4 ms·
> definitely an improvement over their bespoke customer identity and access management solution Is it though? With a service-specific system, if the system ge
by AnthonyMouse 2mo ago
> definitely an improvement over their bespoke customer identity and access management solution
Is it though?
With a service-specific system, if the system gets compromised, you lose your data on that system. With a centralized system that still happens, but then on top of that, there is also a centralized service to get compromised where you also lose your data on that system and every other system using it. The centralized system also ossifies with whatever flaws were present in the naive early implementation like the ancient credit card networks have, because once untold agencies and private entities are using it, anyone who wants to change anything about it is inundated with objections from thousands of entities who don't want to have to redo their integrations.
Meanwhile your activity is then correlated between different accounts. You have retailers using id.me to "verify military, student, teacher, nurse, or first responder status" for discounts. Not only do they get your name via computer instead of a physical document you would object if they tried to copy, you're now using the same system you use for taxes and healthcare. Is ICE going to use this against people? Are foreign intelligence agencies going to silently compromise it and use it against the domestic population? That's inevitable once you allow a centralized system like that to exist.
If you want to do this properly then you publish a reference implementation for an authentication system and let every organization run their own independent instance of it. That way a) none of the accounts are tied together and b) you can improve the system whenever you want and people can adopt the new version independently instead of needing to coordinate the entire world before you can change a single API parameter.