• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Why not a national ID card?

Just a question, as a way of illustrating two alternate perspectives: When you joined the military (thank you for your service, by the way) you were fingerprinted. Those prints are still on file and are accessible -- theoretically, anyway -- to every law-enforcement agency in the world. Does it make you feel more secure to know that no one else can pretend to be you because fingerprints would reveal his lie, or less secure to know that any thing you ever touched anywhere could be traced back to you?

I don't feel that having my fingerprints on file with the DoD (which btw is distinctly different than having my fingerprints "theoretically" available to every law enforcement agency on the planet - but I can go along with the hypothetical) makes me any more secure in the least, and it does invade my privacy much more than I would prefer. As I said, security is not a concern of mine, I feel that it is predominantly an overblown issue used to get people to surrender privacy and freedom much moreso than any real or legitimate concern.

I see a secure ID as protection for me from people who might hurt or defraud me; you seem to see it as a tool that could be used to hurt or defraud you.

A completely secure ID is a deus ex machina fantasy. Installing an ID system that people believe is infallable and uncorruptible leads to false senses of security and the sacrifice of privacy.

...Your service number is less secure than your SS number.

I told you, security isn't an issue that bothers or concerns me greatly, and the only things one can really find out about me with only my service number, are not things that cause me any privacy conerns.

In the modern world, what percentage of humanity do you think would have been known for several years to several people that you have known for several years?

not many, care to ask me how many people outside that number I trust or would expect to trust me,...or can you guess? I see no reason for things to be carried beyond that level. I don't really care if others prefer things differently, I just don't want them to force me to do things I do not wish to do to allow them to do things I don't think they should be doing. If you want to start up a private ID company and encourage people to willingly register to use the service and recruit businesses to participate in the program, by all means go for it, I wish you all the success in the world,...but it becomes a completely different story when you are going to legislate such activities pay for it with taxes and compell me to participate. Ultimately, if such a law were passed, I would probably comply (the only real option apparently being immigration), but you can bet that I would loudly complain, protest and campaign against any such program and any candidate who even hints that they would be open to considering such a program,...and I don't think I'm in a minority on this issue.

That might work in Andy Griffith's "Mayberry," but not many other places.

You say that as if there was something wrong or improper and inadequate about "Mayberry?" I, personally, am of the opinion that small town communities are the ideal model for society. This doesn't mean atechnological, unsophisticated or antiquated, merely smaller community groups, largely decentralized, greatly self-sufficient, where people in the community know each other on a first name basis and the only privacy that is violated happens over a shared backyard fence or in the beauty/barber shops and local watering hole. I understand that this is alien to many people, but I don't insist that those who don't want to live that way abide by my druthers. Is there a viable means to opt out of your national ID and not severely impact or limit the lives of those who choose to opt out?

For one, federal law requires banks and pretty much anyone involved in any part of the financial services industry to confirm the identities of their customers.

Indeed, and there are many ways to provide that confirmation. As a part of such a national ID are you willing to include legislation that specifies that this National ID may not ever be the only acceptable form of ID for any purpose and that any place that uses the National ID card also institutes various acceptable alternatives that they will accept to establish ID to accomidate those who choose not to participate in a national ID system (under penalty of fine and prosecution if the fail to do so)?

If you pay someone with more than $10,000 cash, he is required to file a form with the IRS...

This has what to do with a National ID?

If you are a pharmacist filling a prescription for a narcotic, you better know that it was written by a real doctor for a real patient who is standing in front of you.

This is accomplished tens, if not hundreds, of thousands of times a day without the need for a national ID.

And, going beyond business concerns, if you have young children you might want to find out whether your new next-door neighbor is a convicted pedophile.

I would be more concerned about uncaught and unconvicted pedophiles, but personally the issue doesn't concern me. I have always known my neighbors well, and always meet and get to know any new people who move into my vicinity. The potential of bad people or good people doing bad things is not a security issue that bothers me, I would prefer to sacrifice the false sense of security in exchange for increased levels of privacy.

Could you recognize valid drivers' licenses from all of the 50 states, birth certificates from thousands of cities and counties, school records from tens of thousands of schools, etc.?

I don't need to. If they have prepared a panoply of official and legitimate appearing documentation, have a compelling narrative that fits and is accord with the information, calls to some the various sources substantiate records, and they are vouched for by people I have known for years,...I would accept that they were who they claimed to be until they gave me reason to doubt that acceptance.

Would you really give a United States passport -- issued by an agency that has access to the full investigative and law enforcement resources of the federal government -- less weight than a letter purportedly from someone you didn't know at a school you never heard of?

I wouldn't trust either in isolation. I've seen some pretty convincing fake passports.

You seem to think that privacy and security are at opposite ends of a spectrum. I see security as something that enhances my privacy.

I see privacy as the foundation of security, the less privacy the less security one has.
 
I did, but only 1st grade. Sister Marian...

Ah, you just got the scared-straight program! I was a lifer, 10 years and then a 2-year stint in seminary, before I got parolled to the military.

Why would that be the only information it transmits? Why not other encrypted data to further verify? Or maybe even just a hash tag that must match.

Well, for the most part, at the least, to my understandings, we are talking about a key, not a major data storage device. It is the terminals/readers that are generally the real linked system with the database. Your card just authorizes the reader to access your information on the database, and for most purposes the only information it is going to access is the "cover" of your file, which may have no more than your name, physical description and an encrypted PIN. You could certainly add more, but the cards themselves are generally only storing something like 32Kb and are comparing the data they have imprinted, with the access and verification data on your file in the database. If they match, the reader says that the data matches. What else gets put into or linked to that file are even more problematic than even this superficial level of privacy compromise.
 
A completely secure ID is a deus ex machina fantasy. Installing an ID system that people believe is infallable and uncorruptible leads to false senses of security and the sacrifice of privacy.

I would go so far and even say that as soon as there is enough interest to compromise a system, it will be done. There simply is no 100% secure system, and there will never be one. No matter where you look, "secure" token are broken (look up RSA for example), chip-cards are copied, access cards tampered with, etc.

After all, those things have to be produced somehow. And whatever you can produce, you can also reproduce and thus copy. The next thing is that i think it is problematic to trust electronic systems/networks too much. After all, those are just dumb machines. Machines can fail, machines can be tricked, and they can be broken into.

It's all just a matter of how much effort one wants to put into it. And no matter with how many things you come up: At some point someone has to issue any of these things. And that's the point of attack then. A good bribe can go a long way. Why not fill blank cards with whatever information one wants. Oh, but the database check, you say? Well, what about a compromised computer at the place where there is access to such a database, and simply inject your data into it that way?

I mean, hey, it's not that big a deal to gain access to some computer if you want to. Heck, it might even be enough to spread some USB sticks with your custom malware on it in some parking lots. Someone will always be dumb enough to plug that into his work computer, and that's it. No need to break into a building, or dig up a street to access cables.

And regarding fingerprints, whoever thinks that these will add any kind of security are gravely mistaken. You would be surprised to learn how easy it is to copy a fingerprint and put that copy onto your own finger. Simple household stuff and a laser printer is all you need. Retinal scans may be safe for now, but i'm pretty sure that these scanners can be fooled as well. Especially if you know how such systems (fingerprint, retinal scan) actually sample the object and what information they actually process.

100% secure is nothing but an illusion. It simply doesn't exist in the real world.

Greetings,

Chris
 
100% secure is nothing but an illusion. It simply doesn't exist in the real world.
True, but identification schemes we have now are not 100% secure either. Question is, would benefits of national ID card outweigh the increase in security risk? Assuming there is an increase at all -- I had seen no proof that national ID card would be EASIER to hack/steal/fake than what have now.

Actually, I had seen many scenarios how it COULD be easier to hack or abuse than existing systems. Invariably, slightest scrutiny reveals that these hypothetical hacks/abuses rely on utterly stupid design.
 
