News: 1626782470

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Verified: UK.gov launching plans for yet another digital identity scheme

(2021/07/20)


The UK government is launching proposals to boost the legal status of digital identities, something it claims will ensure they are trusted as much as physical documents such as passports.

The blueprint suggests the technology could take a number of forms such as a phone app or a web-based service.

The government today argued digital identities could help reduce cases of online fraud because they are much harder for criminals to access and replicate than other types of online personal data such as dates of birth.

[1]

Some 220,000 cases of personal data abuse and impersonation were recorded in the UK during 2019, according to govnernment figures.

[2]

[3]

In its proposals, the government also said it thinks digital identities were an easy way to help individuals prove age or qualifications without requiring physical documents.

The intent is to create a governing body that would be charged with making sure organisations follow government rules on online authentication, identity and eligibility solutions.

[4]UK's Government Digital Service extends contracts with Post Office and Digidentity for wobbly Verify ID system

[5]If Tesco was prodded and probed by hackers, your data could be being flogged for just £2.70 – research

[6]UK.gov drives ever further into Nocluesville, crowdsources how to solve digital identity

[7]Your entire ID is worth £820 to crooks on dark web black market

The [8]consultation has asked for feedback on three issues: the governance system to oversee digital identity and make sure organisations comply with the rules; how it might allow trusted organisations to make digital checks against authoritative government-held data; and the legal validity of digital identities.

Digital infrastructure minister Matt Warman said: "Digital identities offer a huge opportunity to make checks easier, quicker and more secure, and help people who do not have traditional forms of ID to prove who they are. This technology is a vital building block for the economy of the future, and we're ensuring that people who choose to use it can have confidence their data will be handled safely."

[9]

The consultation said digital identity would offer people who do not have access to an official document, such as a passport for example, the ability to prove their identity digitally through another government service, a trusted individual such as a doctor, or another trustworthy source.

Second verse, same as the first

The UK government has been here before, of course. Back in 2015, then Cabinet Office minister [10]Mad Frankie [11]Maude said the government was working with industry to look into the potential for ID assurance services to be used more extensively in the private sector.

The government was at the time developing its own Verify system to offer access to government services. Digidentity and Experian were the early certified providers, with Mydex, the Post Office and Verizon set to join later.

But by 2016, [12]the Department for Work and Pensions began developing its own online identity tool to ensure a secure transaction with government services. It was slated as an alternative to Government Digital Service's Verify, which had repeatedly missed its sign-up targets over its four-year programme.

The Verify service [13]went live in 2016.

[14]

Earlier this year [15]contracts with Digidentity and the Post Office were extended in deals worth £5m to keep the service up and running, even though it was experiencing significant issues at the time.

Verify was branded as a mess in 2019, with the National Audit Office saying it had "significantly" missed every target, and the Public Accounts Committee claiming it was "unsccessfully implemented, was badly designed, and had technical difficulties that lacked the necessary departmental and leadership buy-in".

Ouch. ®

Get our [16]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPbzJmkbogVBSupxWMSt9AAAAAE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPbzJmkbogVBSupxWMSt9AAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPbzJmkbogVBSupxWMSt9AAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/06/11/post_office_digidentity_verify_extensions/

[5] https://www.theregister.com/2020/03/04/tesco_clubcard_600k_new_cards/

[6] https://www.theregister.com/2019/07/19/gov_asks_public_how_to_solve_digital_identity/

[7] https://www.theregister.com/2018/03/08/dark_web_market_price_index/

[8] https://www.gov.uk/government/consultations/digital-identity-and-attributes-consultation

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPbzJmkbogVBSupxWMSt9AAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2015/02/02/cabinet_office_francis_maude_retires_from_government_axe/

[11] https://www.theregister.com/2015/02/06/identity_assurance_services_cut_cost_fraud_businesses_maude/

[12] https://www.theregister.com/2016/01/14/dwp_indicates_its_building_a_separate_online_id_tool/

[13] https://identityassurance.blog.gov.uk/2016/05/19/gov-uk-verify-update-on-progress-were-ready-to-go-live/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPbzJmkbogVBSupxWMSt9AAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2021/06/11/post_office_digidentity_verify_extensions/

[16] https://whitepapers.theregister.com/



OK we get it....

IGotOut

Covid scams are so last year, so your Eton chums need a new shit load of cash for doing fuck all.

Re: OK we get it....

Version 1.0

And the ransomware writers will have a new target.

Got to keep the gravy train rolling

bronskimac

Serco or Crapita for the megabuck contract?

Re: Got to keep the gravy train rolling

Anonymous Coward

Atos, for that Gallic post-Brexit punch to the nuts.

Re: Serco or Crapita

Flocke Kroes

I'm betting on Palantir as the sccessful provider.

