this post was submitted on 07 Aug 2024
512 points (98.5% liked)
Technology
59598 readers
3688 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
How about a government-sponsored, non-profit authentication service? That is, it should be impossible to get a loan, open a line of credit, or anything else in somebody's name, without the lending institution verifying that it's actually on behalf of the named individual. Eliminate the security-through-obscurity technique of using bits of easily-leaked personal information as a poor substitute for actual authentication.
I mean, (as a comparative example) I have to go through an OAuth2 consent dialog to connect a third-party app to my email account, yet somebody can saddle me with huge debts based on knowing a 9-digit number that just about everybody knows? It's the system that's broken, tightening up the laws on PII is just a band-aid.
The US system is broken. I have a tax file number in Australia, which is the broad equivalent of a US SSN, and you know what someone can do with it if they also have my name and DOB? Fuck-all, except file my taxes for me, because you can't use it as an identifier anywhere else than the Australian tax office.
If I want a loan or a credit card or to open a bank account or any number of things , I need enough verifiable documents including photo ID to satisfy the other party that I am really them. Basically it's a points system where any form of government photo ID gives you about 80 points and any other item of identifiable data gives you 10-20 points and usually you have to clear 100 points to be "identified".
So my passport plus my driver's licence is enough. My driver's licence plus my non photo ID government Medicare card or my official original copy of my birth certificate is enough. My driver's licence and two bank or credit cards is enough. About 5 or 6 things like my birth certificate, electricity bills in my name or local government rates notices and bank cards is sometimes enough, although photo ID from somewhere is usually required, or you need a statutory declaration from someone in good standing saying that you are who you say you are.
This kind of thing, while slightly more inconvenient, requires a number of physical items that can't be easily stolen en-masse. I carry enough of them in my wallet that I can do anything I need to do, as my driver's licence provides photo ID. People who don't drive or have a passport can scrape together enough bits and pieces to usually get by.
So it's time for a change. But it doesn't have to involve technology or a huge shift in the way of doing things. It just requires a points system similar to what I describe. Whether the US can effect that change now with the millions of systems that rely on a SSN for a trivial key in a database in some small retailer somewhere, I don't know.
That's basically how it works in the US too. For example, for a form I-9, Employment Eligibility Verification, you need a passport, OR both proof of identity and proof of citizenship: https://www.uscis.gov/i-9-central/form-i-9-acceptable-documents
It's similar for stuff like state drivers' licenses.
The thing is, a federal domestic ID is all but prohibited. We have to have passports for international travel, but too many people are against federal ID because of "muh privacy", even though it means we just end up misusing SSNs and companies like this one compensate by collecting multiple data points on each person.
This so much. In fact, go a step further and have a few competing auth services, with some regulatory oversight for managing that much pii.