8 ms·
This country badly needs a national ID system.
by only_as_i_fall 5y ago
This country badly needs a national ID system.
- jimbob45 5y agoDoes the SSN not mostly fulfill that need? Edit: The SSN seems a lot like JavaScript at this point. Y'all are talking about how you would never use it for anything and yet it's the one thing everyone is using for identity verification these days.
- toomuchtodo 5y agoNo, it doesn't. It's not meant as a secure identifier and it doesn't provide for identity proofing. A national ID systems, as only_as_i_fall stated, is required. A previous comment I wrote on this topic: https://news.ycombinator.com/item?id=28280851 https://news.ycombinator.com/item?id=28280851 Someone in the trenches wrote about it: https://billhunt.dev/blog/2020/12/18/federal-policy-recs/#4-solve-identity-once-and-for-all https://billhunt.dev/blog/2020/12/18/federal-policy-recs/#4-...
- duxup 5y agoI recall an interview with someone in charge of the Social Security Administration about how they were constantly asked about various issues surrounding SSNs and he had to constantly respond "It wasn't meant for this, it wasn't built for it, it's not used in a consistent way that we could do that, and I'm not sure you want the Social Security administration to be in charge of that, that's not what we even do..."
- toomuchtodo 5y agoIndeed. Interestingly enough, they support Login.gov (a USDS/18F/GSA identity project) as an identity provider service [1] :) I keep poking government agencies who don't support it. Some are easier, some are harder. Some I have to go talk to legislators about appropriations to extend their applications to include the support. A necessary schlep. [1] https://secure.ssa.gov/RIL/SiView.action https://secure.ssa.gov/RIL/SiView.action
- ceejayoz 5y agoLogin.gov is shockingly well done. Multiple U2F keys, gives clear reasons why SMS is less optimal than U2F/TOTP, very clear flow.
- deleted 5y ago[deleted]
- tyingq 5y agoThe US Digital Service seems to have benefitted from having real technologists run it. The current leader is Matt Cutts, the former public face of Google's anti-spam efforts for search.
- rbanffy 5y agoI remember in my interactions with the White House petitions site folk (when I worked for Avaaz and helped integrate both systems) always impressed me as being very smart and dedicated. Sadly, at some point (during the Trump administration) I lost my White House Github badge. I thought it was quite cool.
- toomuchtodo 5y agoMatt Cutts’ tenure recently ended, and Mina Hsiang has assumed his role as head of USDS. https://news.ycombinator.com/item?id=28390511 https://news.ycombinator.com/item?id=28390511
- sombremesa 5y agoTo add to this, an SSN seems to be pretty carelessly shared these days — I recently had an interaction with a government official where they just asked me for it, and of course there's plenty of forms both online and offline where you need to share it. If I saw that someone printed a form with their SSN on the office printer and forgot to pick it up, I'd just set it aside without a second thought, because it just isn't something that makes one think "red alarm fire". Contrast this with something like a private key, which never leaves your possession and is never shared directly, just used for signing. Unfortunately most non-technical people have no concept of such a thing, apart from...stamps and seals? The chip on a credit card might count, but it doesn't seem like people care about losing possession of that too much either.
- toomuchtodo 5y ago> Contrast this with something like a private key, which never leaves your possession and is never shared directly, just used for signing. Unfortunately most non-technical people have no concept of such a thing, apart from...stamps and seals? The chip on a credit card might count, but it doesn't seem like people care about losing possession of that too much either. So, consider how Apple is about to handle state IDs and driver's licenses with iOS 15. It's what you describe, mostly. Not a private key, but identity built on crypto, with a UX that doesn't suck. We're getting there. https://9to5mac.com/2021/07/27/ios-15-apple-implementing-security-verification-with-selfies-to-validate-id-cards-in-the-wallet-app/ https://9to5mac.com/2021/07/27/ios-15-apple-implementing-sec...
- sonicggg 5y agoIt was never meant to be used as such. Its adoption as an identifier is the worst "hack" I've seen. I hate how businesses trust it as sort of some password. It's ridiculous how much damage a scammer can do by using your SSN. Like it's a freaking plain text number. At this point it really should not be used for anything at all, and we should just assume that our SSN is public knowledge. I think we have the technology and means to come up with something better.
- GeneralMayhem 5y agoAbsolutely not. An SSN is at best a username. It's not a password. It doesn't even have a checksum in it - my library card number is is literally more secure than my SSN.
- ironmagma 5y agoWe use it for identification because there’s no alternative. Hence the suggestion to create an alternative.
- ajsnigrutin 5y agoWhat happens when someone hacks some government database and leaks the whole "first name - last name - ssn" datbase?
- jeffbee 5y agoWe do need one, yes, but realistically we'd have to delay the requirements for presenting one until something like 99.9% of people could be shown to have been issued one. Otherwise it's not really fair and would be a huge lever for abuse. This always comes up with identification requirements for voting. It seems superficially reasonable to require them, especially if you are looking at it from abroad, or if you are pretty young. But the fact is that within living memory many American states had local policies of not recording the births of black people, and to this day there are many living black people who can't prove their own citizenship. Unless and until every one of the fifty US states can demonstrate that they've put an ID card in the hands of virtually everybody, it won't be reasonable to condition things like education, health care, or voting on the possession of one.
- mrits 5y agoFor the people that can't prove they were born, how does a new ID card make it worse? It seems like it would make it better since the new system wouldn't be tied to birth ancient birth certificates or SS #s
- jeffbee 5y agoIt doesn't make it worse when you just issue IDs, but it would make it worse if you required them before they were virtually universal. Today the coverage of state IDs is actually very poor. People who hold them believe they are universally held but in truth only 89% of adult Americans possess one. That is not high, it is terrible.
- InitialBP 5y agoIn order to rollout a whole new ID system you'd need so way to validate the identity of the recipient before you gave them a new one. Presumably the easiest way would be just to turn in your old ID card, which many people don't have, per the previous comment.
- toomuchtodo 5y agoIt's a gradient. People with existing identity docs are frictionless, state IDs, driver's licenses, passports. Heck, ID.me and Stripe Identity can proof these folks remotely. People without those docs still have birth certificates and other legacy identity docs. You use trust anchors and identity to proof them into new identity systems. The latter requires a solid and robust ground game, similar to USPS or the US census, to ensure extremely high rates of coverage to prevent disenfranchisement or a digital divide. (a component of my work is digital identity/IAM)
- notyourday 5y ago> This country badly needs a national ID system. Great! You have just solved the illegal immigration problem. So we are going to legalize everyone right here right now, correct?
- ironmagma 5y agoThe immigration problem is only related to the ID problem for those who have an agenda. They are separate issues.
- notyourday 5y ago> The immigration problem is only related to the ID problem for those who have an agenda. They are separate issues. They are exactly the same issue. National ID only works if everyone inside the border has it -- regardless of how they managed to get there initially -- be that a person who due to whatever the weird way cannot get an ID as their records are messed up ( hello rural Appalachia ) or someone who is here illegally. After that t0 day the borders control and immigration control get teeth and anyone who does not have a National ID gets removed from the country. Otherwise you have just created two different classes of people with a near impenetrable barrier between them
- ironmagma 5y agoOr, we could start with giving a National ID to whoever currently has a Social Security card. That sidesteps the whole issue you’re describing and still solves the problem of how Social Security Numbers are not secret.