True, but identification schemes we have now are not 100% secure either. Question is, would benefits of national ID card outweigh the increase in security risk? Assuming there is an increase at all -- I had seen no proof that national ID card would be EASIER to hack/steal/fake than what have now.

Actually, I had seen many scenarios how it COULD be easier to hack or abuse than existing systems. Invariably, slightest scrutiny reveals that these hypothetical hacks/abuses rely on utterly stupid design.

Generally because, currently, there is no one piece of universally accepted and without exception conclusively acknowledged piece of ID. Instead, we are required to present multiple pieces of independent ID. It is only when all of these independent pieces of ID concur that our identitiy is given the benefit of the doubt. It is generally going to be easier to fake/crack/spoof one ID than it is going to be to do the same to 3-4 seperate pieces of corporate, state and federal ID.
 
Generally because, currently, there is no one piece of universally accepted and without exception conclusively acknowledged piece of ID. Instead, we are required to present multiple pieces of independent ID. It is only when all of these independent pieces of ID concur that our identitiy is given the benefit of the doubt. It is generally going to be easier to fake/crack/spoof one ID than it is going to be to do the same to 3-4 seperate pieces of corporate, state and federal ID.

Doesn't a passport count as ID for all government purposes? And for non-government purposes, don't private companies set what ID they will except, meaning that part won't change?

IF it weren't for ease of use problems, I'd go with passports as ideal.
 
Doesn't a passport count as ID for all government purposes?

Generally, passports are only good for their primary purpose of US entry at the borders. Many agencies will accept them as federal ID documents on par with any other federal ID card.

And for non-government purposes, don't private companies set what ID they will except, meaning that part won't change?

IF it weren't for ease of use problems, I'd go with passports as ideal.

With one overarching Federal ID, it is more likely that in very short order no other form of ID will be considered acceptable or valid. After all the expense of implementing a national ID system, what would be their motivation to continue to accept other forms of ID? Other agencies may even drop their own independent forms of ID. It is this very concern that a national ID would quickly become the only valid and acceptable form of ID that makes a national ID card more likely to become both a major privacy issue concern and would undoubtedly quickly be linked to all manner of private and public databases making it more liable to spoofing, cracking and counterfeiting.
 
It is this very concern that a national ID would quickly become the only valid and acceptable form of ID that makes a national ID card more likely to become both a major privacy issue concern and would undoubtedly quickly be linked to all manner of private and public databases making it more liable to spoofing, cracking and counterfeiting.

If I understand your point correctly, as the value of a single form of identification goes up, the incentive to forge/hack it goes up as well. Has this actually happened in practice for government issued IDs?

I have to examples in mind. One, at the federal level, is the military identification card. This allows access to the PX, the military hospitals, a host of other discounts and benefits. I've even tendered it in lieu of a passport (although I am not sure if this is still allowed). Has that been hacked?

The second one I can think of is the food stamp or welfare benefits type card that people use to purchase goods. In some states, it acts just like a credit card with balances they can spend and so on. Has this been forged?

I know these are not as useful or as valuable as we hypothesize a national ID to be, but they are government issued and managed and do have value.

My logic goes like this: The reason some government issued IDs are not hacked is because there are easier targets. I think your response would be that once they become the norm they will essentially be the only target and hence hacked. But that allows a strong criticism in response -- the easier to hack are being hacked now. Then comes the argument that centralizing things makes it easier to get the entire prize with the variety of ID demanded preventing this. But isn't that the same thing as having multiple protections on a single document? I fail to see the difference, except that documents can be leveraged now so that getting one leads to others and so on.

I can start by forging your driver's license and work my way through all the rest, using that. With a single national ID we have a single target, but also only one thing to protect. How could you possibly expect high security on the several documents you use now (any of which can be leveraged to get the others) instead of one with a great deal of value, protection and oversight. The fact that it is valuable means we would protect it more than, say, your birth certificate. If it takes more effort to get several documents than it takes to get a single document, make that single document harder to hack by adding effort until it at least matches the multiple document idea.
 
Last edited:
If I understand your point correctly, as the value of a single form of identification goes up, the incentive to forge/hack it goes up as well. Has this actually happened in practice for government issued IDs?

