• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Why not a national ID card?

Or hackers haven't seen a good reason to do so?

So long as there are easier pickings why would they explore systems perceived to be complicated and troublesome. ALternately, systems that wish to maintain an image of complete security do not air their dirty laundry to the press, thus, not "hearing" about hacks, does not mean that hacks have not occurred.
 
As for the problem of data being hacked or stolen, how is that any different from now?
The problem is that a single ID number would be the way to locate an individual on every database that has been set up. With the one number, you would be able to find out an individual's credit history, medical history, criminal history, etc.

Yes, I know these systems will have security built in (:sdl:) but that won't stop the hackers.
 
This is probably the strongest objection.

The system (although "system" is really a stretch) now is that for any particular level if ID security, you can either choose to accept the prying eyes of each business you deal with or refuse to do business with them. So, for example, your bank, your hospital, your car dealership, and any of an expanding number of entities know more about you than they probably should. Even if you are presenting a driver's license as identification, they can get your birthdate and other info you might not wish to divulge.

But this is inaccurate. My bank accounts were opened with a Military ID card that I doubt was ever ran through any verification system because I personally have known the manager for several decades. My hospital is a VA facility where my Veteran's card (given to me based upon my service number and my DD214) is good enough with regards to personal information. Last time I bought a car I paid cash (got a big sticker-price discount) and never had to even flash my Driver's License (though I do think my secretary later did fill this in when handling the title transfer paperwork). Most places do have alternative procedures to follow when clients/customers do not want to use their SSN or other "ID" numbers in such processes and documentations.

My selling point to you is that a national, recognized for of identification could increase your privacy if you only authorized the first level -- I am who I say I am.

Why should I trust that from one card? What about that card makes it more reliable or trustworthy than any of the other pieces of corporate, state and federal ID I currently possess? When I want verifying ID from someone I don't know, I would prefer four or five different corroborating pieces of ID and statements from people who I know who have known them for at least several years. No single ID is going to convince me that they are who they say they are, and in most cases such is irrelevent. I don't need to know precisely who someone is for most business encounters, only the color of their money.

It would be enough for me to do business with you because I no longer need all the tangential information about you as "add-ons" simply to verify who you are.

What types of business make it important to know "who" you customer is?

Keep your social security number to yourself, keep your mother's maiden name private -- I no longer need it.

True, with a one-stop national ID card you can get all that just by knowing my National ID number,...which is rather my point, I'd rather make you have to dig to get all of these different numbers and pieces of information on your own, rather than giving you a single key that can unlock all of this information.

Does that help sway you?

Not yet, we seem to have some very different understandings and concerns with regards to privacy and security.

If not, consider how close this is to giving out your signature. Your signature is uniquely yours but doesn't give further information, perhaps not even your gender. All it does is match up some activity with you, uniquely.

Why tie all my information to a card that may or maynot be authentic, why not just use my signature?


Now, let us say you do wish to make a claim based on the standardized ID.

If it is ID alone, I would never want to do that or have that done and the card alone would not verify that, merely assert that.

Suppose you wish to verify that you are a US citizen.
I'd like that ability.

With an ID card? Why? I'm largely unconcerned about the citizenship status of the people I meet or do business with. If citizenship status is a serious concern I would never trust a card as proof that the person standing before me was a citizen. show me a US birth certificate, school records, personal references, DLs/StateIDs, etc., and I would be swayed, showing me an ID card might be the start of that, but it wouldn't in itself present compelling evidence of citizenship.

To do so, I can be empowered to release other information linked to my national ID and bingo! that gets verified as well.

If I don't trust the card, why would I trust any other information released through or from that card?
 
Just a question here. We have a single document now that demonstrates U.S. citizenship. It's called a passport (also available in card form for travel to Canada and Mexico), and once you have one you don't need anything else to prove your identity to the DMV, TSA, banks, employers, etc. Is there any evidence that evil enemy states are manufacturing functional counterfeit passports?

I'm sure the intelligence agencies of most major powers can and do manufacture functional counterfeit US passports.
 
Easy, biometric data. A retina scan for example. The holder of the fake card will fail the retina scan.

Not if the data is altered to have the holder's retina scan attached to the alternate ID information in the case of a fraudulent or spoofed card. Or as in the Man-in-the-middle attack done on the PIN and CHip CCs, as long as the data retrieved by the scanner is given a false greenlight, and the card doesn't recognize that it has even been queried for data, the card is not a foolproof secure and reliable ID system.
 
But this is inaccurate. My bank accounts were opened with a Military ID card that I doubt was ever ran through any verification system because I personally have known the manager for several decades. My hospital is a VA facility where my Veteran's card (given to me based upon my service number and my DD214) is good enough with regards to personal information. Last time I bought a car I paid cash (got a big sticker-price discount) and never had to even flash my Driver's License (though I do think my secretary later did fill this in when handling the title transfer paperwork). Most places do have alternative procedures to follow when clients/customers do not want to use their SSN or other "ID" numbers in such processes and documentations.

You have described the existing system quite well. I don't see any reason to expect that some businesses might continue to accept a variety of IDs but would have to do so at their own risk, in the same way I might accept a check from someone I don't know without verifying it.

Why should I trust that from one card? What about that card makes it more reliable or trustworthy than any of the other pieces of corporate, state and federal ID I currently possess? When I want verifying ID from someone I don't know, I would prefer four or five different corroborating pieces of ID and statements from people who I know who have known them for at least several years. No single ID is going to convince me that they are who they say they are, and in most cases such is irrelevent. I don't need to know precisely who someone is for most business encounters, only the color of their money.

That has to be a critical element -- trust. If such a card existed, surely you would want to use that in preference to alternatives? Do you decline cash because you know cash can be counterfeited? At some point, you accept the risks or you don't play the game. The purpose is to minimize the risk by making a more secure type of ID.

What types of business make it important to know "who" you customer is?

Any business that relies on previous transactions. This is common online, but also offline -- we prove ourselves to others all the time. "This car belongs to Johnny Rotten. I am Johnny Rotten." or "I am the person who is listed as having property X, where X is a degree, a privilege, a vested interest... on and on.

True, with a one-stop national ID card you can get all that just by knowing my National ID number,...which is rather my point, I'd rather make you have to dig to get all of these different numbers and pieces of information on your own, rather than giving you a single key that can unlock all of this information.

It doesn't have to be a single key, but can be graduated so that more secure information is more secure. In essence, a single lock with multiple keys to gain deeper access. Still, I agree that trust is an issue.


Not yet, we seem to have some very different understandings and concerns with regards to privacy and security.

I agree. I think I am coming at it from the advantages of being able to represent myself honestly and seeing a value in that, rather than from a sense of privacy rights and the ability to hide facts. After all, isn't the purpose of concealing your information at least partly to hide truth?

Why tie all my information to a card that may or maynot be authentic, why not just use my signature?

Standardization. The same reason gold often comes in one ounce coins. You don't have to compare against an exemplar and weigh it (although you could).

If it is ID alone, I would never want to do that or have that done and the card alone would not verify that, merely assert that.



With an ID card? Why? I'm largely unconcerned about the citizenship status of the people I meet or do business with. If citizenship status is a serious concern I would never trust a card as proof that the person standing before me was a citizen. show me a US birth certificate, school records, personal references, DLs/StateIDs, etc., and I would be swayed, showing me an ID card might be the start of that, but it wouldn't in itself present compelling evidence of citizenship.

I see your example as a problem, not a security feature. When a passport alone establishes citizenship, I think of that as a strength, not a weakness.

If I don't trust the card, why would I trust any other information released through or from that card?

Exactly. We would have to have a trustworthy card or the idea doesn't work.

I thought of an added feature. You get a daily report of all the transactions using your card. I like it because I want to incorporate individual motivations to keep their own ID secure. Would that help establish trust with you?

Let me ask another question (I find your objections very worthwhile): Are you satisfied with the way ID is determined online or do you perhaps avoid online commerce and the associated risks (or something in between)?
 
So long as there are easier pickings why would they explore systems perceived to be complicated and troublesome. ALternately, systems that wish to maintain an image of complete security do not air their dirty laundry to the press, thus, not "hearing" about hacks, does not mean that hacks have not occurred.

Nonsense. The fact is, that there were lots of problems before with magnetic cards getting cloned etc. This is a kind of fraud that's almost eliminated. You don't think the criminals would like to get their "business" back?

The rest is just conspiracy stuff unless you can prove otherwise.
 
...My hospital is a VA facility where my Veteran's card (given to me based upon my service number and my DD214) is good enough with regards to personal information.....

Just a question, as a way of illustrating two alternate perspectives: When you joined the military (thank you for your service, by the way) you were fingerprinted. Those prints are still on file and are accessible -- theoretically, anyway -- to every law-enforcement agency in the world. Does it make you feel more secure to know that no one else can pretend to be you because fingerprints would reveal his lie, or less secure to know that any thing you ever touched anywhere could be traced back to you? I see a secure ID as protection for me from people who might hurt or defraud me; you seem to see it as a tool that could be used to hurt or defraud you. (By the way, the military stopped using "service numbers" by 1974, and earlier in some branches; since then, they have used Social Security numbers for most purposes. And service numbers are public information available to anyone; Social Security numbers are subject to at least some federal privacy protections. Your service number is less secure than your SS number.)
http://en.wikipedia.org/wiki/Service_number_(United_States_armed_forces)

.... I would prefer four or five different corroborating pieces of ID and statements from people who I know who have known them for at least several years. ...

In the modern world, what percentage of humanity do you think would have been known for several years to several people that you have known for several years? That might work in Andy Griffith's "Mayberry," but not many other places.

...What types of business make it important to know "who" you customer is?...

For one, federal law requires banks and pretty much anyone involved in any part of the financial services industry to confirm the identities of their customers. If you pay someone with more than $10,000 cash, he is required to file a form with the IRS. If he pays you, you have to file the form. And every employer is required -- theoretically, anyway -- to confirm that anyone he hires is legally authorized to work here. If you are a pharmacist filling a prescription for a narcotic, you better know that it was written by a real doctor for a real patient who is standing in front of you. And, going beyond business concerns, if you have young children you might want to find out whether your new next-door neighbor is a convicted pedophile.

...show me a US birth certificate, school records, personal references, DLs/StateIDs, etc., and I would be swayed....

Could you recognize valid drivers' licenses from all of the 50 states, birth certificates from thousands of cities and counties, school records from tens of thousands of schools, etc.? Would you really give a United States passport -- issued by an agency that has access to the full investigative and law enforcement resources of the federal government -- less weight than a letter purportedly from someone you didn't know at a school you never heard of?

You seem to think that privacy and security are at opposite ends of a spectrum. I see security as something that enhances my privacy.
 
Last edited:
got a link to some details?

It wasn't as easy to find as I had hoped. I got more of my information from the radio than I expected and a lot of the news stories I have been able to find are about how, post 2009, the scheme would no longer be mandatory.

This is the best I can do...

Torygraph said:
Now it turns out that they are planning to sneak in just such a power presumably hoping that no-one noticed. But the eagle-eyed lawyers at Liberty spotted that clauses in the draft Borders, Immigration and Citizenship Bill – confirmed as part of the Government’s programme for this session of parliament in the Queen’s Speech - give state officials the power to make anyone who has ever entered the country, at any time, prove who they are.

http://www.telegraph.co.uk/comment/telegraph-view/3563928/ID-cards-are-not-voluntary.html

So this would not have applied to British Citizens who had never left the country, but for the rest of us we would have had to be able to prove who we are at any time.
 
The problem is that a single ID number would be the way to locate an individual on every database that has been set up. With the one number, you would be able to find out an individual's credit history, medical history, criminal history, etc.

Yes, I know these systems will have security built in (:sdl:) but that won't stop the hackers.

So why isn't this happening everywhere that single ID systems already exist?
 
With an ID card? Why? I'm largely unconcerned about the citizenship status of the people I meet or do business with. If citizenship status is a serious concern I would never trust a card as proof that the person standing before me was a citizen. show me a US birth certificate, school records, personal references, DLs/StateIDs, etc., and I would be swayed, showing me an ID card might be the start of that, but it wouldn't in itself present compelling evidence of citizenship.

For the record, Swedish national ID cards don't have citizenship on them. I have a swedish ID card, but am not a swedish citizen.

If it did have citizenship then I think it might aid discrimination. I was trying to think of circumstances where it might be an issue and the only one I could think of was voting. I can vote in local elections, but not national elections. I haven't tried but I assume if I tried to vote at national elections I wouldn't show up on the electoral rolls.

Which of course brings me to probably one of the biggest reasons the US doesn't have a national ID system. It would make it too easy for the rabble to be able to vote! :cool:
 
So this would not have applied to British Citizens who had never left the country, but for the rest of us we would have had to be able to prove who we are at any time.


The same article (and it's nearly 4 years old) also says -

When the Government introduced its ID card legislation several years ago, it made one thing clear. Even though it would be obligatory to register on the ID database when obtaining a new passport, it would not be compulsory to carry a card.


and about the then introduced draft bill -

Perhaps the Government did not intend the legislation to be so widely drawn and meant it merely to apply to people when they arrive at the border as part of a proper immigration control system.


Indeed, the Home Office said -

It is simply wrong to claim there are any plans whatsoever to make identity cards compulsory for British citizens or to require British citizens to have their ID card – or any other form of ID – on them at all times and to present it when asked to do so.

It would appear your claim that -

The Don said:
Needing to carry the card has been repeatedly mentioned by the people proposing its introduction in the UK as a key element of enforcement.

is inaccurate
 
It would appear your claim <snip> is inaccurate

You're probably right. I was probably misremembering and conflating various interviews and phone-ins from several years ago.

If the UK ID card was not going to be compulsory then I cannot understand how it ever could have been effective as a means of identifying illegal immigrants or somehow controlling terrorism. As a means of doing other stuff, then perhaps, but at the time the government were positioning it as an effective measure against those two.

This still means it would be ineffective, expensive, badly implemented and would leave a whole new set of information that could be left lying around.
 
So why isn't this happening everywhere that single ID systems already exist?
[Simpsons Mode]How do you know it isn't? I bet the ads on your emails/web pages are more targetted to your needs than the ones I see are to mine.[/Simpsons Mode]
 
Why tie all my information to a card that may or maynot be authentic, why not just use my signature?
I've noticed that my signature, since the computer age, has changed drastically from what it was 20 years ago. Nobody writes much anymore, and without that constant repetition handwriting becomes far less uniform IMHO.

Not if the data is altered to have the holder's retina scan attached to the alternate ID information in the case of a fraudulent or spoofed card. Or as in the Man-in-the-middle attack done on the PIN and CHip CCs, as long as the data retrieved by the scanner is given a false greenlight, and the card doesn't recognize that it has even been queried for data, the card is not a foolproof secure and reliable ID system.
In that case the spoofed card is no longer a replica of the one in the database, and the card is easily identified as fraudulent.
 
You're probably right. I was probably misremembering and conflating various interviews and phone-ins from several years ago.

If the UK ID card was not going to be compulsory then I cannot understand how it ever could have been effective as a means of identifying illegal immigrants or somehow controlling terrorism. As a means of doing other stuff, then perhaps, but at the time the government were positioning it as an effective measure against those two.

This still means it would be ineffective, expensive, badly implemented and would leave a whole new set of information that could be left lying around.
There's a difference between being required to have an ID card and being required to carry it with you at all times.
 
There's a difference between being required to have an ID card and being required to carry it with you at all times.

I appreciate that, but if you're not carrying ID, what use it is to try and identify illegal immigrants and terrorists ?
 
I've noticed that my signature, since the computer age, has changed drastically from what it was 20 years ago. Nobody writes much anymore, and without that constant repetition handwriting becomes far less uniform IMHO.

(You obviously never attended Catholic school!)
My signature is largely unchanged, but then I still physically write letters (and frequently still wirte paper checks), and fill our physical forms, reports and various other (literal) paperwork.

In that case the spoofed card is no longer a replica of the one in the database, and the card is easily identified as fraudulent.

The only information the card transmits is its account verification sequence. SO long as the spoofed card possesses the proper access protocols and addresses the database in the way it expects, it is indistinguishable from the real card.
 
(You obviously never attended Catholic school!)
I did, but only 1st grade. Sister Marian...

The only information the card transmits is its account verification sequence. SO long as the spoofed card possesses the proper access protocols and addresses the database in the way it expects, it is indistinguishable from the real card.
Why would that be the only information it transmits? Why not other encrypted data to further verify? Or maybe even just a hash tag that must match.
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom