My multiples

Greyscale backing image
[Dave Birch] I watched a strange TV show on a plane back from the US. I was about a woman with “Multiple Personality Disorder” (remember that book Sybil — not the one by Benjamin Disraeli — from years ago). I make no comment about whether the disorder is real or not (the TV show wasn’t that interesting) but there’s no doubt in my mind that when it comes to the virtual world, multiple personalities are not only real, but desirable.

Here’s a good reason for not having your Facebook account in your real name (as I don’t):

Five interviewees who traveled to Iran in recent months said they were forced by police at Tehran’s airport to log in to their Facebook accounts. Several reported having their passports confiscated because of harsh criticism they had posted online about the way the Iranian government had handled its controversial elections earlier this year.

[From Emergent Chaos: Fingerprinted and Facebooked at the Border]

I’ve already created a new Facebook identity and posted a paen to Iran’s spiritual leaders just in case I am ever detained by revolutionary guards and forced to log in. But will this be enough? Remember what happened to film maker David Bond when he made his documentary about trying to disappear? The private detectives that he had hired to try and find him simply went through Facebook:

Pretending to be Bond, they set up a new Facebook page, using the alias Phileas Fogg, and sent messages to his friends, suggesting that this was a way to keep in touch now that he was on the run. Two thirds of them got in contact.

[From Can you disappear in surveillance Britain? – Times Online]

So even if you are careful with your Facebook personalities, your friends will blab. As far as I can tell, there’s no technological way around this: so long as someone knows which pseudonym is connect to which real identity, the link may be uncovered. Probably the best we can do is to make sure that the link is held by someone who will demand a warrant before opening the box.

Criminal inconvenience

Greyscale backing image
[Dave Birch] It was identity theft week, or something like that, and since I’m about to start the CSFI’s 2010/2011 Research Programme into “Identity in Financial Services”, with support from Visa Europe, I’ve been thinking about the key aspects of the problem. For example: how well are current know-your-customer procedures working? After all, they are pretty stringent. To the point where the typical customer finds dealing with financial services organisations an absolute nightmare.

The ID banks require is getting beyond a joke. I’ve just been locked out of one of my online accounts, through no fault of my own, and they’re demanding I send them a certified document plus a utility/bank bill, but they won’t accept one printed online. Yet like many people, both for the environment and ease, I opt for paperless billing wherever I can, so I simply don’t get any printed statements anymore, leaving me at an ID disadvantage when banks refuse to count those as ID.

[From Martin Lewis’ Blog… | The bank ID farce: online accounts don’t accept online statements]

Still, I’m sure we’d all agree that it’s worth the massive imposition on customers, and the massive costs to companies, in order to crack down on ne’er-do-wells who are trying to defraud our banking system (at least, the ones who don’t work for banks). But since identity fraud appears to be at record levels, either these stringent controls are counter-productive (because only criminals will bother jumping through the hoops) or a total waste of money.

Drawing upon victim and impostor data now accessible because of updates to the Fair Credit Reporting Act, the data shows that identity theft impostors supply obviously erroneous information on applications that is accepted as valid by credit grantors. Thus, the problem does not necessarily lie in control nor in more availability of personal information, but rather in the risk tolerances of credit grantors. An analysis of incentives in credit granting elucidates the problem: identity theft remains so prevalent because it is less costly to tolerate fraud. Adopting more aggressive and expensive anti-fraud measures is extremely costly and jeopardizes customer acquisition efforts.

[From SSRN-Internalizing Identity Theft by Chris Hoofnagle]

Given the amount of trouble I find in accessing my own accounts — I tried to log in to my John Lewis card account this week and it asked me a password that I’d forgotten and when I followed the “forgotten password” link it asked me for a secret word or something that I didn’t even know I’d set — I can only assume that the total amount of time, effort and money wasted on this sort of thing across the financial services sector as a whole is enormous.

Share and share alike

Greyscale backing image
[Dave Birch] I’m not sure if it was a good idea to have National Get Online Week at the same time as National Identity Fraud Prevention Week and at the same time as announcing record identity fraud figures!

