already integrated with it. It opens up to private sector integrations in December 2026, just in time for all involved in the under-16 social media ban to realise it's not working effectively and for Digital ID to save the day. The law states that Digital ID is a voluntary means of identification and other methods should always be offered, but the UX of OAuth 2 vs. uploading photos of your ID documents and a selfie, and waiting for it to be reviewed, will make Digital ID the de facto standard for Australians proving their age and, in the process, permanently linking their Digital ID Identifier to all their social media accounts. That includes "anonymous" ones like Reddit. And integrators can apply for an exemption to Digital ID being voluntary on their platform, making the case that the per-user cost of complying with the law without Digital ID is prohibitively expensive.
Once Australia rolls this out to social networks, it will keep expanding until virtually everything is captured.
Governments can do that today already. Digital IDs don't contribute anything to this. They just make our lives easier, not governments'.
> but they have to do a lot of legwork to link data to specific people. They'll always get false positives, false negatives, duplicates, etc.
Those false positives/negatives, duplicates affect real people too. That's just a case for digital IDs, not against.
> and, in the process, permanently linking their Digital ID Identifier to all their social media accounts
How do you reach to that conclusion? How are they permanently linked? It's perfectly possible to verify your age digitally without permanently linking your ID with your social accounts.
> Once Australia rolls this out to social networks, it will keep expanding until virtually everything is captured.
Again, that can be done without digital IDs. You're holding the wrong front here. Privacy invading laws should be fought, but the public shouldn't be kept away from the convenience and privacy gains of digital IDs. It makes no sense.
This is just straight up not true for the EUDI which is probably the most serious and advanced approach to digital ID. The wallets are decentralized and the government does not see the individual authentication transaction in any way.
It feels healthier for the enforcement apparatus to have a budget, in terms of material personnel or time, that requires some degree of priority-setting. That priority-setting is by its nature a politically responsive process. And it’s compatible with the kind of situation that allows Really Quite Good enforcement, but not of absolutely everything absolutely all the time.
Otherwise ossification feels like exactly the word, as you said, stavros: if it costs nothing for the system to enforce stuff that was important in the hazy past but is no longer relevant, nobody wants to be the one blamed for formally easing restrictions just in case something new bad happens; 20 years later you’re still taking off your shoes at the airport. (I know, I know, they finally quit that. Still took decades. And the part that was cost-free—imaging your genitalia—continues unabated.)
Since most of that "digital ID" manifestations are just pixels on a screen, these are not a problem to fake pixel-perfect.
I did some limited travel during the COVID era, including areas that did not want to recognise my country's digital vaccination certificate. I presented them with a pixel-perfect picture of their own country's digital vaccination certificate. It's easy to copy from a screen of a friend, and it's not complicated to create your own Apple Wallet pass that looks like the one you want.
Eventually in a system like that they may refine their procedures and then you get dinged essentially...
"The guy who went to jail" could be unvaccinated (or even infected) and presenting other people's certificates to enter an area for vaccinated people only (e.g. hospitals) where he might have endangered other people's lives; that's something that might be deserving jail time. I was vaccinated however, and by all means had the right to enter that shopping mall; I just wasn't able to prove it to the imperfect system that was there to check.
Digital IDs can't be faked. The only way to fake them would be to convert them to physical (what you did) and hope that the physical ID gets accepted.
(Digital IDs indeed can’t be faked but usually they are a part of a process that can be easily bypassed by using something that presents itself as a valid Digital ID even if it’s not.)
Credit cards are a great example: they can't be faked, however while the cryptographers are sitting on their high hill and patting themselves on the back for doing great job, the credit card fraud rings billions of dollars every month. It doesn't happen because of fake cards -- it happens by exploiting the flaws in the whole process that a (non-fakeable) card is a part of.
Once everyone is mandated to carry digital ID, then possibilities to track population open up.
[1] to paraphrase one many excellent John McCarthy-isms: http://jmc.stanford.edu/general/sayings.html
Digital ID doesn't have to report your location either, depending on the implementation. It's not like it's a given a digital ID system has to give your location.
An SSH key is a digital ID. Does it report your location when you use it? A GPG key can be a digital ID. Does it report your location when you sign something?
You normally aren't carrying your passport with you, right? So even if lower security, the chance of that information being swiped is generally lower.
Phones are pretty high profile targets, this makes them more so.
I do like the idea and the convenience, but I'm definitely wary of these things too. Especially in the modern tech world where security is often being treated as a second thought as it is less impactful for sales. I'm pretty sure it is always cheaper to implement the security, but right now we're not great at playing long games and we like to gamble. Humans have always been pretty bad at opportunity costs. We see the dollars spent now and that seems to have far more value than what you save later.
On the other hand, currently US citizens are not legally required to walk around with their IDs on them. That's not true for non-citizens btw. You should have to just give the officer your name, but they can detain you while they "verify your identity." With an ID becoming frictionless and more commonly held on person, will this law change? Can we trust that it'll stay the same given our current environment of more frequent ID requests (I'm trying to stay a bit apolitical. Let's not completely open up that issue here?). I'd say at best it is "of concern." But we do live in a world run by surveillance capitalism.
There's a really good example I like of opportunity cost that shows the perverse nature of how we treat them. Look at the Y2K bug. Here on HN most of us know this was a real thing that would have cost tons of money had we not fixed it. But we did. The success was bittersweet though, as the lack of repercussions (the whole point of fixing the problem!) resulted in people believing the issue was overblown. Most people laugh at Y2K as if it was a failed doomsday prediction rather than a success story of how we avoided a "doomsday" (to be overly dramatic) situation. So we create a situation where you're damned if you do and damned if you don't. If you do fix a problem, people treat you as if you were exaggerating the problem. If you don't fix the problem you get lambasted for not having foreseen the issue, but you do tend to be forgiven for fixing it.
Just remember, CloudStrike's stock is doing great[0] ($546). Had you bought the dip ($218) you'd have made a 150% ROI. They didn't even drop to where they were a year previously, so had you bought in July of 2023 ($144) and sold in the dip you'd have still made a 50% profit in that year... (and 280% if you sold today).
Convince me we're good at playing the long game... Convince me we're not acting incredibly myopic... Convince me CloudStrike learned their lesson and the same issue won't happen again...
Look at Germany where they outright refuse to acknowledge emails as a legal notification / correspondence so everything still gets sent as letters and fax. It's extremely slow and cumbersome.
Also it will help for security as the central service can authenticate you, instead of every little hotel and bank branch, etc. keeping a copy of your passport.