Fake identities are dime a dozen. It is not exactly hard for an illicit entity to just put some random ID numbers it bought off the dark web on its books. And now you have just made it even harder for the people who had their identities stolen to clear themselves. How do you convince some company drone doing sanction compliance that you didn't actually work for Sanction Circumvention Ltd when your ID number matches the one on their company's payroll files?
Not to mention the sanction list is full of foreigners. The American authorities compiling the list aren't going to know what's the national ID of a random Russian or Iranian guy running an import business. So what is going to happen if your name matches someone who's on the list with a blank ID field? Probably the same thing that happened to the author, I guess.
Verifying identity is a much simpler problem than establishing identity.
They didn't care to figure out if the Sean Byrne of County Sligo actually existed before putting the name on the list. I doubt they would bother verifying an ID number.
Plus, going back to my point about the list being full of foreigners, how do you verify the validity of a foreign ID number and address? Maybe Ireland is going to comply with a US request, but many other countries won't, and you are now back to square one.
Not bending to the US might be less convenient at times but if you bend for them you will eventually be bending for China.
It's fine to propose a solution but if people aren't convinced just throwing an aphorism grenade at them isn't productive.
> In both cases the courts called for better matching. Compare the date of birth. Compare the middle name.
> There is no version of that available to me. The listing has no date of birth to compare. No middle name and no passport number, because the person doesn’t exist. A screening system that does its job perfectly will still flag me, forever, on the only two facts the record contains: a common Irish name and a country.
These systems operate by matching as much information as possible. If the information isn’t there but the rest matches (even if it’s just a name) it flags in the system.
> Failing that, the actual person can prove that they don’t belong on the list by verifying their identity.
Sounds like you should tell the author. They’ve been living with this problem for 6 years but I’m sure your zero experience with these systems or trying to deal with it will help him immensely.
The idea is you largely prevented the theft, and made it easier to prove, by linking to a physical verifiableb address.
The real Sean Byrne can produce a government-issued passport number, but that's clearly not enough for Apple.
I think it's more of a problem of all these "hyperscale" platforms where the cost of not being zealous enough is long litigation and devastating fines, while the cost of losing a single customer (or a thousand) is basically nil. This leads to all kinds of opaque, customer-hostile outcomes like this, also if you trip some filters not related to sanctions / mistaken identities. There's a recurring theme of HN posts along the lines of "an automated process at Google cut my business off, HN plz help".
I do not know how are they handled, but they probably get assigned one plausible date and it probably depends on the country.
In a sense, a birth date can be just as much an assigned number as an ID is. An ID can also have a checksum in it, potentially even a cryptographic one that only government can sign.
Having the full name + national ID was enough to bypass verification and activate various services, and many people weren't tech savvy enough to realize how dangerous it was to share or leak that info
All else being equal, I'd rather see national ID numbers which are so incredibly obviously un-secret that, at least on their own, they're nothing except a tool for avoiding overlaps and collisions.
Same as with passports. Even in the Anglosphere people have passports with passport numbers. They could be used to uniquely identify the passport holder, except of course there are many passports, and therefore, many numbers, for each passport holder.
Small problem? Just update whatever database is holding the information for sanctionted persons (or, indeed, persons who should not be sanctioned)?
Turns out, that is not a small problem.
In Singapore, your number is fixed, even when they give you a new document.
All that these numbers do is uniquely identify people. They aren't private. To actually prove your identity, you present your ID, passport, or a digital signature tied to that identity number.
That also means they should be used simply as an identifier and not as any for of authentication or secret knowledge.
I’m applying for a second citizenship. That means that I can have two national ids that are unlinked. In the US, you can petition to have your SSN number changed, as well, so that doesn’t work. If you are willing to commit crimes and lie, it isn’t that hard to spin up an entirely new identity. Some people are born to parents that don’t notify the government. The real world is incredibly messy.
If I were to be placed on a list with one passport/id, I could just use a different one.
The bigger issue is that the list is meant as a risk alert, but companies treat a match as truth because the penalty for doing business with a sanctioned entity is far higher than whatever they might lose by not hiring someone mistakenly.
What you need, at minimum, if you are going to make these lists is an easy way for false positive people to prove they aren’t the person named (tsa/homeland security have a “redress number” you can provide if you have the same name as someone on their list). Then a legal requirement that anyone checking this list must also ask for additional documentation if they are making a decision based on a hit.
I'm sorry what? A second citizenship to the same country?
I won’t have two unlinked national ids to the same country, I would have a national id in two countries.
What happens when every app, website, and mobile OS requires a signature for every single post or message, tying all communication to an identity that the government can retaliate against?
This creates many more problems than it solves.
With services requiring it, you can just not use them: as long as it does not get mandated (unfortunately, a direction we are heading in), hopefully market self-regulates and privacy conserving options win.
Yes, we all know that's not how that movie plays out :)
Try existing in the USA for a month with no phone number.
or do you mean HSMs in the possession of the user? what happens when they lose it, or the device is stolen?
It says the state assigns "A body" a number.
-vs-
The state is made up of us as individuals.
So while the serial keyfield is a data engineers dream, politically I'd welcome something more personal.
Time of birth/parents and other identifying information is on our birth certificates in the UK. Concatenate some of that.
I could be.
DavidAndrewEvans-01011980-0036-MRI-JeanDavis-AlexEvans
Name-DOB-TOB-LocationCode-Parent(s)
Location of Birth like an airport code - MRI (Manchester Royal Infirmary), Parent(s)... i mean we can use their birthdates too.
I actually quite like the idea of it. It seems intrinsically validating to a person to identify them in this way.
Ideally, government could issue a cryptographically signed ID, so anyone with access to countries' public key can verify authenticity (with revocation mechanism built-in for both individual keys and all keys signed with one government — this is where it gets tricky). Obviously, governments become new CAs, and people in them can provide fakes when they want if they are corrupt, but anyone can easily validate it.
You're reinventing a natural key with a bunch of identifiers which aren't stable enough.
The reason is there. It's no big secret. Pick up a history book.
Nazi Germany and occupied forces used census data, municipal population registers, etc., to identify and track down targeted people. The United States, during World War II, used census information to assist in the removal and incarceration of citizens with Japanese, Italian, and German heritage. The Rwanda population database explicitly classified people as Hutu, Tutsi, or Twa. This became the mechanism to target Tutsi during the Rwandan genocide. In China today, these databases are used to surveil and imprison Uyghurs.
Those are examples of official policy turned to dark purposes. It did not even include malfeasance for malfeasance or criminality by individuals or cartels who somehow gain access.
It's not like you care about all the thing you enumerated, they literally ask you for your "race" when getting a driver's license, which is the defacto ID document anyways. You're installing flock cameras everywhere and gargling palantir's balls while they implement the surveillance state.
The lack of a comprehensive population database only seems to hinder the actual useful civilian bureaucracy, not law enforcement, intelligence services, or ICE. The latter just grab anyone who looks brown enough.
Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Many countries have laws about having to carry an ID on you all the time. Not as bad as a tattoo, but still not acceptable IMO.
> Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Are we really gonna keep pretending there are no differences between cultures?
Also, I find the point kind of moot for the US where a driving license is essentially an ID card, you have to carry it to drive, and you have to drive to go anywhere in most places.
Either way you are branded forever.
Even GDPR admits it