- notyourday 5y ago> Or, we could start with giving a National ID to whoever currently has a Social Security card. That sidesteps the whole issue you’re describing and still solves the problem of how Social Security Numbers are not secret. It does not because we fundamentally have enough fake social security numbers based identify theft to still create a two class system except this time there's zero guarantee that the person who should get the ID will have it and not his or hers "counterpart" My wife got IRS notification that she already filed taxes a few years ago when she attempted to file hers. It was because someone has been using her identity. That person did not get arrested. Rather there are now two people running around the country with her SSN - her and not her. Oh and they are still filing taxes as her. Year after year. She just needs to use a special code now to separate her return from an imposer return
- bpodgursky 5y agoI don't see how this helps at all in a remote setting. National ID numbers aren't private and could be stolen just as easily. Unless you truly have a national ID equivalent to like a Yubikey / 2-factor auth (I don't think anyone does) this just changes the implementation.
- only_as_i_fall 5y agoEh, I think the issue is that because there's no central system, every institution that needs to verify identity latches onto systems that were never intended for that purpose (such as ssn). The use of a bunch of different systems means that it'd hard to do simple things like verify that an applicant is actually a living person or that the same persons info isn't being used across multiple counties, states etc... Obviously there are a number of potential pitfalls in any such system, but I have to believe that even a flawed system which was intentionally designed would be harder to exploit than a hodgepodge of 100 incidental systems.
- nickff 5y agoWon't any system as valuable as national ID be vulnerable to similar attacks as SSN? The problem seems to be that American ID is extremely valuable; it will suffer more attacks than almost any other national ID, just because of the sheer amount of money involved.
- only_as_i_fall 5y agoNo, because a much better system could be designed if we planned on using it for id verification from the start. Some easy improvements even keeping a number based system would be: 1) don't assign ID numbers sequentially and based on location of birth 2) have consistent laws about who can collect these and liability for leaks (like hipaa) 3) allow them to be changed in cases of theft But we could actually do much better by using asymmetric cryptography.
- ajsnigrutin 5y agoYou don't hide the ID number, you show the card itself. In slovenia (and other former yugoslav countries) we have a unique ID for every person here.. It's set up from the date of birth (0101021 - 1. jan. 2021), then two digits for the foreign yugoslav state (50 for slovenia), then a tri-digit counter for each birth (first person born that day is 001, and so on), and one digit for the checksum, which can be easily calculated.... so basically, with a calculator and 2 minutes of typing in the numbers, you can calculate a valid ID number. But to open a bank account, you show the ID, which has any-copying measures (like money has), a photo, a serial number (to be cancelled if stolen), and only then the bank creates a new bank account for you. You can also use the same card to buy alcohol and travel through many european countries (no need for a passport).
- rbanffy 5y agoI'd go for stricter anti-money-laundering regulations and stiff penalties for executives of financial institutions that opt to take part of such schemes. If we severely punish a bank that looks the other way while someone opens an account using a stolen identity, I am very sure they'll work really hard to make that impossible. How hard they'll work depends on how severely they are punished.
- ok123456 5y agoAll the anti-money-laundering laws do is make it harder for everyone else except criminals. You're treated like a criminal simply by doing business in cash or having a lot of cash. Enhanced KYC just means that banks capriciously terminate your accounts and services if they find out you're a sex worker. If you're living abroad, no one wants to let you open an account.
- gruez 5y ago>Enhanced KYC just means that banks capriciously terminate your accounts and services if they find out you're a sex worker. are you saying this because of onlyfans? AFAIK that was due to pressure from banks/payment processors themselves (ie. not wanting the PR associated with facilitating human trafficking or whatever), not due to compliance reasons.
- ok123456 5y agoNo. Chase bank has always done this.
- jdavis703 5y agoNot only this. Large cash transactions also raise red flags. There have been American politicians tripped up in sex scandals because of AML laws.
- rbanffy 5y agoWhich, I guess, is a good thing. You don't want politicians to have such conflicts of interest. They can have as much sex as they want, they can pay as much as they want (as long as it's their money) for it, but the moment someone has a way to extort or otherwise force a politician to behave in a way that's illegal or against the interests of the people, I'd like that to be exposed.