That suddenly means a data leak doesn't matter - nobody can make new signatures.
Verifying someone's ID would be as simple as asking them to sign your company name and today's date.
[1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...
Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.
What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.
Things are already bad enough as it is, but at least it’s still possible to get by even if the system takes a dislike to you.
If you're within the borders of the US, this ability already exists, they have a monopoly on violence in the country, something the government is very eager to demonstrate this year.
And again, as long as backchannels exists in the system to accommodate those without a Government ID, it is possible to get by even if the system tries to cut you off.
Don't you see and understand you already have government ID? You're just calling it by another name...
Do you seriously not get it yet? You have IDs now, and you claim those backchannels exists now, and haven't been cut off. Why would calling something something else suddenly make those backchannels be cut off? How come they exists today in the first place then?
I have not seen a definition of this that is simultaneously true and useful
The sole provider of violence in the U.S. is not the government.
Of course many engage in "violence", or "provide it", that is not in doubt.
In the U.S. I can lawfully use violence in many ways under many circumstances. I.E. if you’re in my house and I didn’t invite you there, I can slay you lawfully.
In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
Yes, and you can do so, because the government and state says it's OK to do so. If they didn't, it wouldn't. This is the core idea.
> In the U.S. the federal government is not the only institution responsible for law making or law enforcement. It is not only entity that can lawfully use violence. Etc.
Hence the whole "sole arbiter of" and last paragraph in my last comment. All those entities are "allowed to use violence" because your government says it's OK.
I don't know if you're in the US, but that's simply not how our Constitution works. "Monopoly on violence" is just something some people made up. It's meaningless, just some empty words on paper.
(Which is also true for the Constitution itself, of course. But if you're talking about the theoretical and philosophical basis for lawmaking in the US, that's what determines both. Theoretically.)
In any case all the old gods are dead or dying, including old ideas of statehood, so enjoy the ride, everyone.
There are clear counter examples to your statement in the U.S.
States are not “allowed” to use violence because the Federal government says it’s okay. States have a right to create and enforce laws.
This is because the US made a critical flaw by tying the authentication and authorization tokens into one single token - your driving license/ID. They should be separate things. Your authentication token (who are you?) should have your picture and be forgery resistant. Your authorization token (what can you do?) should be a piece of plastic with zero pictures (like your insurance card). Did you get stopped for DUI? The officer takes your authorization token, instead, the officer confiscates both tokens and hands you a paper receipt.
The FAA does it the smart way, your authorization token (pilot's license) has no photo. You do something stupid, the ATC tells you to "call this number" and if it is really badly stupid, then the local FAA person confiscates your authorization token.
What would happen today if your government revokes a SSN which is your de facto "personal identification number" today? Can you still rent/buy a home? Can you have a job?
But while cash is printed (physical currency): Not having an SSN becomes a major impediment but not impossible to make transactions and survive.
Our migrant workers—who are basically carrying white collar workers like me—are proof of this.
Point is, the US already basically have a de facto "ID card", they just don't call it as such (yet?), so claiming somehow correctly labeling this thing would make things worse or more difficult, doesn't make much sense.
That can be a military id, passport, NEXUS card, DL, state ID.
If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).
We'll get there eventually, but not before we try everything else first.
"They can already send a drone to watch you and track your cell location and, and, and, why does it matter if they also slap up a million AI powered cameras?"
The comprehensiveness of the system matters.
This is Chesterton’s Fence.
https://en.wikipedia.org/wiki/G._K._Chesterton#Chesterton's_...
What attributes should require proof? Where do you draw the line?
Age?
Gender?
Race?
Religion?
Political party?
Citizenship?
> We'll get there eventually, but not before we try everything else first.
We got here by trying everything else first.
The “good old days” are now. Thousands of years of progress and blood delivered our liberal societies. Don’t give it up so easily.
Really, the broader point is I'm tired of giving away massive chunks of my PII (SSN, DL copies, etc) instead of just having something from the government that will say "Yep. He is who he claims."
If we, collectively, decide we need age-gated websites, then let's enable that properly. I shouldn't have to give NYT a scan of my DL and my SSN to gain access.
We haven’t decided this.
> having something from the government that will say "Yep. He is who he claims."
You’re literally trading liberty for convenience.
I understand your position. I just fundamentally disagree that the tradeoff you are so eager to make is worthwhile.