I have to examples in mind. One, at the federal level, is the military identification card. This allows access to the PX, the military hospitals, a host of other discounts and benefits. I've even tendered it in lieu of a passport (although I am not sure if this is still allowed). Has that been hacked?

http://www.foxsanantonio.com/newsroom/top_stories/videos/vid_11055.shtml

http://arklatexhomepage.com/fulltext?nxd_id=6058

http://www.youtube.com/watch?v=dMxvKZFPDIg

Of course, we're only aware of the instances where the fakes were spotted.

The second one I can think of is the food stamp or welfare benefits type card that people use to purchase goods. In some states, it acts just like a credit card with balances they can spend and so on. Has this been forged?

http://www.newschannel5.com/story/1...tealing-welfare-benefits?clienttype=printable

http://www.abc57.com/news/state-and-regional/State-employee-charged-with-theft-156463345.html

Again, too common, and the prize isn't that spectacular even when committed with 100s of cards. I wonder how many individuals using fake cards in reasonably appropriate manners are getting away with their crime?

I know these are not as useful or as valuable as we hypothesize a national ID to be, but they are government issued and managed and do have value.

My logic goes like this: The reason some government issued IDs are not hacked is because there are easier targets. I think your response would be that once they become the norm they will essentially be the only target and hence hacked. But that allows a strong criticism in response -- the easier to hack are being hacked now. Then comes the argument that centralizing things makes it easier to get the entire prize with the variety of ID demanded preventing this. But isn't that the same thing as having multiple protections on a single document? I fail to see the difference, except that documents can be leveraged now so that getting one leads to others and so on.

I can start by forging your driver's license and work my way through all the rest, using that.

not really, a fake driver's license might give you a base to create a fake identity based on my name, but even if you had a copy of my DL to work from, you couldn't recreate or forge my complete ID profile based upon the information on my DL.

With a single national ID we have a single target, but also only one thing to protect. How could you possibly expect high security on the several documents you use now (any of which can be leveraged to get the others)...

that is your unsupported assertion, not something you have compellingly supported as of yet.

instead of one with a great deal of value, protection and oversight. The fact that it is valuable means we would protect it more than, say, your birth certificate. If it takes more effort to get several documents than it takes to get a single document, make that single document harder to hack by adding effort until it at least matches the multiple document idea.

Which would mean replacing what we have now with a more expensive single tie-together of all our information. One of the primary issues is that each of these current ID documents contains unique information distinct and seperate from what is contained on any of the other pieces of ID. The security resides in the privacy aspect of not having all of your information tied together and accessible in and from a single public database.
 
Trakar,

You make a strong case. I think you've swayed me, at least away from a naive "it will be better" point of view. Thanks.

If the issue is ever seriously considered, I'll make sure to see if they can convince me they've figured out all the problems.
 
.... Which would mean replacing what we have now with a more expensive single tie-together of all our information.....

I don't understand why a secure national ID would need to replace other IDs. It would simply demonstrate that a person is who he says, like a passport does now. A driver's license is now generally accepted for that purpose, but is much easier to obtain and much easier to forge. But most employers, private and public, issue their own work IDs for their own purposes, including access to specific work areas and particular buildings. Why would that change? If you ask a police officer for his ID, he'll show you his badge and departmental credentials, not his driver's license. Why would that change? If you get a government license for any purpose -- driving, flying, hunting, fishing, real estate, cosmetology -- the appropriate federal, state or local government agency issues a license that authorizes you to do that activity under specified conditions, and you can lose it if you violate them. College students get an ID to get into the dorms, cafeterias and library. Your health insurance issues an ID that shows what kind of coverage you have. Credit cards are a kind of ID, and you get a different one for every account. All kinds of entities issue all kinds of credentials for their own purposes. There is no reason to think that they wouldn't continue to do so. But for all of them the starting point is proving you are who you say. A fraud-resistant (let's agree that it would never be fraud-proof) standard ID would make it harder to commit fraud in obtaining those other credentials. The enhanced driver's license that some states now issue might ultimately function as a national ID as more states participate -- it would be issued by the states according to federal standards. But no one is talking about using it for other purposes. Nobody wants to link dorm access cards to medical records to fishing licenses to voter registration cards to Netflix accounts. Facebook, Google and the credit bureaus are probably bigger threats to privacy than a standard national ID would be.

