>Truly there are almost zero situations in which an entity needs to know your real identity.
1000 percent this!
What entities really need to know to do their function is shockingly small compared to what they ask for. Here are some examples:
- Bank: proof you are authorized to make decisions for a given bank account. (Possibly jurisdiction info if the government forces banks to screen on citizenship.)
- Voting: proof that you didn't vote twice. (Possibly jurisdiction info if you are only allowed to vote in a specific area.)
- Job: a nickname, contact info, where to send compensation, a way to grant (and revoke when terminated) your access to non-public information. (Possibly jurisdiction info if the government forces companies to screen on citizenship or calculate taxes in a specific way.)
- Social media network: way for others to connect with you (eg email).
- Bars: (possibly proof of age, if the government forces establishments to limit sales on that basis.)
- Online or in-person payments: proof that the funds transferred to the business's account.
They ask for it. They may currently require it. They don't necessarily need it.
E.g. Some medical services may need to know your medical history. Others need just some token that lets the bureaucracy figure out who to ultimately bill for it. Leasing/crediting services - well, they'd love to know everything about you, but that doesn't mean they should get it.
No, all these services need my identity in order to offer me services that i want/need (my blood analysis results, bank account including cards/loans/leases, IRS, DMV, etc. Basically everything that is tied to my real identity and should be seen/accessed only by myself).
I am not from US so just using IRS/DMV as comparable examples. Third party ID providers or Government ID provider returns only my name and personal UID to all these services.
Maybe in the USA but i am not from there. All these services require to log in with your real identity at least once and depending on the service you can use it with your set up email address in read only mode, for example the DMV equivalent service allows you to see your vehicles, tickets (and pay them) and other info but in order to change vehicle owner you will have to log in with real identity provider.
My point is: these services may require identity, but they don't truly need it, could work without it, and it's only a bad design that they do ask for it.
I do agree that i could use anything (email, phone etc.) to login in those services but this "something" would be still mapped/tied to my real identity (in a previously validated way). So if it is the first time i am using DMV online service, i can login using my real identity because that is much easier than going to real world location and getting my account credentials.
> >Truly there are almost zero situations in which an entity needs to know your real identity.
> 1000 percent this!
> What entities really need to know to do their function is shockingly small compared to what they ask for. Here are some examples:
> - Bank: proof you are authorized to make decisions for a given bank account. (Possibly jurisdiction info if the government forces banks to screen on citizenship.)
> - Voting: proof that you didn't vote twice. (Possibly jurisdiction info if you are only allowed to vote in a specific area.)
> - Job: a nickname, contact info, where to send compensation, a way to grant (and revoke when terminated) your access to non-public information. (Possibly jurisdiction info if the government forces companies to screen on citizenship or calculate taxes in a specific way.)
> - Social media network: way for others to connect with you (eg email).
> - Bars: (possibly proof of age, if the government forces establishments to limit sales on that basis.)
> - Online or in-person payments: proof that the funds transferred to the business's account.
But for all of these use cases, who would be the provider of these attributes to the third parties? Haven't we already seen issues with centralization of identifying information? (Like the case with the OPM breach?)
What if you apply for a state benefits (e.g. benefits for your children, or student state grants)? These kind of services being accessible online are common in the Nordics and when authenticating the service provider would need to know a lot of personal information such as name, age, adress or email, previous given benefits records from other service providers, current loan debt status, university registration status, bank account nr, family members etc...
Zero knowledge proof in identity is a thing, but then the assurance of identity falls on a third party that has to verify your identity. There is also Self-Sovereign Identity and user-centric identity management which many consider the future of identity. But even in that case, most often a third party needs to at least maintain the infrastructure of where your identity is stored.
> What if you apply for a state benefits (e.g. benefits for your children, or student state grants)?
The best solution in this case is to stop means testing them, and also convert every plausible benefit from stuff to cash-to-buy-stuff-with (i.e. UBI). Because at that point it's the same as voting, all you have to prove is citizenship and that you haven't already received the benefit, there is no separate eligibility information required.
People have the intuition that not means testing things would be expensive, but when the benefit is in cash that comes out in the wash. If you receive $5000 more in cash than the value of the benefits you were previously eligible for, but then have to pay $5000 more in tax, it just cancels out and you're back to the original situation. Only now nobody has to prove eligibility status outside of basic citizenship, which also greatly reduces administrative costs and fraud.
Perhaps you are right, but we have to create systems for the needs of today's society as well, and in today's society you need to be eligible for a certain benefit in order to get it. Therefore, we need a person's identity (with all the personal information that are required for such eligibility to be checked) when that person is authenticating online and applying for that benefit.
> The best solution in this case is to stop means testing them, and also convert every plausible benefit from stuff to cash-to-buy-stuff-with (i.e. UBI). Because at that point it's the same as voting, all you have to prove is citizenship and that you haven't already received the benefit, there is no separate eligibility information required.
How do you prove that you did not already receive a government ID, and go back and get five more with different names and numbers on them? Same question, same answer.
This is good stuff but in one case at least - jobs - add to your list the need to perform background checks during the application process, which does require an actual identity verification.
Background checks? Maybe if you're joining the secret service. In most cases the employer just needs to check that the qualifications you claim to have are genuine.
Probably you should be allowed to keep quiet about qualifications that you don't want to claim. I read about a case in which a factory worker was sacked with the justification that they had failed to declare their university degrees when applying for the job. They had a degree in politics and the employer believed (probably correctly) that they had got the job specifically in order to be a trade union activist. However, whether that ought to be a valid reason for dismissing an employee is another question.
Amusing story! But in some countries (not sure about the US) it is common to perform a criminal record check, credit check etc. on new employees. In high compliance environments (e.g banks) the checks may span any countries you have resided/worked in for the previous few years.
Given the verifier has physical control over the location in which the verifiee must verify themself, it's trivial to ask for info only accessible from that location at that time.
As for determining your jurisdiction, that usually means residency, which off the top of my head could be minimally verified by govt proof via (redacted) taxes filed in that state.
I am just speculating but if they don't provide door to door delivery then you probably have to upload whatever documents they need defined by law. This clears them and it doesn't matter that they are sending stuff to a mail forwarder as now you are committing a crime.
Convicts being able to be employed is likely a net good for society at large. There are also countries where asking whether someone was ever convicted of a crime is not the default and they are fine.
Or invert the push requirement to a pull one: instead of citizens being required to give a valid method of immediate contact, require that they check for new messages at regular intervals. Failure to do so would be the same as ignoring push notifications.
1000 percent this!
What entities really need to know to do their function is shockingly small compared to what they ask for. Here are some examples:
- Bank: proof you are authorized to make decisions for a given bank account. (Possibly jurisdiction info if the government forces banks to screen on citizenship.)
- Voting: proof that you didn't vote twice. (Possibly jurisdiction info if you are only allowed to vote in a specific area.)
- Job: a nickname, contact info, where to send compensation, a way to grant (and revoke when terminated) your access to non-public information. (Possibly jurisdiction info if the government forces companies to screen on citizenship or calculate taxes in a specific way.)
- Social media network: way for others to connect with you (eg email).
- Bars: (possibly proof of age, if the government forces establishments to limit sales on that basis.)
- Online or in-person payments: proof that the funds transferred to the business's account.