Digital identity cards: Estonia takes the plunge
economist.com
economist.com
A National ID Card Wouldn't Make Us Safer
- Bruce Schneier
https://www.schneier.com/essays/archives/2004/04/a_national_...
> But my primary objection isn't the totalitarian potential of national IDs, nor the likelihood that they'll create a whole immense new class of social and economic dislocations. Nor is it the opportunities they will create for colossal boondoggles by government contractors. My objection to the national ID card, at least for the purposes of this essay, is much simpler:
> It won't work. It won't make us more secure.
It's hard to see how a decently-implemented electronic ID wouldn't at first seem to be significantly more secure than the current mix of services that exist at the moment. Think how much havoc a determined individual (who knew and hated you) could cause if they were determined to usurp or disrupt your identity: I'm pretty sure all kinds of government and private services could be diverted with phone calls, lies and trivially-forged paper documents.
On the other hand a central system has the risk of all the data being stolen, sold or subjected to denial of service. It's a difficult thing to weigh up.
The failure modes Scheier describes would still be applicable, of course. But as a developer, I might still appreciate having the system available. I couldn't trust its responses beyond a reasonable doubt. But still it might be valuable to have some extra degree of certainty about a user's identity, in some scenarios.
Let's say, for example, I'm developing an online liquor store. Let's say I accept various forms of payment, some of which don't come with age verification. I might appreciate a simple, unified ID API for that purpose. Granted, it would still be possible for minors to exploit the vulnerabilities Schneier describes and buy alcohol from me. But conceivably, if that happened, the law might grant me immunity, because I checked against the government API and the failure was on the government's part. Which would be a valuable assurance for me as the developer or business owner.
I wish my country emulated this instead of having this corporate conglomerate that takes major cash to let anyone use the same system as is used for banking identification.
The company that produced the solution Telia used have exited that market (and focus on providing smart card solutions for companies and organizations like the public care providers).
False! If someone has access to your Estonian ID card for about 11.5 hours or 27 hours (depending if the card uses 1024-bit or 2048-bit RSA keys), he can decrypt documents or forge e-signatures, even without knowing your PIN code: https://eprint.iacr.org/2012/417.pdf
More tech details about the card: https://www.opensc-project.org/opensc/wiki/EstonianEid
On the other hand, there are lots of apps where you don't really need to be able to verify the end user's identity. Like Twitter. I can imagine a world where such applications require verified ID from all users, just because the government makes it really easy to do so. That would be a big loss for privacy an anonymity. As has been discussed at length elsewhere, providing an anonymous (or pseudonymous) voice for people is one of the Internet's most important function.
How is this different from passports? The government already has your basic information. Why passports and not identity cards? To me, my ID card is like a passport in credit card dimensions.
At any given time less than half of Americans have valid passports.
1) The expanse and culture of the U.S. favors driving cars, so most people learn to drive a car. A driver's license is most people's form of photo ID.
2) A puritanical history makes for strict age limits on alcohol and tobacco; young adults must show photo ID in order to enter many bars and clubs where alcohol is served.
These two factors mean that most Americans have an ID by the time they are 21. In fact, I don't know anyone who doesn't have one.
Your passport can't really be used for online identification. An ID card can. But this also means your online activity can potentially be tracked. Who will have access to this data and for what purpose will it be used? What control will users have over their data? Lot's of peeople (including me) don't trust the competence or goodwill of our governments over such matters.
But there are also many instances where we readily give up some of our most personal information. For example, a lot of European countries require your fingerprints when you apply for a passport. This is stored as biometric information on the passport. When you travel, some countries will also take your fingerprints before allowing you into their country. Many travellers are happy to do that. So yes, when it comes to privacy and identity we often exhibit contradictory behaviour and opinions.
The other issue I see is Estonia/EU doesn't exactly have the most robust freedom of expression:
http://www.article19.org/resources.php/resource/37287/en/eur...
Without that, I'm not sure I'd really want to participate.
"The only thing that saves us from the bureaucracy is inefficiency. An efficient bureaucracy is the greatest threat to liberty."
http://infohost.nmt.edu/~shipman/reading/mckie.html
"The main theme of the two principal Jorj X. McKie stories, Whipping Star and The Dosadi Experiment, is the Bureau of Sabotage, an interesting concept in government that is kind of like a ninja GAO.
The idea is that all governments and other bureaucracies tend to snowball over time, finally becoming juggernauts that crush mere humans unthinkingly. So the Bureau of Sabotage was founded with a legal right to throw wrenches into the gears of bureaucracies. No agency can sabotage the BuSab itself.
So what keeps the BuSab from turning into a juggernaut? Their promotion policy. The way you get promoted is to sabotage your boss."
That sounds like a fascinating set of stories and I'd love to read them.
That said, I have full faith in the corruptibility of human beings to assume that they would find some way to capture that agency too.
Yes, sacrificing privacy and liberty can provide conveniences - this is nothing new; we've known it since Huxley's Brave New World, if not earlier.
That doesn't mean these policies are something we want to emulate, such as their stance on sex trafficking[0], free speech[1], and other human rights. Authoritarian policies like 'national identity' initiatives are very strongly correlated with abuses in human and civil rights.
[0] https://en.wikipedia.org/wiki/Human_rights_in_Estonia#Traffi...
[1] Ibid, http://www.article19.org/resources.php/resource/37287/en/eur...
Well, no, that assertion is a subjective statement, so it's not possible to cite that. (Hence why I didn't - the footnote appears immediately after the portion of text being cited).
The links are intended to demonstrate that there are a number of other aspects of Estonian society that we might not want to emulate. Cherry-picking one benefit would be misleading.
> or "are very strongly correlated with abuses in human and civil rights"
The original sentence was "Authoritarian policies ... are very strongly correlated with abuses in human and civil rights". Would it be clearer if I replaced the word "policies" with "governments"?
Estonia might be an authoritarian hellhole, but I wouldn't say the ID system has anything to do with it. That edit probably would help :)
An interesting point to consider: How would a formalized electronic ID scheme affect our present concerns with respect to governments spying on their citizens? On the one hand, putting everyone's public lives online will make it a lot easier to start aggregating data for unwholesome purposes, and puts everyone's personal information in potentially vulnerable computer systems. On the other hand, there are huge efficiency gains and convenience benefits that come from digitizing everything, and maybe having a government bureaucracy centered around digital records will confer that medium with the level of discretion the bureaucracy currently gives paper records.
1) The underlying identity info such as SSN, photo, name, birthdate, etc. Which most governments already have even without this system.
2) A record of each request from a third party to authenticate a user. E.g. if I user my government ID to sign up for Facebook, that signup event will be logged.
Again, it depends on the implementation. The above two would almost certainly be collected in even the most privacy-respecting implementation. But, it's certainly possible to devise an implementation that enables the government to collect far more.
Exactly as happens when I pay my UK taxes online!
A textbook example of Poe's Law :)
I envision (I'm not the only one for sure) something like the Madison Project [1], i.e., an online voting platform where people can discuss and vote on legislation, regulations, budgets, etc., in their jurisdiction (and submit edits and amendments), while allowing anonymous or pseudo-anonymous participation and allowing people to prove they're electors, political party members, etc., for users' filtering. So we can invest our time and energy in exhausting discussions with anonymous people, knowing they have a stake in the outcome and that we're not wasting our time on a discussion with someone who has absolutely no incentive to seek a successful solution.
This provides a missing piece. Only a government-issued digital ID can provide sufficient reliability and trustworthiness for such an application.
I can't see any byline on the article.
http://estonianworld.com/technology/estonia-works-to-create-...
The level of tracking and privacy violations online is already disturbing and downright creepy
This would take it to a whole new level.
There are other bad things possible, for example, I can already see Media Industry lawyers rubbing their hands, tie National ID cards to ISP database and overnight suing people would become easier.
One for the entity managing your retirement funds, one for the national healthcare, one for the tax filing, one for requesting a certificate etc, one for filing a request with the police etc, one for the city council services, one for the district, one for the region, one for the university, one for the separate agency that manages scholarships etc.
I am, honestly, listing the ones I had to cope with. In my country, each entity manages their own system, with different bugs, varying level of security and screw ups, incompatible data, delays of up to two weeks to receive a PIN when signing up for a new service and the occasional "wait, you are not supposed to exist" moments.
I'd take a unified, compatible multifactor auth system like the estonian one every day. Heck, there was even an OpenID bridge some years ago!
EDIT: it's still up apparently
We already have solid methods for identifying ourselves as the same person as we used to be (various public keys, for example), and if we want to establish a consistent identity across multiple contexts/domains, we also have that option. This really doesn't benefit consumers in any way.
As long as you need to access government services, I'd rather have them be efficient.
My country has had national IDs for close to a century, and they make life a lot easier for databases and programming :)
Strange, from my perspective, this seems like a negative result.
I cannot convincingly prove that I entered any work agreement I did online.
I cannot proove anything anyone committed to online.
Giving any binding signatures online or via mobile?
Any official communications with government services where both sides need to know who the other is, not just who they say they are?
Legally binding online agreements between private parties?
However, there isn't a national identity card scheme, so this will probably be messy.
Why would renting an apartment require an id? Never heard of that, just 2 people coming to an agreement. Quite often nobody asks to see your papers.