The National Fraud Authority (NFA) said fraudsters who stole identities had gained £1.9bn in the past year. Their frauds had affected 1.8 million people, the NFA estimated.

[From BBC News – Identity fraud now costs £1.9bn, says fraud authority]

As Philip Virgo notes, there appear to be some conflicting messages here and there may be some danger of a lack of strategic co-ordination.

Just after Martha had described her plans to the “Parliament and the Internet” conference last week, those at the session on “On-line Safety” discussed the need to bring the two sets of messages together lest they cancel each other out.

[From Mixed messages: “Get Online Week” v. “National Identity Fraud Prevention Week” – When IT Meets Politics]

I’ve scoured the coverage to find out exactly what it is that the “Get Online” campaign and the “Fraud Prevention” campaign plan to do about identity infrastructure and I’ve looked through the Cabinet Office “Manifesto for a Network Nation” (which does not mention identity or authentication even once) to find out what the British equivalent of the US National Strategy for Trusted Identities in Cyberspace is but I’m afraid I’ve come up with a bit of a blank (although a search of the Get Online Week website did turn up one article that mentioned identity theft in 2008). Perhaps I’m looking in the wrong places and a correspondent can point me in the right direction.

The UK national security strategy that was released last week does at least mention identity theft as a problem (it says that “Government, the private sector and citizens are under sustained cyber attack today, from both hostile states and criminals. They are stealing our intellectual property, sensitive commercial and government information, and even our identities in order to defraud individuals, organisations and the Government”) but doesn’t actually mention identity or authentication, nor does it put forward any suggestion as to what might be done about the problem.

Tripped up

Greyscale backing image
[Dave Birch] Many people have a real problem with the apparently anonymous nature of the interweb. I say “apparently” because, of course, unless you work really hard at it and really understand how the internet works, and really understand how your PC works, and really plan it carefully, you’re not really anonymous in the proper sense of the word.

Our sense of anonymity is largely an illusion. Pretty much everything we do online, down to individual keystrokes and clicks, is recorded, stored in cookies and corporate databases, and connected to our identities, either explicitly through our user names, credit-card numbers and the IP addresses assigned to our computers, or implicitly through our searching, surfing and purchasing histories.

[From The Great Privacy Debate: The Dangers of Web Tracking – WSJ.com]

I’m surprised that politicians, in particular, who keep going on about how terrible internet anonymity is, don’t understand a little more about the dynamics of the problem. If they did, they would realise that anonymity isn’t what it seems.

You might think, after enough major stories about “IP addresses” hit the news wires, everyone in political life would be aware that “anonymity” on the Internet is limited.

But someone in Sen. Saxby Chambliss’ (R-GA) office didn’t get the memo. In the aftermath of this week’s failed vote on the military’s “don’t ask, don’t tell” policy, someone named “Jimmy” registered an account at the gay news blog Joe.My.God. just to say, “All Faggots must die.”

[From Outed! Senate staffers, anti-gay slurs, and IP addresses]

In the general case, you are not anonymous on the interweb, but economically-anonymous, which I propose to label “enonymous”, and that’s not the same thing at all. If you threaten to kill the President, you will be tracked down, and the state will spend the money it takes on it. But if you call Lily Allen a a hereditary celebrity and copyright hypocrite (not my own views, naturally) then it’s not worth the state’s money to track you down. If Lily wants to spend her own money on tracking you down and taking a civil action for libel, then fair enough, that’s the English way of limiting free speech. If the newspapers want to spend their own money on it, fine. For issues of great national interest, such as spurious death threats to the nation’s sweetheart, Cheryl Cole, The Sun can step in.

Yesterday The Sun traced the sender of a chilling anti-Cheryl message that blasted her over Zimbabwean Gamu’s TV exit. Wannabe rapper Sanussi Ngoy Ebonda, 20, admitted penning the sinister rant, which accused Cheryl of “da biggest mistake of your life” and included a threat to attack other girls sharing her name.

[From Cheryl Cole boosts security at mansion | The Sun |Showbiz|TV|X Factor]

So even though there’s precious little anonymity, should we allow enonymity to be the norm? There are plenty of people who think not, and they’re not all English libel lawyers. Surely common sense is on their side? Isn’t it wrong to let people hide behind pretend names?

Let’s focus on a specific and straightforward example. The comment pages on newspaper, magazine and other media web sites. Many such sites require registration but are still essentially enonymous. Is it right that enonymous commenters can say bad things about celebrities, politicians, business leaders? Would people be as horrible about public figures if they were forced to identify themselves?

Would the online debate among commenters be stifled by requiring commenters to sign their real names?

[From What did you say your name was? | Analysis & Opinion |]

The Chinese government certainly hope so.

China is considering measures to force all its 400m internet users to register their real names before making comments on the country’s myriad chat-rooms and discussion forums, in a further sign of tightening controls on freedom of speech.

[From China to force internet users to register real names – Telegraph]

We already know this doesn’t work, incidentally, because the Chinese already tried this for Internet cafes, supposedly to deal with the problem of young people spending too much time in virtual worlds. The only result was an instant, and profitable, black market in ID card numbers, whereby kids would get the ID numbers of people who weren’t going to play in cybercafes (eg, their grandparents) and used them to log in instead of using their own. There was an alignment of economic incentives here, because the cybercafes would not make money by turning people away.

Cafés that did not ask for identification often still had a registration book at the front desk, in which staff members were seen to write apparently random identification numbers and names during their free time.

[From HRIC | 中国人权]

Incidentally, another large and well-known country closely associated with our economic future (albeit a virtual one) has just abandoned plans to try and force Chinese-style real-name registration after a revolt by citizens (well, subscribers):

Blizzard has reversed a controversial decision that would have forced thousands of Starcraft and World of Warcraft (WoW) players to use their real names on the company’s online forums

[From Blizzard stands down over forum controversy | TG Daily]

I simply would not allow my kids to log in with their real names. I’m happy for them to log in using one of their multiple e-mail addresses. They’ve had pseudonymous e-mail addresses since they were old enough to go online. This isn’t just paranoia about people grooming children for sexual exploitation (the UK takes this kind of thing very seriously) and such like. There are lots of really good reasons for not wanting to use your identity in online debate and comment. I wrote once before about being shocked by some hate e-mails I received when I once posted some comments in a discussion about interest rates (“interest is the work of the devil”, “we know how you are” etc etc). Now, I still enjoy participating in online debates, but do so pseudonymously: my friends know who I am.

That, incidentally, may not be much of a protection, because the mapping of social graphs can soon locate you within a group of friends even if none of those friends disclose who you are. A determined third-party can learn very interesting things from those graphs and, unless everyone is anonymous or pseudonymous under certain conditions, figure out who you are.

Iran appears to be in two minds about whether to embrace or stymie technological progress. On the one hand, Twitter accounts helped the opposition mobilise demonstrations in the wake of last year’s contested presidential election… On the other hand, by monitoring Twitter traffic, Tehran was able to identify who was organising the protests.

[From FT.com / FT Magazine – Who controls the internet?]

As I’ve said before, in cyberspace no-one knows you’re a dog, but no-one knows you’re from the FBI either. Thus our government, the US government and many others are caught in two minds, just as the Iranians are. On the one hand, they are supposed to be in favour of free speech, but on the other hand, well, you know Danish cartoonists, criminals, child pornographers, terrorists, enemies of the state, dissidents, apostates etc.

Now, maybe you don’t care. You’re “not doing anything wrong.” Well, Hoder wasn’t doing anything wrong when he went to Israel and blogged about it in Farsi. But he’s serving 20 years in jail in Iran.

[From Emergent Chaos » Blog Archive » AT&T, Voice Encryption and Trust]

But back to online commenting in our democracy. It’s not a simple issue, and “common sense” is not a good guide to anything in the virtual world, but it is clearly the case that in that virtual world some people behave inappropriately. You only have to read The Guardian newspapers online “Comment is Free” or Guido Fawkes, the UK’s top political blog, to see how appalling, disgusting, racist, misogynist, anti-semitic and just plain thick the general public can be. I am one of those old-fashioned liberals who thinks that the response to bad free speech should be more free speech, not less. I think we should be wary about limiting the anonymity of people who comment online, even if we could think of a way of doing so.

The Nazareth District Court has upheld the right of the Walla Web portal to refuse to hand over the IP addresses of commenters accused of defaming a journalist.

“The good of online anonymity outweighs the bad, and it must be seen as a byproduct of freedom of speech and the right to privacy,” Judge Avraham Avraham wrote in his ruling last week.

The court also said the critical remarks concerning Yedioth Ahronoth reporter Israel Moskovitz, posted online in 2008, were unlikely to harm his reputation since they were poorly written and appeared only once, and readers were not likely to take them seriously.

[From Uphold talkbacker’s anonymity in defamation trial, court says – Haaretz – Israel News ]

Actually, for journalists to complain about online comments, criticism and even abuse is a tiny bit worrying, since their business depends on such.

It doesn’t take long to find articles on CNN that quote anonymous officials. For them to rage against “cowards” who won’t stand behind what they say, and then to regularly quote “anonymous” sources, seems pretty damn hypocritical. Phillips claims anonymity online is “very unfair.” Phillips also attacks the media for “giving anonymous bloggers credit or credibility.” But again, CNN quotes all kinds of anonymous sources all the time.

[From CNN Claims ‘Something Must Be Done’ About Anonymous Bloggers | Techdirt]

On balance, then, I think a free society not only permits certain kinds of anonymity but actually depends on them, because we need informed and honest public debate to function properly. This was well-put in the Washington Post recently.

For every noxious comment, many more are astute and stimulating. Anonymity provides necessary protection for serious commenters whose jobs or personal circumstances preclude identifying themselves. And even belligerent anonymous comments often reflect genuine passion that should be heard.

[From Andrew Alexander – Online readers need a chance to comment, but not to abuse]

I couldn’t agree more. However, as the Post goes on to note, we have to recognise that people can be pretty horrible and we need a way to deal with that. Not banning anonymity, but managing the anonymousness (if there is such a word) in a better way.

The solution is in moderating — not limiting — comments. In a few months, The Post will implement a system that should help. It’s still being developed, but Straus said the broad outlines envision commenters being assigned to different “tiers” based on their past behavior and other factors. Those with a track record of staying within the guidelines, and those providing their real names, will likely be considered “trusted commenters.” Repeat violators or discourteous agitators will be grouped elsewhere or blocked outright. Comments of first-timers will be screened by a human being.

[From Andrew Alexander – Online readers need a chance to comment, but not to abuse]

This — in essence, baby steps toward a reputation economy — could be toughened up by using better identity infrastructure, but it’s not a bad place to start. But there are areas where the better infrastructure is more of a priority. Newspaper comments are one thing, but there are businesses that depend on online comments, and a good example is the burgeoning group review sector.

SEPAarate development

Greyscale backing image
[Dave Birch] There is a looming deadline for SEPA compliance in the cards business: by 31st December 2010, all payments cards and ATM cards in the EU27 plus Norway, Switzerland, Iceland, Liechtenstein and Monaco must be EMV-compliant and all POS and ATM terminals in those countries must support EMV applications. This is extremely unlikely to happen as far as I (and other observers) can see. Currently Germany, Portugal, Italy and Slovenia have less than 80% of their cards converted and Romania, Greece, Bulgaria, Hungary, Spain, Portugal and Malta have less than 40% (according to Banking Automation Bulletin for September 2010). Apart from the UK & Ireland, France and Luxembourg, no countries have 100% POS compliance (in Germany it's not even 10%). Additionally, many countries do not have ATM compliance, including Germany, Belgium, Italy and Portugal.

Why the slow progress? And what does it mean for the future? Well, I was invited along to a meeting of experts to discuss the progress towards SEPA and eSEPA (SEPA for the internet and mobile payments), but unfortunately I've been told by the Commission that the discussions were confidential and so I can't comment on them here.

It’s not all sexy stuff

Greyscale backing image
[Dave Birch] I’m giving a talk on identity services as a potential new business for mobile operators, and I’m trying to make the point that there are routine, everyday, prosaic applications for this kind of thing: it’s not all about opening bank accounts and reporting deaths. Every single day I take part on transactions that are made complicated, expensive and unsatisfying because of the lack of an identity infrastructure. How many times in an average week do you press the “forgot your password” button? I do it all the time. Here’s the standard pattern:

1. Get e-mail from British Gas asking for a meter reading (we still have dumb meters — more on this in a future post).

2. Read meter.

3. Click on link in e-mail to submit reading.

4. It asks for e-mail address and password, so enter e-mail address and then click on “forgot your password”.

5. It says I’m not registered, so then I have to go and register. I use the same password that I use for everything else.

6. But my password has to be between 8 and 16 characters (they take security seriously) so then I have to think of another one (which I am certain to forget again next time).

6. Then I can log in and give the reading.

7. But I get “We’re sorry but access to your online account is temporarily unavailable. Please try again in a few minutes.”

8. Next day get an e-mail from British Gas apologising for problems with online system. (This isn’t really anything to do with identity, but it was nice of them, so I thought I’d report it.)

The process should have been:

1. Get e-mail to remind me to read meter (British Gas must have my e-mail on file somewhere to do this).

2. Read meter.

3. Clink on link in e-mail to submit reading.

4. Since the system knows the e-mail address it can prefill this and then ask for my login code from my Barclays dongle (or mobile phone, or whatever).

Bingo. Secure log in, with no effort, since my card and dongle are next to the computer.

Incidentally, and apropos of nothing, I was curious why the system was a bit crap, so I googled British Gas CRM to see if other customers were complaining, and I found this:

A good CRM system can provide automated, reliable and accurate billing and cope with high levels of customer switching and multiple service offerings. This is what British Gas set out to do with Project Jupiter in 2001, when it commissioned Accenture to install a new £317 million SAP billing system. Unfortunately, the well-documented problems with Jupiter resulted in a spike in customer complaints, loss of market share and a £182 million legal battle between British Gas and Accenture that looks set to rumble on for several years.

[From British Gas sorts out billing issues and prepares for smart metering – Interviews – Features : Utility Week]

Anyway, back to the topic. We must, as a matter of urgency, start moving to an identity and authentication infrastructure that puts a stop to this time- and money-wasting replication at every service provider.

Market failure

Greyscale backing image
[Dave Birch] I was in a meeting today discussing some ideas for introducing a sort of trust service, that could fit in a framework along the lines of NSTIC but as a commercial proposition. You know the general idea: a private-sector, for-profit issuer of trust identities. The customer and the segment aren’t relevant (and I wouldn’t tell anyway), but I wanted to reflect back something I was thinking about the market. The idea that I was involved in exploring assumes, as do many similar ideas, a “two-sided market”.

In this market paradigm users and relying parties both interact with each other with the help of a platform. The platform (e.g. single players like Facebook/Google/ Paypal/etc or a network of cooperating parties) optimizes both the proposition towards users and the relying parties. The relying parties are business (including banks) and governments, all with clear business needs: relying parties achieve better e-services for their customers and lower cost of operation… If there is value, a market can come and the growth will come by itself when the trust is organized properly. It’s just a matter of getting the industry act together.

[From Innopay – Payment Consultants – home]

The problems that “e-identity” businesses might try and solve fall into the this two-sided (aka “chicken and egg”) structure, and this has so far proved a barrier. This isn’t because there aren’t problems to solve: here’s some examples of how straightforward the business problems are.

  1. I wanted a new credit card from a UK card issuer and I couldn’t use my Barclays Bank “identity” to get it. Surely this should be one of the simplest problems to solve? I just called John Lewis to find out why a chip and PIN transaction in Waitrose had been declined (a problem with the network apparently) and it took me longer to “log in” than to deal with the issue: I had to punch in my card number, date of birth, last 4 digits of phone number and then when I got through to person I had to give my name and the first two letters of my secret word. Surely card number followed by CAP/DPA OTP is all that is required?
  2. I can’t use my Barclays identity to log in to Barclaycard.
  3. The British government presumably trust Barclays, since they regulate them, but when I log on to sort out taxes or get my car tax I have to use completely different username/password combinations (ie, no security) instead of just linking my government “identities” to my Barclays identity for authentication purposes.

So despite having all of the technology already in place and deployed, there is no functioning two-sided market. I wonder if it’s because it’s just too complicated to either explain to senior management or make it accessible to the general public?

Listening in

Greyscale backing image
[Dave Birch] Who should we be listening to when formulating digital identity strategy? Consumers? Experts? Politicians? Lobbyists? Consultants? Consider, for example, the issue of privacy. This is complicated, sensitive, emotive. And some of the voices commenting on it are loud. Take a look at the “Wal-Mart story” — the story that Wal-Mart are going to add RFID tags to some of their clothing lines — that has naturally attracted plenty of attention. One particular sets of concerns were founded on the idea that consumers could not have the tags “killed” and so would be tracked and traced by… well, marketeers, advertisers, sinister footsoliders of the New World Order, the CIA and so on. So what is the truth?

The tags are based on the EPC Gen 2 standard, which requires that they have a kill command that would permanently disable them. So the tags can, in fact, be disabled. Wal-Mart does not plan to kill the tags at the point of sale (POS), only because it is not using RFID readers at the point of sale.

[From Privacy Nonsense Sweeps the Internet]

As a consumer, I don’t want the tags to be turned off, because that means that the benefits of the tags are limited to Wal-Mart and not shared with me. I’d really like a washing machine that could read the tags and tell me if I have the wrong wash cycle. And there are plenty of other business models around tags that might be highly desirable to consumers.

If it adds £20 to the price of a Rolex to implement this infrastructure, so what? The kind of people who pay £5,000 for a Rolex wouldn’t hesitate to pay £5,020 for a Rolex that can prove that it is real. Imagine the horror of being the host of a dinner party when one of the guests glances at their phone and says “you know those jeans aren’t real Gucci, don’t you?”. Wouldn’t you pay £20 for the satisfaction of knowing that your snooping guest’s Bluetooth pen is steadfastly attesting to all concerned that your Marlboro, Paracetamol and Police sunglasses are all real.

[From Digital Identity: The Rolex premium]

So does the existence of convenience, business model, consumer interest and practicality mean I have no privacy concerns? Of course not! So what is a reasonable way forward?

Wal-Mart is demanding that suppliers add the tags to removable labels or packaging instead of embedding them in clothes, to minimize fears that they could be used to track people’s movements. It also is posting signs informing customers about the tags.

[From Wal-Mart to Put Radio Tags on Clothes – WSJ.com]

That seems like a reasonable compromise: make it easy for people to cut the tags off if they don’t want them. So is that the end of the story? I don’t think it is.

What could possibly violate our privacy with tracking pants in a store to make sure there aren’t too many extra-large sizes on the shelves?

[From Privacy wingnuts « BuzzMachine]

The thing is, I agree with Jeff Jarvis here that some people are, indeed, “wingnuts”. But that does not mean that there are no genuine concerns and it does not mean that anyone who is concerned about privacy (eg, me) is a wingnut. But what it does mean, I think, is that we need to implement new identity technologies in a privacy-enhancing fashion and make the “privacy settlement” with the public more explicit so that there is an opportunity for informed comment to shape it. It seems to me that some fairly simple design decisions can achieve both of these goals, something that I’ve referred to before when using Touch2id as an example.

There has to be a reason for this

Greyscale backing image
[Dave Birch] The German personal identity card is being introduced with an online framework. The eCard-API framework — which is essentially collection of standards for services including e-passport, e-health and so on — means that e-commerce, e-banking and e-government will be able to use the card to provide secure services to the public (although note that these third-party service providers will not have access to the on-card biometrics). The cards have a contactless interface: to use them online, customers will have to buy a USB contactless reader to plug in to their PC and then download the free “Burgerclient” software. Service providers who want to access data on the card have to mutually-authenticate, which means that they must present the card with a valid permission certificate (they get these from accredited certificate service providers, known as “Trust Centres”). If service providers want the use the card in a transaction, the customer must first confirm what data is beign read from the card then authenticate with a six digit passcode, thus providing convenient 2FA for online services.

SCM’s RFID-based contactless card readers form the core of Secure IT Kits that the German government will make available without charge to citizens, through its suppliers, to encourage the use of the electronic ID cards.

[From Global IDentification: SCM Microsystems to supply German eID readers]

For Martha’s sake! Germans not only get a useful ID card but they get free card readers for their PCs as well. Now that’s what I call a networked nation. Germany has over 70% Internet penetration and, according to BITKOM (the German Federal Assocation for Information Technology, Telecommunications and New Media), five months before the official launch of card more than half of them had already stated that they wanted to use the card for home banking and access to public services. The Brundesdruckerei (Federal Printing Office) has already put forward a plan to allow citizens to load their electronic identities on to NFC-capable mobile phones in the future.

I particularly like the way in which the cards generate per-service provider pseudonyms, so that everytime the customer logs in to, say, Amazon, they would have the same “ID number”, but the bank would see a different number and so would the tax authority or another store or anyone else. This basic partitioning was precisely the kind of intelligent design decision that I would have advised the UK Home Office to adopt, had they asked me.

Germany’s new contactless National Identity Card… sounds rather like what the UK ID card was meant to do, but the policy and politics surrounding it were so poorly conceived and communicated that the concept was never likely to be a success.

[From Electronic ID cards are rubbish? Don’t tell the Germans – Computer Weekly Editor’s Blog]

No! It was not an issue of policy and communication. The UK card was rubbish: it was just a different-shaped passport. You couldn’t use it for e-business or e-commerce or, for that matter, business or commerce. The German card has been designed by identity experts and engineers, not by politicians and management consultants. We Brits didn’t get an API or even a published interface.

Passport minus

Greyscale backing image
[Dave Birch] Pretty much every decision that the British government has made about ID cards has not only turned out to wrong, but almost optimally wrong. The collection of civil servants, management consultants, ministers and special advisors managed to leave us in as bad a situation as when they started — with no national identity management infrastructure — but hundreds of millions out of pocket. There is now a manifesto to get everyone online by 2012, but when they get there they won’t be able to do anything since there’s mechanism to identity or authenticate anyone other than usernames and password, which of course mean a massive increase in identity fraud.

The current coalition are just as bad: they have no strategic vision for identity, no tactics for getting us there and (crucially) no more understanding of the technology than their New Labour predecessors (who, to be fair, didn’t understand the problem either). As Ben Laurie of Google, someone whose opinion I always take seriously, puts it

The trouble with allowing policy makers, CEOs and journalists define technical solutions is that their ability to do so is constrained by their limited understanding of the available technologies.

[From Links]

Quite. And in the field of identity, where “common sense” is an appallingly bad basis for requirements capture, they have even less chance of randomly happening across a workable solution than they do in the fields (pun of intended) of rural payments, where a cool ONE BILLION POUNDS has been totally wasted. The coalition’s decision to simply scrap the ID card scheme was stupid.

Neither the existing scheme nor the Coalition scheme (ie, nothing) actually solve any of the problems that the lack of an identity infrastructure creates and I absolutely predict that the lack of such an infrastructure will in turn create a major barrier to improving efficiency in public services

[From Digital Identity: Back to the future of the ID card]

One of my pre-election suggestions to a couple of relevant “think” tanks was that the ID card should be renamed the Passport Plus, and sold as a revenue-raising £50 optional extra to passport holders: this would be straightforward to implement, since the ID card has no function other than as a travel document in the EU anyway. The wisdom of this suggestion has just come back to bite me.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.