http://www.dhs.gov/files/crossingborders/gc_1197575704846.shtm
 
Last edited:
I am rather fascinated by the discussion between Trakar and Bob001, as they seem to represent worldviews so fundamentally different, as agreement is impossible:
Bob001 said:
You seem to think that privacy and security are at opposite ends of a spectrum. I see security as something that enhances my privacy.
I see privacy as the foundation of security, the less privacy the less security one has.

Really? Imagine for a moment you have NO privacy -- you are one of those Internet exhibitionists who are on webcam 24 hours a day. You don't think you would be secure? If anyone tried to rob you, you'd have hundreds of witnesses. If police tried to do a Rodney King on your ass, same. If someone stole your identity and tried to buy a large-screen TV under your name, you have video footage demonstrating you were nowhere near the TV store at the time. Etc. Seriously, you cannot get much more secure than that.

Now, there are reasons why I do not want to live like that. But still, I mostly come down on Bob001's side, for practical reasons. Privacy has fled already, and Trakars of the world are trying to hold back the tide. As CEO of Sun Microsystems famously said "You have zero privacy anyway. Get over it." I'd rather make the best of the reality, like ensuring citizens have legal right to record police misconduct -- if you and I have no privacy, neither should government officials.

Trakar said:
You say that as if there was something wrong or improper and inadequate about "Mayberry?" I, personally, am of the opinion that small town communities are the ideal model for society. This doesn't mean atechnological, unsophisticated or antiquated, merely smaller community groups, largely decentralized, greatly self-sufficient, where people in the community know each other on a first name basis and the only privacy that is violated happens over a shared backyard fence or in the beauty/barber shops and local watering hole. I understand that this is alien to many people, but I don't insist that those who don't want to live that way abide by my druthers. Is there a viable means to opt out of your national ID and not severely impact or limit the lives of those who choose to opt out?
I don't know what town Trakar lives or had lived in, but in every small town I've been everyone had their nose in everyone else's business. That violation of privacy "over a shared backyard fence or in the beauty/barber shops and local watering hole" is FAR more intrusive than Trakar seems to think. Which is why small towns are such hellholes if you are gay, goth, or otherwise do not conform to local norm. You cannot hide.
 
I am rather fascinated by the discussion between Trakar and Bob001, as they seem to represent worldviews so fundamentally different, as agreement is impossible:...

The fundemental difference that you seem to have skipped over, in order to be functional, a national ID system requires near 100% participation to be effective. Privacy is a voluntary issue, individuals may sacrifice as much of their own as they wish without seriously impacting the privacy of others. If you can come up with a system that protects the privacy (the ability to opt-out of the national ID system) of those who value privacy without them being severely disadvantaged, I'd have no problem at all. Forcing those who value privacy to sacrifice that which they value so that others can enjoy a false sense of security, however, is unacceptable.
 
Last edited:
...I don't know what town Trakar lives or had lived in, but in every small town I've been everyone had their nose in everyone else's business. That violation of privacy "over a shared backyard fence or in the beauty/barber shops and local watering hole" is FAR more intrusive than Trakar seems to think. Which is why small towns are such hellholes if you are gay, goth, or otherwise do not conform to local norm. You cannot hide.

And you think one ID which can track all of one's reading, clubbing, purchases and travels is going to help those who wish to hide from those who seek to discriminate against people who make choices like those who wish to hide their choices?

Your bad experiences aren't due to small towns, rather they are due to the particular small towns you had experience in; these experiences sound predominantly like small towns where the majority of the inhabitants shared different social customs or attitudes than those you embrace. In a large city people tend to exagerate their differences and distinctions from the norm they perceive just to stand out among the crowd, in small communities more subtle approaches suffice. Even within the largest metropolitan areas, people tend to cluster into smaller communities of like-thinking individuals, the fact that they don't deliniate each small community into seperate townships doesn't mean that they aren't effectively distinctive, and individual communities.
 
