Live data from Hacker News

Britain to introduce compulsory digital ID for workers

reuters.com

651–660 of 809 posts

Re: Britain to introduce compulsory digital ID for workers

#651

A secure, optional digital ID could be useful. But not in today’s UK. Why? Because the state has already shown it can’t be trusted with our data. - Snoopers’ Charter (Investigatory Powers Act 2016): ISPs must keep a year’s worth of records of which websites you visit. More than 40 agencies—from MI5 to the Welsh Ambulance Service—can request it. MI5 has already broken the rules and kept data it shouldn’t have. - Encry…

The ID cards as realized in many other countries are comparatively benign, because they are a physical credential in the possession of the person concerned. The government cannot stop this credential from being used except by physically confiscating it or by waiting (years) for it to expire. Distributed storage in action. The UK's proposal makes the "digital ID" a pointer to an entry in a centralized database. This d…

Not just that, but currently, requiring real data to register to eg. social networks (reddit, hn,...) is hard. With everyone having a digital ID on their phones, tying their identity to their real ID will be easy, you'll just "sign" (or whatever) your reddit registration with your ID and your real name will be tied to that account. Combine this with EU chat control (and UK alternatives.. and well, EU digital ID alternatives), and the era of semi-anonymous internet use is over.

Re: Britain to introduce compulsory digital ID for workers

#652
post #17

I'm not clear if this is digital ONLY or if I people can choose to carry a physical card when required, instead of a smartphone. If it's the former, then it means it's now mandatory for all British citizens to become customers of the Google/Apple duopoly LOL

It's been mentioned that you will be able to get a physical card with a chip in it for those who want it

thanks, do you have a source?

Re: Britain to introduce compulsory digital ID for workers

#653

The point of digital ID might be to add more cases when ID is required in future. One thing if everyone buying a kitchen knife must fill a long form, another thing if they just must tap a phone on the cash register linking knife ID and person's ID. Half of you are already tapping a phone to pay for the items anyway. One thing is showing a passport to enter the gay bar, another thing is tap a phone and have time, pers…

Once the ban on pointy cutlery is imposed and knife crime gives way to fork crime, you’ll be glad you only have to tap your phone at the pub instead of eating that Sunday Roast with a spoon.

Re: Britain to introduce compulsory digital ID for workers

#655

The UK is absolutely paranoid about national ID cards and has been for decades. Not sure how that happened tbh seems like the US has a similar allergy.

We both have governments with a track record of technological incompetence and surveillance overreach. Unfortunately it seems pretty rational to me.

Re: Britain to introduce compulsory digital ID for workers

#656
post #590

Earlier quoted context omitted.

When a credential is stolen, its validity across multiple unrelated services is often checked by credential stuffing. That's just one type of simple attack. Has cybercrime been rendered obsolete with a government credential? Why is this master account immune to theft? On the contrary, it appears to be a credential that once stolen, could be more impactful than having your primary email account and phone compromised.…

What master account are you even talking about? That's not what this is. The subject was a system being breached. And the account you set up for a driver's license is generally different from the one for your health care. If you're reusing the same password for both it doesn't matter if they're linked by the same digital ID number or the same email address or just the same name and birthday. A digital ID number isn't…

In the UK's own post linked below (also in the OP), they describe what's more than a digital ID number. It's credentials. Which humans are bad at handling. And there are always implementation flaws, because we're humans.

https://www.gov.uk/government/news/new-digital-id-scheme-to-...

Re: Britain to introduce compulsory digital ID for workers

#657

Earlier quoted context omitted.

The ID cards as realized in many other countries are comparatively benign, because they are a physical credential in the possession of the person concerned. The government cannot stop this credential from being used except by physically confiscating it or by waiting (years) for it to expire. Distributed storage in action. The UK's proposal makes the "digital ID" a pointer to an entry in a centralized database. This d…

> The government cannot stop this credential from being used except by physically confiscating it or by waiting (years) for it to expire This is not true. Government agencies generally look up your ID as necessary to check if it's still valid. Stopped for speeding? The cop is going to look up your driver's license. Leaving the country? They're running your passport number. Starting a job? They're checking the status…

Even for renting a car these days you need a verification code that you can request from the DVLA using your national insurance number.

Re: Britain to introduce compulsory digital ID for workers

#658
Are there any Amish in the UK? In the US, they probably have ID (like most other citizens) but not the digital form that's being discussed here. I'm not against the idea of having an ID card, as like many others I have some of my own, but that's a physical, inert object which stands on its own, not tied to anything ephemeral and fragile like a mobile phone or computer would be.

Re: Britain to introduce compulsory digital ID for workers

#659

A secure, optional digital ID could be useful. But not in today’s UK. Why? Because the state has already shown it can’t be trusted with our data. - Snoopers’ Charter (Investigatory Powers Act 2016): ISPs must keep a year’s worth of records of which websites you visit. More than 40 agencies—from MI5 to the Welsh Ambulance Service—can request it. MI5 has already broken the rules and kept data it shouldn’t have. - Encry…

The ID cards as realized in many other countries are comparatively benign, because they are a physical credential in the possession of the person concerned. The government cannot stop this credential from being used except by physically confiscating it or by waiting (years) for it to expire. Distributed storage in action. The UK's proposal makes the "digital ID" a pointer to an entry in a centralized database. This d…

SSL has Certificate Revokation List, this could be implemented for Digital ID as well.

In fact, if British Digital ID is based on PKI, then CRL will come out of the box

https://en.wikipedia.org/wiki/Certificate_revocation_list

Re: Britain to introduce compulsory digital ID for workers

#660

Earlier quoted context omitted.

They're talking about government spyware. Why not install a little bit extra into that digital ID app

But as long as the phone is unrooted the all can't spy on anything. Your phone restricts it. If you root your phone and install apps, your apps can do anything and spy all they want. So the comment still makes zero sense.

Apps on a rooted phone can only do anything if you give them the root permission. Otherwise, permissions the same as always.
Post reply on HN