Re: Got to keep the gravy train rolling

R Soul

Nah. This can only be a job for Fujitsu.

The whole project can be overseen by Dildo Harding. She's got time on her hands after spunking away £53B on the spectacularly successful track and trace.

I see another overly expensive failure on the horizon

Dave 15

Of course the contract will go to a foreign firm - no civil servant would miss on the business trips abroad clearly required to negotiate the billions of contract that leads to the nice little earner for family/friends/themselves.

The foreign firm will charge per engineer per day what they are paying in bangalore per month.

The contract will of course indemnify the company if through their failure to deliver the contract is cancelled.

Then of course we have the 'what the hell is this' which will come out of it.

After all the only real way to have a meaningful digital identity is some sort of key based setup. But where are people going to store the keys? On their phones or laptops - places where the key is going to end up being stolen. Or, the phone is lost/breaks and suddenly you cant do anything (even get in touch with the government scheme) to get a new set of private keys to go on your new device and cancel the keys on the old one.

There is really no obvious and good way to mak such a scheme actually work

Then there is the worst of all, its a snoopers charter, as soon as gvmt has conned (sorry persuaded the gullible) into having a digital identity they will force every website to make you enter it so they can track everything you do, every page you view, every post you make - all in the name of protecting kids and avoiding terrorism

D'oh

Nafesy

Stopped reading at "the government also said it thinks digital identities were an easy way to"... it's like they don't have a clue... ah.... well.... yes

Re: D'oh

Chris G

I have a snappy name for it, we could call it STASI: Secure Technology Authenticating Subjects Identity.

It makes so much sense to put all of you identity including qualifications etc into one govermment data base, after all, who could the British people trust more with all of their life's details?

Now, where did I put that sarcasm icon?

Re: Sarcasm icon.

TimMaher

You left it behind a bus stop in Kent.

Re: D'oh

Anonymous Coward

I have a whole bunch of digital identities - does this mean I can show that I've been vaccinated 15 times?

poohbear

" trusted organisations"

How much did you donate to the Tory party in the last three years?

J.G.Harston

Instead of the gvvnt picking and choosing and thrusting something upon providers, why don't providers work out for themselves what they need. The government didn't invent ATM machines, standing orders or direct debits, banks did. The government didn't invent the clinical software systems almost all GP practices use, SystmOn, EMIS and Vision did*.

*Other clinical systems may be available, those are the ones I have experience with.

elsergiovolador

Companies can weasel out of any responsibility currently, so they have no incentive to develop any systems that would prevent fraud.

If, for example, banks would be required by law to refund any fraudulent transfer, then maybe they would stop sitting on their hands.

Dan 55

I don't see how 100 flowers could bloom when it's the government that has the monopoly on identity. Most problems stem from the government being unable to lay out a spec and roping the private sector in to fill in the blanks. E.g. why on earth would the government need Experian to verify who you are since between the Passport Office, the DVLA, and the DWP they should know already.

Also bank security is handwavy nonsense (banking apps, SMS 2FA, credit card number algorithm, online payment gateways, 3D secure...).

Anonymous Coward

Just save us all a lot of time and money and throw the money allocated in the bin. We all know these schemes just line the pockets of politicians and business partners with no benefit to the public

Case in point: HS2

Anonymous Coward

I love the cynicism on here.

Chris G

@AC

Cynicism implies that there is doubt about thr outcome, whereas the attitude here is fueled by history, experience and certainty. If the British government is going for any all embracing system involving technology, any successes will be in spite of government involvment not because of it.

Anonymous Coward

Cynicism?

It's called experience. We have a lot of it. Most of us have seen this all before so many times.

Anonymous Coward

rather than 'experience', which can go along a parameter of 'variable', I'd prefer to use a term 'remarkably consistent track record' :/

Cynic

TimMaher

“To be a true cynic you must first be a true romantic”Me circa 1976.

The solution

elsergiovolador

I know what would reduce fraud:

Agencies that actually do their job. If you ever had a pleasure of reporting fraud, you would notice that you will be tossed from one place to another and some bodies like Trading Standards would sound like being on the side of fraudsters and would do their best to discourage you from any action.

Digital ID is embarrassingly easy ...

JimmyPage

... it's crowbarring all that 1984 goodness into it that's the problem.

Don't hold your breath

Long John Silver

The government, the current one especially so, has a solid track record of incompetence and waste regarding contracting for software development.

Perhaps a phone 'app' shall appear. One way or another it will be hackable or circumventable.

The NHS 'app' relating to 'track and trace' is a risible failure at three levels.

First, its conception in context of a moderately severe 'flu-like epidemic.

Second in its construction and use; notable at present is endangerment to the economy via "pingdemic".

