9 ms·
Quite a few people who voted against this did so purely because they didn’t want private companies controlling the system. If the proposal had been for the gov
by esja 6y ago
Quite a few people who voted against this did so purely because they didn’t want private companies controlling the system.
If the proposal had been for the government to issue and control the identities, it may well have passed.
- krastanov 6y agoIt does not seem like such a terrible idea if it is government run to me. But it depends on having trust in the checks and balances implemented in your system of governance.
- MeinBlutIstBlau 6y agoIt's fine if a majority of the people can overrule a political policy by a referendum. It's not fine if the government was like the US or China.
- deleted 6y ago[deleted]
- Ericson2314 6y agoYes, and that's a good thing. Balkanizing ID info between a gazillion government databases as we do in the US just creates inefficiency, and raises the thirst for more intensive surveillance to counter the inefficiency with which the data is used. (Consider the talk after 9/11 on the FBI and CIA not sharing info, and then we get the Patriot Act.)
- deleted 6y ago[deleted]
- XorNot 6y agoThat article about effective government policy being a database access policy a month or so ago was particularly illuminating (and made a lot of sense to me). That any given policies effectiveness really depends on whether you can actually construct - functionally - an appropriate database view to implement it's stages.
- jariel 6y agoMaybe the opposite though - having a 'single, semi-competent authority and source of control/failure/security' is probably not a good reality for security and resiliency. Ironically, there's a >50% chance that the solution will entail 1) privately hosted platforms like AWS and 2) privately hosted support services and 3) privately written core modules (McKinsey business strategy, Accenture implemented etc.) and 4) at least some privately contracted IT people to manage the solution. There's no reason to believe the gov. will make a more robust, scalable and secure solution that other entities. A better approach might even be to mandate very specific identity protocols, and then allow citizens to chose their own identity provider among those that fit the regulatory requirements and oversight. For example: https://en.wikipedia.org/wiki/Swiss_Post https://en.wikipedia.org/wiki/Swiss_Post It's owned by gov. and effectively independent. They could be an identity provider. They are already close to being able to do whatever need be done. Having to create new government bureaucracies to do things is hard.
- Ericson2314 6y ago> Ironically, there's a >50% chance that the solution will entail 1) privately hosted platforms like AWS and 2) privately hosted support services and 3) privately written core modules (McKinsey business strategy, Accenture implemented etc.) and 4) at least some privately contracted IT people to manage the solution. That would be in the US, with it's shit managment and governance culture of no expertise being required. The Wwiss are explicitly rejecting such willy-nilly privatization; did you read the article? > There's no reason to believe the gov. will make a more robust, scalable and secure solution that other entities. Again this is US ideology about US government. In another places they have something closer to actual democracy, a robust civil service, and an awareness that some things are too important to risk the profit motive sliding to rent-seeking. > A better approach might even be... I actually agree with you here. The next step after centrally planning how electronic identity should work is to realize many things don't need to require an "official one true personhood" surrogate key, and can make due with something weaker and more friendly to anonymity. The same functioning society that can figure out devolved cantons and federated cooperatives would be excellently prepared to figure that out.
- AnthonyMouse 6y ago> Balkanizing ID info between a gazillion government databases as we do in the US just creates inefficiency It improves security through the reduction in the scope of harm and eliminating single points of failure. If someone compromises your Candy Crush login they can't drain your bank account. > and raises the thirst for more intensive surveillance to counter the inefficiency with which the data is used. (Consider the talk after 9/11 on the FBI and CIA not sharing info, and then we get the Patriot Act.) Your argument in favor of centralized ID is that otherwise nefarious spies will lobby in favor of something equivalent to centralized ID so they can correlate everything? That's the argument against it.
- Ericson2314 6y ago> It improves security through the reduction in the scope of harm and eliminating single points of failure. If someone compromises your Candy Crush login they can't drain your bank account. "Security through ad-hoc redundancy" is going to replace one possible-good auth systems with a gazillion shity ones that no one has the budget or interest to secure. It's a greater attack service. > It improves security through the reduction in the scope of harm and eliminating single points of failure. If someone compromises your Candy Crush login they can't drain your bank account. No, by all accounts FBI and CIA still hate each other and keep secrets. What we got is more surveillance (NSA dragnets), not more efficient use of the data they already have.
- AnthonyMouse 6y ago> What we got is more surveillance (NSA dragnets), not more efficient use of the data they already have. Or we could just not do that anymore and still not have centralized authentication. > "Security through ad-hoc redundancy" is going to replace one possible-good auth systems with a gazillion shity ones that no one has the budget or interest to secure. It's a greater attack service. You mean attack surface. But that's the trade off. Because none of them are actually secure. Even when you have a full time security team, there are still vulnerabilities. Before the attacker had to find a vulnerability at the DMV, then start over at the bank, then start over at every company's file server. Now instead the attacker only has to find one in the central authentication system and they get everything at once. Even if there aren't as many vulnerabilities, if there is even one, you're screwed beyond comprehension across all systems everywhere. On top of that, widespread use cuts the other way. Suppose the system was originally deployed using sha1. That starts looking pretty weak so you begin the decade-long process of transitioning literally everyone to a system using something else. Then suddenly sha1 gets completely broken beyond all hope, but you can't stop using it because 15% of people haven't migrated away yet and that's too much of the world to abruptly cut off. Whereas in the decentralized system only 15% of things would be vulnerable because the other 85% had already migrated and disabled sha1, and the important stuff like banks who have their own security teams would be in the 85%. More to the point, there are other ways to reduce vulnerabilities without centralization. Use simpler, more stable software from vendors who spend more time on security and less time on feature bloat. Restrict local services to local users so they're not exposed to the internet. Use defense in depth so that a single vulnerability is not enough but the expense of finding five stackable vulnerabilities is uneconomically large relative to the value of compromising an individual system. Whereas the only way to avoid the ominously large scope of compromise of centralized authentication is to decentralize it.