Some of you need to go read 1984.
Ah yes. The kind of state where any hacker would have been shot without trial. If Oceania had electronic records, do you think private citizens would have been able to rummage it with impunity the way Trakar describes?

I noticed this is a very common pattern among people paranoid about electronic identification (card, implanted, whatever):

1) They claim it is an evil government plot to keep an eye on everyone. Debatable, but fair enough.

2) They come up with all sorts of ways such electronic system could be hacked/abused by individuals. Invariably, slightest scrutiny reveals that these hypothetical hacks/abuses rely on utterly stupid design.

3) At which point they say "Do you expect the government to come up with SMART design?", completely ignoring that hackable/stupid design makes the entire system useless for the nefarious purposes they claimed in (1).
 
Last edited:
And you think one ID which can track all of one's reading, clubbing, purchases and travels is going to help those who wish to hide from those who seek to discriminate against people who make choices like those who wish to hide their choices?
It works both ways. If homophobes can seek out and target gays, gays -- or straight people who do not tolerate homphobia, -- can seek out and publicly shame homophobes.

As I already said -- privacy is dead. Transparency is here. Best you can hope for is two-way transparency, where anyone watching you is himself visible.
 
Ah yes. The kind of state where any hacker would have been shot without trial. If Oceania had electronic records, do you think private citizens would have been able to rummage it with impunity the way Trakar describes?

I noticed this is a very common pattern among people paranoid about electronic identification (card, implanted, whatever):

1) They claim it is an evil government plot to keep an eye on everyone. Debatable, but fair enough.

2) They come up with all sorts of ways such electronic system could be hacked/abused by individuals. Invariably, slightest scrutiny reveals that these hypothetical hacks/abuses rely on utterly stupid design.

3) At which point they say "Do you expect the government to come up with SMART design?", completely ignoring that hackable/stupid design makes the entire system useless for the nefarious purposes they claimed in (1).

None of these are arguments I have used, nor are they serious concerns of mine. I am largely unconcerned about government tracking, I am concerned about making it easier for malicious individuals and corporate entities to invade the privacy of others by only having a single point of attack to access an individual's entire information and identity profile.
 
It works both ways. If homophobes can seek out and target gays, gays -- or straight people who do not tolerate homphobia, -- can seek out and publicly shame homophobes.

As I already said -- privacy is dead. Transparency is here. Best you can hope for is two-way transparency, where anyone watching you is himself visible.

As I stated, design a system that excludes the possibility of it disadvantaging and/or discriminating against those who opt out of participating in it, and allow that as an option for all, and I would have no problem with such a voluntary national ID system.
 
None of these are arguments I have used, nor are they serious concerns of mine. I am largely unconcerned about government tracking, I am concerned about making it easier for malicious individuals and corporate entities to invade the privacy of others by only having a single point of attack to access an individual's entire information and identity profile.

I agree. You haven't gone down the paranoia road, and it makes your arguments stronger. However, I am now wondering why it has to be "an individual's entire information and identity profile" if it's just an ID card?

Arguably, these things are distinct. For example, I already carry around a couple pieces of ID: my fingerprints and my DNA. These are (purportedly) unique to me and could be used for identity. Isn't it really a problem about who links to my identity and what they associate with it?

How would a system be different if it used these existing forms of ID -- one we don't have to purchase and one we carry with us anyhow. I think you're argument is more about databases than strictly about identification.

The databases are the responsibility of the data holders. If, for example, a credit card company issues credit based on spoofed ID, I have no liability. And when databases are misused (for example, a release of medical records) I can sue to recover damages.

It seems the harm is to those who handle the data, not to me.

Unless you believe a loss of privacy is a harm, in and of itself.

I support transparency for those who hold my data and would like the right to dispute what they hold or prevent some types of information from being stored at all.
 
Last edited:

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom