Live data from Hacker News

UK Petition: Do not introduce Digital ID cards

petition.parliament.uk

121–130 of 373 posts

Re: UK Petition: Do not introduce Digital ID cards

#121

France, Germany, Sweden, Estonia and India already have government id. However, this being hackernews there will never be a link to a well researched article on the pros and cons of introducing id cards (digital or otherwise), only conspiracy theories and confident declarations that id cards are a surefire symbol of authoritarian states. I don't know what I think, I lack sufficient knowledge to have an opinion. But I…

France Identité app is closed source, requires GMS and Play Integrity, and is only available on closed stores. It is not yet mandatory but who knows when it'll happen. No thanks.

Re: UK Petition: Do not introduce Digital ID cards

#123
To me it's a question of benefits vs drawbacks. In my understanding ID cards are beneficial for 1) Running government services 2) Fraud prevention 3) Some immigration control (as at least some reason why people try to migrate to UK is lax document checks) Some people argue that it's somehow becomes authoritarian, when you have an ID card. I personally don't buy that as most of us have already passports, NI numbers etc, so all the security cervices if need be have access to that. Obviously if people start to engage with hypotheticals, that these cards will be used to check whether you can access internet etc, I agree, that would be dangerous, but that is not being proposed. Also the argument that implementing it will take a lot of money and will never be done is not a convincing one, as in that case one should not really try to do anything in this country.

Re: UK Petition: Do not introduce Digital ID cards

#124
post #73

Earlier quoted context omitted.

I currently live in the UK, and I am not significantly restricted from anything (banking, ISAs, investments, healthcare, etc) for refusing to use a Google approved build of Android. Moreover, I actually on principle refuse to make myself dependant on my phone for these things, which means that (at a small convenience cost) I don't have any banking apps, or investment apps, or healthcare apps, or whatever). My phone i…

Oh I agree a system, if implemented, should not depend on a tie to Apple or Google, however, I'm not aware that detailed implementation guidance has been produced as yet which would require that tie, although I could have missed that. I'd hope that a system as implemented is as technologically neutral as possible. Good on you for avoiding the smartphone tie on banking though, it's getting increasingly hard for decent…

They haven't specifically said anything, but they have directly compared the ID to phone based payment card systems, which on the google side do rely strictly on a google-blessed android build[0][1][2].

It's also incredibly popular in the security industry (I know, I work in it) to claim that every possible app in existence must:

* Obfuscate

* Do root detection and refuse to work

* Detect attempts to attach a debugger, and refuse to work

* Detect running from a VM, and refuse to work

* Do certificate pinning (although as an industry we've stopped recommending this bullshit practice, although we still insist on it for some things)

* Prevent screenshots from being taken

* Force you to re-authenticate using biometric ID every time you look away from the app

* and... break at the slightest hint of a non-standard build of android

So I don't have high hopes, because the company I work for does work for the UK government, will likely be picked to review this app, and inevitably all that shit is what we'll recommend (although I hope I won't be working here by then because I'm just sick and tired of cargo cult / checkbox security).

[0]: Not because of any specific feature, but solely based on signing keys.

[1]: I believe specifically you have to license GMS integrate them into the build, which e.g. GrapheneOS does not do.

[2]: And no, GOS's sandboxed google services don't fix this problem, Google Pay will still refuse to work.

Re: UK Petition: Do not introduce Digital ID cards

#125
post #5

Earlier quoted context omitted.

I wonder how much you're loading into "simply practicing free speech".

In many cases the “free speech” genuinely is racial hatred bordering on incitement. But on the other hand there genuinely have been many people arrested (and in some cases convicted) under these laws for statements that are shockingly milquetoast.

> But on the other hand there genuinely have been many people arrested (and in some cases convicted) under these laws for statements that are shockingly milquetoast.

Care to name some?

The vast majority of cases I've looked into end up being a lot more than the initially presented "They Were Arrested For Saying Bad Words On The Internet!" story pushed on the internet.

In fact, I can't remember a single one where there wasn't a lot more, but that's not really more than anecdote.

Re: UK Petition: Do not introduce Digital ID cards

#126
post #10

Earlier quoted context omitted.

Many of the former colonies of the UK have chosen to secede from the UK. Is there any chance England might too?

No, English people still somehow tie their identity to the UK Government somehow. Scotland will not be granted another independence vote for at least 15 years, despite the last one being build upon a house of lies and nobody knows anything about what the Welsh think. I do think we’re witnessing the collapse of the UK, but more like a Roman Empire collapse - as in it’s happening over decades. Dying with a whimper, not…

If I had to guess I would think it would collapse more like the USSR, from the centre, with the english withdrawing their support for a british state that no longer serves their interests

Re: UK Petition: Do not introduce Digital ID cards

#127

Earlier quoted context omitted.

The latter part at least is true. Sending "grossly offensive" messages is illegal under the Malicious Communications Act 1988 and the Communications Act 2003, specifically Section 127: > a person is guilty of an offence if he— > (a)sends by means of a public electronic communications network a message or other matter that is grossly offensive or of an indecent, obscene or menacing character; or > (b)causes any such m…

[flagged]

> “Grossly offensive” is absolutely not the same thing as “any message online that anyone could find insulting or offensive”.

There is no statutory definition of “grossly”, so in effect it is the same. There is prior art for it being interpreted incredibly widely.

Not to mention the other incredibly vague adjectives in the law.

> Correct

https://news.ycombinator.com/newsguidelines.html “Don’t be snarky”.

Re: UK Petition: Do not introduce Digital ID cards

#128
post #106

Earlier quoted context omitted.

> It is a criminal offense in the UK to use insulting words in public, or to send any message online that anyone could find insulting or offensive (whether any one does or not is irreverent). This is categorically untrue.

Public Order Act 1986 "insulting words or behavior that cause distress to others" Malicious Communications Act 1988 (Section 1): "Outlaws sending messages, electronic or otherwise, with the intent to cause distress, or anxiety" Communications Act 2003, Online Safety Act 2023, hate speech, terrorist legislation all made these many orders of magnitude worse in many ways.

You cannot be arrested for sending “any message online that anyone could find insulting or offensive”. That’s not what the law says. You can be arrested for spreading hate speech, inciting violence, sending illegal media or harassment online.

All of the arrests mentioned in this thread in relation to these acts have been campaigns of intimidation, harassment and calls to violence, not simply saying something “insulting or offensive”.

In the UK political expression of free speech is protected by the ECHR, which overrides both those acts (look carefully who wishes to abolish the ECHR).

Re: UK Petition: Do not introduce Digital ID cards

#129
I don't trust the UK government either. But I'm both British and Australian and I see the need for a centralised identity service.

Because the alternative is that we provide our passport to every online service that 'needs' to verify our identity. Then – lo, would you believe it! – they get hacked, and now all of our data is in the wild again.

I'd much rather the government, who already know everything about me because may I remind you they issued the documents, had some way of that company querying my 'verified identity'. They might do it by me providing, say, an ID number string which is looked up. That's all they get: my ID number. In return, they get confirmation that I am who I say I am.

Oh by the way I already have at least 2 of these ID numbers as an Australian citizen. My aforementioned passport, and my driver licence. Both of which I know I should keep 'private', lol, but if I want to interact with the world in any meaningful way the reality is that I spray these digits – along with my date of birth and address and whatever else they ask for – all over the goddamned place.

But sure, centralised identity is bad.

Re: UK Petition: Do not introduce Digital ID cards

#130
post #98

Earlier quoted context omitted.

> I don't get the resistance to a digital/national id in other countries. To us it is quite bizarre. It depends on the country and its relationship with the people. If the people trust that their government represents the people's interests, there is little push-back. In countries where citizens have reason to believe their government is hijacked by interests that do not have their best interests at heart, then every…

Seems like a red-herring. Does a government need a digital ID to do that? Many do that with the "free market" of publicly-tradable information + pre-existing government IDs already used for certain things. I don't know for sure how much the UK government is purchasing all that, but there's a lot of cameras and tech tracking in the country already, like those of us across the pond also are watched with. It won't rever…

if they want private information, they should buy it on the open market like every other company!
Post reply on HN