Third, it, as is or modified to be an 'internal passport'', is impracticable as a 'real time' identity and immunisation status checker. A robust and rapidly responding online database capable of coping with immense numbers of peak time requests is pie in the sky. Reality would be delayed responses and frequent crashes. If the 'app' is intended to allow entry to restricted premises it will end up with extremely angry users and similarly cross owners of premises. It stands to fail spectacularly.

If points raised for the third level hold then the 'app' must be designed to cope with being unable always to phone home. That entails the device running the 'app' holding an updatable version of the central record. That easily can be altered and the device when interrogated could falsely indicate connection to the central database. Doorkeepers lack forensic computing skills.

That said, such an 'app', should point four be acknowledged, could be a success in terms of widespread uptake by a suitably gulled populace. Having a small self-directed percentage of the population play ducks and drakes with it must be regarded inevitable and not stoppable.

I shall play with my feathered friends.

Adair

It's the 'One Ring To Rule Them All' approach to 'Identity authentication' that really fucks everything up - it's like trying to reach the last Prime Number: you know there's almost certainly another one out there somewhere.

Likewise with an all embracing 'Identity' scheme - there's always going to be another almighty, hair tearing, life destroying, freedom stifling, corrupt as hell fuck-up out there somewhere, that will demonstrated conclusively that the concept of of a 'One Ring To Rule Them All' identity scheme is a crushing monument to political hubris and stupidity, not to mention greed (that always fits in somewhere).

Infinitude of Primes

Anonymous Coward

> it's like trying to reach the last Prime Number: you know there's almost

> certainly another one out there somewhere.

"almost certainly" should be "absolutely definitely".

Euclid proved it around 300BC.

https://en.wikipedia.org/wiki/Euclid%27s_theorem

Re: Infinitude of Primes

Adair

Yes, but it's the finding of it - like looking for a tiger in the long grass. It could be right there, about to rip your head off, or you could go for months and still not find it.

Laugh, or cry?

Freezus

"Digital identities could help reduce cases of online fraud because they are much harder for criminals to access"

Re: Laugh, or cry?

Arthur the cat

Scream in frustration.

What's the high level picture...

ColinPa

Can someone explain to me how this would be used.

1) I understand having a smart card which I can use/wave around - like like a contactless credit card ( can we use the same technology?)

2) How would we do online stuff. Do I need a Hardware key I plug into the side of my computer so it can use my private key.

3) How do I validate someone who has sent me a data file/contract/money

4) My bank gives me a card reader, I enter my card, type my pin, and enter the encrypted value in an online session.

In simple terms what's the difference between a credit card and a private identity. The infrastructure is there. The banks validate "certificates" and I could get a "bank statement" with the name of the person who owns the identity.

Just asking....

Re: What's the high level picture...

Fonant

I think the problem, as the government sees it, is that they don't get to track everyone with the current situation.

For us, this is a Good Thing.

We currently have multiple "identities", each one suited pretty well for the task we use it for. This works well and has each identity quite nicely separated, so if one is breached the others aren't affected.

Trying to have one "identity" that works as a bank card, passport, COVID-19 vaccination record, Windrush immigration record, password for all those websites, Tax Account Number, age verification, NHS number, Amazon account, Company Director registration, milk round number, etc. is (a) impossible and (b) a disaster waiting to happen when something goes wrong.

eID

Anonymous Coward

https://e-estonia.com/eid-in-estonia/ no central db of data, and smart card, SIM based, or mobile software that's initially configured using the smart card for authentication. Digital ID and signing, it's considered secure enough for property purchase. [don't mention voting!]

I guess when there's 65M people using it instead of 1.2M we'll really see how secure it is

Verified: UK.gov launching plans for yet another digital identity scheme

Anonymous Coward

is it being launched to give a top position to a Hancock and they couldn't squeeze him into anything else?

Trust the government with your identity …

Arthur the cat

and you get [1]this mess when the records go wrong and the government decides you're dead. And that's without computers being involved.

[1] https://www.theguardian.com/world/2021/jan/12/french-woman-spends-three-years-trying-to-prove-she-is-not-dead

Er, what?

yetanotheraoc

" the government also said it thinks digital identities were an easy way to help individuals prove age or qualifications without requiring physical documents." ... and ... "help people who do not have traditional forms of ID to prove who they are."

How does one get this digital ID in the first place? Could my partner who knows all my personal details just enter those details into a web form and then use that ID to sell my house?

To my mind, the only way to get a digital ID must be to first get a non-digital ID, or at least have sufficient documentation to satisfy the requirements of a non-digital ID, *and be physically present* at issue, otherwise it's ludicrous to say it's equally valid. And after you solve that problem, then there are still all the phishing and tracking and digital forgeries problems to solve.

But of course nobody of any importance cares what engineers think.

You have an unusual equipment for success. Be sure to use it properly.