The EU/EEA is rolling out a digital identity mechanism with interoperable wallets that can hold any range of identity documents and other credentials. You don't need to pick a single wallet provider - several EU countries are approving multiple, including private providers. You don't need to standardise on a single ID.
This is already the case for many already in-use ID solutions in Europe. E.g. in Norway, there are at least 3 signing providers, and only one provider is government issued - the by far most popular (BankID) is private. You identify yourself to the provider when requesting issuance, not to the government (unless you sign up with a government provider).
AFAICS from the other side of the pond, United States Government can track people well enough even without a national ID card. They have successfully worked around that problem.
So, it's a moot point now. No?
There is no reason a digital equivalent can’t be made using the passport system, and it can be left optional, just like passports are optional.
"Border controls aren’t supposed to exist between EU member states – that’s the promise of the 1985 Schengen treaty. Yet today, travelers routinely face checks when crossing borders within the [European] union"
https://euobserver.com/198454/law-professor-sues-germany-for...
EU did border checks without digital IDs being a thing, so why couldn’t US states do a border check without digital IDs?
Digital IDs are not a causal factor for these concerns, seeing as how those government abuses already happen without digital IDs.
The GDPR in a nutshell......
Unnecessary personal data is a liability.
In the US, courts have ruled that the compiler of data owns all that data - you have no control about data about yourself (except in a few legal categories like credit reporting). Some of these old court rulings covered telephone books and business directories.
> Unnecessary personal data is a liability.
Absolutely.
I wish it would be more enforced and controlled tho.
Everyone just gets away with everything.
Recently a bit dutch ISP was hacked and it turned out they kept millions of former customers' details way way beyond any normal lifecycle term. People were still in there that hadn't had anything to do with that company for a decade. This is illegal in the EU but even after this practice was exposed by the leak, the personal data authority just let it all slide.
They also sent out a press release pooh-poohing the consequences for affected (ex-)customers and all they did in compensation was to give a "free" antimalware subscription that was basically advertising just like the few months of mcafee crap you get with a new computer. But all we get from regulators and politicians alike is crickets.
Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?
Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?
Hm.
But it has to be freely given. "Give permission or you can't use this service" is not ok for data that isn't required to provide the service.
If the purpose wasn't "we keep to resell it later" it's likely illegal.
Well, "illegal" given that this type of criminality is pretty much ignored (I've been fobbed off by the regulator after pointing a systematic law-breaking by a $company many many many times. Still better than not having this).
Just locate a prosecutor.
Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.
Correct, like being criminally negligent of a child, if you leak data through long-known vectors (for argument’s sake), one could argue you are criminally negligent in securing the private data.
It doesn’t really go that way, often, now.
It could, as more e.g. water treatment and energy providing facilities get pwnd.
Good luck arguing against their conviction rate.
18 U.S.C. § 1028 makes certain transfers involving identification documents criminal. It specifically covers a driver's license or personal identification card and provides enhanced penalties for transferring such documents.
1028 expressly recognizes electronic transfer as satisfying its interstate-commerce requirement.
What are you talking about?
This means the police don't get involved. The only thing you need is a tort lawyer willing to take a share of the damages. Also, a data breach is proof that you possessed the data.
A business wouldn't be able to reduce their liability exposure to zero, but to an acceptably low level, for instance by actively erasing the data before a breach can occur.
Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.
Part of the attack was physical, aka skimmers. I still remember the relatively elegant inspection tool blogged by Target Tech on HN 3 years ago:
Target's EasySweep – Simplifying Skimmer Detection: https://news.ycombinator.com/item?id=36788831
How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out).
Heartland - #19, Target - #20 at:
https://www.upguard.com/blog/biggest-data-breaches-us
You may notice that the poster of the comment you are responding to is mentioned a lot on that page.
So most businesses are not permitted to just delete the data.
Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.
Not in the US, but in Spain, police gets this data real time when you rent a car or check in to a hotel.
This is of course important for protecting you.
Well, that's very kind of them. I am constantly impressed at the kindness of our governments, and the recent growth of that kindness. I guess that, with all of the power that modern technology is giving them, they're finally getting to live out their heart's desires of being very, very kind.
There can be a discussion about retention periods and the like but too short a retention period amounts to "trust us bro" in the eyes of some un-feeling government agency who is trying to screw you either at the behest of the law or at the behest of whoever hates you and has their ear.
Something needs to be done but "just delete it after you've verified it" is not workable at scale. Yes I know it worked fine for brick and mortar forever. Maybe some acceptable technical solution could be reached, idk.