- nickez 6y agoIn Sweden we have a company running the ID system and that works fine. The company is coowned by all the large banks afaik. I was really surprised at how far behind Switzerland is compared to Scandinavia when it comes to digitalisation. Being able to handle my life hassle free online instead of going to physical places (like post office, banks, gov office) is liberating. I also get all my bills digitally and all my receipts (even physical stores)
- zo1 6y agoIf you think that's bad, look at the UK. They had a government-ID system with an ID card, and then they scrapped it. Now people run around using driver's licenses and municipal bills (I guess) to open bank accounts and other things. Utterly backwards. https://en.wikipedia.org/wiki/Identity_Documents_Act_2010 https://en.wikipedia.org/wiki/Identity_Documents_Act_2010 I've been formulating my thinking around it and I'm starting to think that this is some sort of new-age "luddism" at play, coupled with some odd distrust of government for this particular problem, as if government is trustable elsewhere.
- deleted 6y ago[deleted]
- katbyte 6y agoWhat did the Goverment ID offer over a drivers license? Here in bc Canada drivers license is sufficient ID most places, and if you don’t drive you get bc Id which is just a drivers license without the driving part.
- robin_reala 6y agoThere is an online identity verification service run by the UK government: https://www.gov.uk/government/publications/introducing-govuk-verify/introducing-govuk-verify https://www.gov.uk/government/publications/introducing-govuk... Verification is done by third-parties in conjunction with government data. At the moment it’s only used for government services, but there has been talk for half a decade about expanding it to the private sector.
- 6y ago
- cmehdy 6y agoWhich makes a lot of sense in Switzerland, since "the government is the people" is more true than in the overwhelming majority of countries on Earth. Pragmatic take from the Swiss as usual :) (said by a jealous French citizen)
- oumua_don17 6y agoAFAIK, Switzerland is the only country with direct democracy or ‘Govt is the people’. As you said overwhelming majority, are there any countries that have direct democracy or come close?
- deleted 6y ago[deleted]
- vinay427 6y agoCalifornia (not a country, obviously) is otherwise virtually comparable with Switzerland in this respect. Full constitutional amendments and legislative vetoes can occur via referendum. EDIT: In practice, larger cities in California seem to have a comparable number of referendums as well. Unfortunately, they're all bundled into an election every 1-2 years rather than the Swiss system of elections every 3-4 months. This has its upsides, mainly in turnout which is still low in much of Switzerland, but also means many "less-notable" issues often aren't discussed in CA to the same degree that they seem to be here.
- sologoub 6y agoNot familiar with the Swiss system, but CA system has some interesting nuances - laws enacted as approved propositions cannot be modified at all, except by another approved proposition. In theory, that protects them from legislative overwriting/meddling, but also does not allow to fix unintended consequences. Here’s an example where a proposition was needed to authorize state legislature to make modifications to an older proposition: https://en.wikipedia.org/wiki/2018_California_Proposition_7 https://en.wikipedia.org/wiki/2018_California_Proposition_7 And of course, CA still has daylight savings time because this proposition required two thirds vote.
- burundi_coffee 6y agoWhich is why the opponents, backed by a non-partisan alliance of representatives, will bring forward not one but two proposals to the houses. If they get a majority vote, the federal council will have to try to make it into a law.
- Shacklz 6y agoDefinitely why I voted against it. When I first heard about it I was all for it - until I realized that the plan was to let private companies handle it. Complete no go, glad it got rejected.
- deleted 6y ago[deleted]
- stjohnswarts 6y agoThey are doing the correct thing then. Prisons, ID, policing NONE of that stuff should ever be in corporate hands. It just stinks of fascism to anyone who really thinks about it for more than a moment. Governments are bad enough, corporations should never take on such roles because then they have a second incentive of profit to be bad actors and not just petty power trips.
- OOPMan 6y agoI don't want to be that guy but it really has nothing to with facism. I suggest you google the definition. It's definitely a bad idea, but just because something is a bad idea does not magically make it facism. If you think stuff like this being okay in the hands of a government then you might want to reexamine that line of reasoning, given that most governments are barely any better than corporations at the end of the day...
- deleted 6y ago[deleted]
- alfiedotwtf 6y agoAnd once everyone forgets about it, a right-wing government will privatise to the same orgs that would have gotten the contracts... it’s just putting off the inevitable :(
- Lukas_Skywalker 6y agoI did vote against it, but mostly for other reasons. The companies (mostly banks and insurances) lobbying for the e-ID have already implemented a similar project called "Swiss-ID" which was supposed to be used across a majority of service providers. From the point of view of the user, it looked and behaved a lot like OAuth. What I am afraid of is that the e-ID will be implemented in a similar way, and data will be stored centrally. That's a big difference to the classic physical ID we have, because while the government controlled some data centrally (name, year of birth etc), no information about banking or illnesses was ever stored in a central place. If there was an indication about how the e-ID was going to be implemented, and if there was a reasonable effort to make sure data is being kept isolated (e.g. by issuing a physical tokens and encrypting the data with them) I might have voted yes. But there was no such information, and I expected the worst.
- tingle 6y agoThat was my rationale for voting "no". The task of deciding who is swiss and who isn't shouldn't be entrusted to some AI running on a facebook server.