3 ms·
All it takes is one breach or vulnerability and then yes, they DO have access to all your data. Imagine someone steals your driver's license. No biggie. Now i
by array_key_first 1y ago
All it takes is one breach or vulnerability and then yes, they DO have access to all your data.
Imagine someone steals your driver's license. No biggie.
Now imagine they steal your identity which is linked to everything you ever do.
- jama211 1y agoBut that’s already the case without a digital id. It’s not like those accounts aren’t already linked together.
- hereme888 1y agoBreach = data for all citizens. Card = one person, limited use. But most importantly: a Hitler rises to power = opposition is screwed.
- pezezin 1y agoAh, good old Godwin's law... If a Hitler rises to power you will be screwed with or without an ID card, so please don't use such a silly argument.
- protocolture 1y agoDoesnt have to be a Hitler, imagining the worst case scenario for laws is absolutely apt. Consider the Australian Access and Assistance bill. Among other things, it permits ministers to issue TCN's verbally. As far as we know (theres no oversight) this hasnt been done. But its concerning that the government can verbally require a corporation to (open endedly) change app functionality. It would be better if Jim Hitler, had to fight the existing democracy to erode our freedoms, rather than just having to ask a minister to make it so. Its absolutely better to assume the worst case than the best.
- hereme888 1y ago[flagged]
- grues-dinner 1y agoThe accounts generally aren't linked together. Everything about the UK government IT is a huge group of independent systems all pretty much isolated from each other. You can argue over whether that's down to incompetence, organisational turf wars, or good security design. Which is why you have completely separate account to pay the same government for crossing one specific brige in East London than you do for vehicle tax. Most government websites do use the same frontend toolkit (a rare win for UK governmental IT) but front completely separate systems.
- jama211 1y agoI mean they could be more tightly integrated but any agency could match one account with another any time they felt like it
- crazygringo 1y ago> All it takes is one breach or vulnerability and then yes, they DO have access to all your data. No they don't. If they breach the health system, they don't have access to tax returns. Just because people are identified by a single ID number doesn't mean all their data is being stored on the same server. And for purely organizational reasons, that's incredibly unlikely to happen. And I don't know what you mean by "steal your identity". People's names are date of birth are generally a pretty unique identifier already. It doesn't really matter if systems use that or a single ID number to identify you, or if hackers look you up by your name.
- 9x39 1y agoWhen a credential is stolen, its validity across multiple unrelated services is often checked by credential stuffing. That's just one type of simple attack. Has cybercrime been rendered obsolete with a government credential? Why is this master account immune to theft? On the contrary, it appears to be a credential that once stolen, could be more impactful than having your primary email account and phone compromised. It's reasonable to be concerned even just from an infosec perspective.
- kelseyfrog 1y agoIs this a _could_ happen or _has_ happened type problem? I'm trying to understand if it is speculative or if we have a base-rate for occurrence.
- crazygringo 1y agoWhat master account are you even talking about? That's not what this is. The subject was a system being breached. And the account you set up for a driver's license is generally different from the one for your health care. If you're reusing the same password for both it doesn't matter if they're linked by the same digital ID number or the same email address or just the same name and birthday. A digital ID number isn't changing anything here.
- 9x39 1y ago