Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Obligatory:

A National ID Card Wouldn't Make Us Safer

- Bruce Schneier

https://www.schneier.com/essays/archives/2004/04/a_national_...

> But my primary objection isn't the totalitarian potential of national IDs, nor the likelihood that they'll create a whole immense new class of social and economic dislocations. Nor is it the opportunities they will create for colossal boondoggles by government contractors. My objection to the national ID card, at least for the purposes of this essay, is much simpler:

> It won't work. It won't make us more secure.



I understood this to be something different from what Schneier describes. (Though I could be mistaken.) I took this to be primarily an API for Internet applications to verify an end user's identity claims. I realize there are physical cards involved, and those could be problematic, but the API part sounds better.

The failure modes Scheier describes would still be applicable, of course. But as a developer, I might still appreciate having the system available. I couldn't trust its responses beyond a reasonable doubt. But still it might be valuable to have some extra degree of certainty about a user's identity, in some scenarios.

Let's say, for example, I'm developing an online liquor store. Let's say I accept various forms of payment, some of which don't come with age verification. I might appreciate a simple, unified ID API for that purpose. Granted, it would still be possible for minors to exploit the vulnerabilities Schneier describes and buy alcohol from me. But conceivably, if that happened, the law might grant me immunity, because I checked against the government API and the failure was on the government's part. Which would be a valuable assurance for me as the developer or business owner.


In Finland we have a system based on authenticating through your bank (TUPAS[1]). It works pretty well, and is easy, at least for the end-user, to use (you just select your bank and get redirected to their login site; the banks system then passes your info to the site). I don't know what kind of requirements there are for businesses to use it though.

[1] http://en.m.wikipedia.org/wiki/TUPAS


Huh? The point of national identity is not to improve safety - it is to improve effectivity. Which it does.

I wish my country emulated this instead of having this corporate conglomerate that takes major cash to let anyone use the same system as is used for banking identification.


Based on your username I'm guessing the country is Sweden. Which corporate conglomerate and which system are you referring to? Telia e-legitimation? BankID?


BankID is the sole player in that market.

The company that produced the solution Telia used have exited that market (and focus on providing smart card solutions for companies and organizations like the public care providers).


If security is the goal of a national ID card, then you're already doing it wrong. Everything. Wrong.


Not security in the sense of tracking people with malign intent, but security of the identity system against attacks and fraud.

It's hard to see how a decently-implemented electronic ID wouldn't at first seem to be significantly more secure than the current mix of services that exist at the moment. Think how much havoc a determined individual (who knew and hated you) could cause if they were determined to usurp or disrupt your identity: I'm pretty sure all kinds of government and private services could be diverted with phone calls, lies and trivially-forged paper documents.

On the other hand a central system has the risk of all the data being stolen, sold or subjected to denial of service. It's a difficult thing to weigh up.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: