Slashdot Mirror


Obama Eyeing Internet ID For Americans

Pickens writes "CBS News reports that the Obama administration is currently drafting the National Strategy for Trusted Identities in Cyberspace, which will be released by the president in the next few months. 'We are not talking about a national ID card,' says Commerce Secretary Gary Locke, whose department will be in charge of the program. 'We are not talking about a government-controlled system. What we are talking about is enhancing online security and privacy and reducing and perhaps even eliminating the need to memorize a dozen passwords, through creation and use of more trusted digital identities.' Although details have not been finalized, the 'trusted identity' may take the form of a smart card or digital certificate that would prove online users are who they say they are. These digital IDs would be offered to consumers by online vendors for financial transactions. White House Cybersecurity Coordinator Howard Schmidt says that anonymity and pseudonymity will remain possible on the Internet. 'I don't have to get a credential if I don't want to,' says Schmidt. There's no chance that 'a centralized database will emerge,' and 'we need the private sector to lead the implementation of this.'"

44 of 487 comments (clear)

  1. how about no by trolman · · Score: 5, Insightful

    This Internet ID scheme has been floated a couple of times now and it is not going to happen. The Federal Government like big companies and big programs aka Comcast/NBC, Net Control(net neutrality) and National Healthcare. It is about controlling the most people with the least effort. This is no different than requiring me to 'show my papers.' All of this really needs to stop. --If the feds need something to do they could start by implementing IPv6 and getting everyone an IP address.

    1. Re:how about no by transami · · Score: 4, Interesting

      "If the feds need something to do they could start by implementing IPv6 and getting everyone an IP address."

      +1 (x 2^128)

      --
      :T:R:A:N:S:
    2. Re:how about no by arivanov · · Score: 5, Interesting

      Typical American paranoia. Not that UK is much better.

      Anyway, I have had a Bulgarian digital ID for nearly 4 years now. It is privately run - there are several companies which have been licensed to issue the certificates and they issue certs/smartcards to individuals and businesses. The govmint has nothing to do with it besides being obliged by law to accept a smartcard signed electronic document as a valid signature in any form of communication. I can sign a contract, sign my tax return, sell/buy stuff that requires a signed contract, give instructions to my bank and all of these are _EQUALLY_ legally binding to me showing up with a passport/ID and signing it in person. On top of that most cert authorities and smartcards fully support Linux at least on x86 so you do not even need to pay MSFT tax to use it.

      On the negative side, banks, etc have been pretty quick on the uptake that this is an acknowledged and transactions are legally binding so you cannot do any electronic banking without it any more.

      In any case - an example where "technological backwater" "undeveloped" "fifth world economy" and "third rate democracy" (all are labels which BG has had in USA press at various times) shows how this _CAN_ be run as a useful tool for individuals and companies to do business without the govmint having anything to do with it besides collecting some license revenue.

      --
      Baker's Law: Misery no longer loves company. Nowadays it insists on it
      http://www.sigsegv.cx/
    3. Re:how about no by Lawrence_Bird · · Score: 4, Insightful

      exactly. typical nannystatery, looking to solve a problem that does not exist with a government sponsored effort. And who for a moment doesn't think that this would carry advantages for the 3 letter boys and girls?

    4. Re:how about no by Anonymous Coward · · Score: 5, Insightful

      Yeah, typical paranoia. You write: "you cannot do any electronic banking without it any more." "I don't have to get a credential if I don't want to," says Schmidt. Of course the government will not make a central database when it gets tax return files signed by everyone in the country. No, certainly not. How stupid do you and the government think we are?

    5. Re:how about no by Anonymous Coward · · Score: 3, Insightful

      Typical American paranoia. Not that UK is much better.

      Anyway, I have had a Bulgarian digital ID for nearly 4 years now. It is privately run - there are several companies which have been licensed to issue the certificates and they issue certs/smartcards to individuals and businesses. The govmint has nothing to do with it besides being obliged by law to accept a smartcard signed electronic document as a valid signature in any form of communication. I can sign a contract, sign my tax return, sell/buy stuff that requires a signed contract, give instructions to my bank and all of these are _EQUALLY_ legally binding to me showing up with a passport/ID and signing it in person. On top of that most cert authorities and smartcards fully support Linux at least on x86 so you do not even need to pay MSFT tax to use it.

      On the negative side, banks, etc have been pretty quick on the uptake that this is an acknowledged and transactions are legally binding so you cannot do any electronic banking without it any more.

      In any case - an example where "technological backwater" "undeveloped" "fifth world economy" and "third rate democracy" (all are labels which BG has had in USA press at various times) shows how this _CAN_ be run as a useful tool for individuals and companies to do business without the govmint having anything to do with it besides collecting some license revenue.

      So if the smartcard was spoofed, we'd be right fucked, huh.

    6. Re:how about no by Seumas · · Score: 5, Interesting

      I'm sure Bulgaria has absolutely no political corruption and that everyone in the government is absolutely trustworthy and that there is and was absolutely nothing shady about the selection of the private entity (yay, another government utility monopoly!) to provide the services and that there are absolutely no questionable connections between government officials and the selected company, just like there are no relations in America between officials and the selection of companies like Haliburton, L-3, and various FDA fast-tracks, either.

      I don't know a lot about Bulgaria, but Americans and Brits tend not to like to be identified and monitored, though their government and the stupider sheep among the population constantly do everything they can to undermine this desire. It's abhorrent enough that our SS# has gone from being something you ONLY provide to your employer to set aside SS tax in your account and to the government when you're ready to withdraw and has instead come to be used to get a driver's license, create a cell phone account, cable account, internet account, bank account, blockbuster rental account, etc.

      Let's either value privacy and autonomy or throw up our hands and quit this charade and go full bore into fully complying with all wishes and desire of the motherland.

    7. Re:how about no by Culture20 · · Score: 4, Insightful

      Typical American paranoia.

      There may be countries where the government is trustworthy enough to allow this. But the United States isn't one of them.

      In fact, the government was set up to not trust itself. The framers of the constitution didn't trust the government they were creating, so they crafted it to be full of gridlock.

    8. Re:how about no by Anonymous Coward · · Score: 5, Funny

      'Nanny state' is a teabagger code word for Democratic lead government. Republicans get a free pass from you'all as God puts them in power to extend his justice (or so you'all would seem to claim).

      And... Using the word "teabagger" in an argument is liberal code for, "I think Anderson Cooper is really hot and maybe I'll come out of the closet."

    9. Re:how about no by hedwards · · Score: 4, Informative

      National Healthcare is about controlling people?

      Two questions, what have you been smoking? And where can I get some?

      The Internet ID is genuinely that bad an idea, as is failing to provide real net neutrality rules, but you've got to be high if you think that national health care is some sort of infringement on your rights. There are exemptions baked into it for people that genuinely can't afford it or have religious objections to it.

    10. Re:how about no by Sloppy · · Score: 4, Insightful

      Um, yeah, that's why we were all complaining about the Nanny State when Bush had Ashcroft go after the state of California over medical mariju-- wait, were we talking about Democrats?

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    11. Re:how about no by Chapter80 · · Score: 5, Insightful

      You mean all Americans are going to end up in concentration camps because of this digital ID? Look-up paranoia.

      Naaah, not everyone. Just the bad guys. And the dissidents. Potential terrorists, and neo-nazis, too. And anyone who is on the TSA no-fly list. Really, any foreigners. And those who are against the 2-party system. Those tea-party wackos should really be identified and tracked. Lump the libertarians and green party people in there, too, because you really never know when they might "fringe out on us". What's the harm in "identifying" and "tracking" them. Especially if they're not doing anything wrong. What could they possibly be afraid of?

      And if someone is a crack addict, we should track that. We don't want those people in power, or flying our planes. We certainly don't want to give them access to large sums of money. You have to admit, tracking crack addicts is a good idea.

      But not a single person has ever *started* with crack. Usually they start with marijuana or alcohol. Don't believe me? Well, we should track that. We can actually predict which people are more prone to become crack addicts, simply by tracking the population, their purchases, and their habits.

      Really, we shouldn't let someone behind the wheel, if they have purchased open liquor within the past 2 hours. We should track that.

      And the people who are causing our healthcare costs to skyrocket. Especially those with Aids. And a genetic disposition toward expensive illnesses.

      This country was founded with a strong religious bias, and God wants it that way. We should identify the atheists too. And the evolutionists. How dare you say I'm part monkey.

      Really, the only ones who can be trusted are the ones like me. In thought, actions, beliefs, genetics, and disposition. So we need to classify and identify. No need to tattoo their arms - that's old school. Let's just track them by ID. No harm. If you aren't doing anything wrong, what is there to fear? I know I don't do anything wrong. I'll sign up, and even maintain the database for free.

      They came first for the Communists,
      and I didn't speak up because I wasn't a Communist.

      Then they came for the trade unionists,
      and I didn't speak up because I wasn't a trade unionist.

      Then they came for the Jews,
      and I didn't speak up because I wasn't a Jew.

      Then they came for me
      and by that time no one was left to speak up.

    12. Re:how about no by patjhal · · Score: 3, Insightful

      I do not normally criticize but your comment is dumb. It specifically says this is to simplify and make more secure important transactions like using the bank. Too many people use 4 or 6 character passwords on their banking that they share with other sites because of password overload. This is supposed to give them something more secure like an ssh key for that type of thing. You can still post anonymously to slashdot or make some temp facebook account or whatever. Now I understand the slippery slope argument that in future laws could be passed requiring this id, much like people say with the social security number. I feel something like this is needed and it is our responsibility as the electorate to make sure it goes no further than securing transactions that need securing. Fact is if they required it for too many things then it becomes increasingly easy to get plucked in an identity theft type of way and it looses its power (like the way SSN's are so important now that you never really give it to anyone except in the most important occasions like bank accounts, national security clearance, after you are offered a job, etc.)

    13. Re:how about no by gandhi_2 · · Score: 5, Funny

      Problem that doesn't exist????

      You don't get it. This could solve child porn, terrorism, and free expression in one shot!

    14. Re:how about no by Miamicanes · · Score: 5, Insightful

      > If someone can sign your name on a paper and send it by mail you'd be fucked to. ...

      Actually, no. You could legitimately argue (in court, if necessary) that your signature was forged. Forgery is so common, assertions of it in court are almost automatically accepted by juries as credible unless the party claiming it's legitimate can bend over backwards and demonstrate (through supporting evidence, like driver's license data, video surveillance footage showing the individual perform the transaction, etc) overwhelming evidence that it's legitimate.

      Smart card-based certificates upset that delicate balance of power. They don't prove that it was signed by you, but they do prove (almost beyond doubt) that something was signed by someone with physical possession of your card/cert and knowledge of its security code. Thus, they instantly shift the issue from claims by the victim that his signature was forged (something that's happened throughout human history, is commonplace, and an easy defense for consumers to successfully raise in court) to claims by the banks that you were negligent in your handling of the certificate and/or its security code. As a consumer, you have basically no duty to prevent someone else from forging your signature, because you can't. And the scenarios where banks could claim you were negligent would be almost impossible for them to prove. In contrast, with the cert/card, if anything goes wrong, banks have a MUCH easier time of shifting liability to you, the consumer.

      You could argue that a similar situation exists with ATM cards, but ATMs have an advantage (for consumers) that internet transactions don't -- pervasive video surveillance. If a criminal coerces you to give up your PIN code, it's likely to be pretty easy to prove his involvement and demonstrate coercion. If the criminal is out of view, but the victim claims otherwise, the bank's in an awkward position. If the bank were to push the issue, a jury would probably sympathize with a victim complaining that the ATM offered no way for the coerced user to summon the police. If the bank were to argue that it doesn't provide that capability because it doesn't want to risk a lawsuit from somebody shot by the criminal for attempting to exercise the duty to notify the police implied by the existence of such a feature, the jury would STILL be unsympathetic because at that point, the bank has effectively admitted that to them, the amount withdrawn by the victim at gunpoint is pocket change compared to all possible alternatives. In contrast, there aren't surveillance cameras recording internet purchases. If a cert gets stolen, the instant presumption is that you, the cert's owner, are the one who engaged in fraud, and the burden is on YOU to prove that it was stolen, or your cooperation was coerced, and that you weren't negligent in safeguarding it.

      Legislation to enable smart card signatures is nothing new -- I think it's been part of the UCC in the US for almost a decade (or at least, was proposed a decade ago). The problem is, the legislation was so completely lopsided in favor of banks against consumers that you would have had to be financially suicidal and have an economic deathwish to voluntarily participate in it. Even the banks were slightly embarrassed by it, and recognized that it was dead on arrival because no sane consumer would have ever agreed to it.

    15. Re:how about no by Sporkinum · · Score: 4, Interesting

      Which brings to mind the current catch-22 I am stuck in. My driver's license expired on my birthday about 3 weeks ago. You have 60 days grace period to get it renewed. I went down to the office to get it renewed, but was rejected because the date of birth didn't match Social Security's. I actually noticed that several years ago, when I first e-filed my income taxes. It wasn't hard to figure out what they wanted. They either transcribed a 1 as a 7 or their OCR software did. I just remember to make that change when I file and everything was fine.

      I had to take off work an hour an a half early to go down to Social Security with my certified birth certificate and wait around for a drone to make the change. I give them the birth certificate and then the ask for my drivers license. They say, we can't use that, it's expired! We need a passport instead. Being like most Americans, I don't have one. So here I am, I can't get my license renewed because of Social Security, and I can't get Social Security renewed because of my drivers license. Eventually the drone shuffled off to sector 7G for a long time and returned with a piece of paper saying that I have to get a signed medical record from my doctor. What that has to do with my identity, I have no idea.

      --
      "He's lost in a 'floyd hole"
    16. Re:how about no by sycodon · · Score: 3, Interesting

      I would propose that only those with a valid picture ID can vote.

      Driver's License, Military ID, Student ID Card,etc.

      Actually, I'd prefer only those who PAY income taxes be allowed to vote in Federal elections.

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    17. Re:how about no by element-o.p. · · Score: 4, Insightful

      I have a friend who says, "Democrats want to be your mommy. Republicans want to be your daddy. Libertarians just wish the government would treat us all like adults." I think he's right, by the way, so I'd agree that "Nanny state" and "Democratic lead (sic) government" are pretty much synonymous. However, Republicans certainly don't get a free pass from me, since IMHO, they are largely closet fascists looking to extend the government-led power grab of the last decade+. Unfortunately, the Dems seem to be following along in that tradition quite nicely, too.

      --
      MCSE? No, sir...I don't do Windows. Yes, I am an idealist. What's your point?
  2. Slight conundrum? by Chas · · Score: 5, Insightful

    We will be enhancing your privacy and security.
      By making you more uniquely identifiable and creating a single point of failure for the security method.

    *HEADDESK*

    --


    Chas - The one, the only.
    THANK GOD!!!
    1. Re:Slight conundrum? by Culture20 · · Score: 4, Funny

      I see, so you live in Russia?

      No, Soviet Russia lives in him.

  3. no centralized database, for now by Attila+Dimedici · · Score: 5, Insightful

    There is no chance that a centralized database will emerge, unless of course this catches on, in which case a centralized database will be necessary to address abuses.

    --
    The truth is that all men having power ought to be mistrusted. James Madison
  4. Offered for financial transactions? by newcastlejon · · Score: 4, Insightful

    OK, fine. But you should know that my credit card company are already happy that I am who I claim to be (and that I pay my bill on time, natch) and my bank have already given me a free security token. Oh, and I have no problem with remembering a few different passwords so thanks, but no thanks.

    To be honest, I'm more interested in whether this Schmidt fellow even knows what a smartcard or CA is. I doubt he could be more ignorant than that fool in France that started the OO.org is a firewall thing though.

    --
    If God forks the Universe every time you roll a die, he'd better have a damned good memory.
  5. Morons. by unity100 · · Score: 4, Insightful

    anything that can be read by a computer, can be changed or faked, by another computer. those who commit crimes, will be much more able to do it than ordinary citizens.

  6. A great idea by drinkypoo · · Score: 5, Insightful

    Digital signatures have been legally equivalent to normal ones for some time now, but where is the accountability? Many have long said the USPS should provide certs; I stand by that idea.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  7. Re:Why is the government involved in this? by g0hare · · Score: 3, Insightful

    Oh, probably standardization and compatibility with government systems, if the government is going to accept the ID.

    --
    Vote Quimby!
  8. Same as Social Security by Grapplebeam · · Score: 3, Interesting

    Which they were constantly telling us, "No, it'll only be for the program!" Don't trust these people farther than you can throw them.

    --
    There is no -1 Disagree.
  9. National ID Please! by Jahava · · Score: 4, Interesting

    So when can I get a cryptographically secure national ID card with multi-factor authentication? I'm as much a fan of the government tracking and cataloging me as the next guy, but this isn't exactly a slippery slope; we already have national IDs in the form of social security numbers and driver's licenses: Government-issued numbers required for identification and backed by a central database.

    It's just that the current system is about as poorly-implemented as it can be (and justifiably so, since it was never meant to be used like it is). Not only are SSNs weak, predictable, and easily-forged; there is no way to protect or limit their usage by authoritzed or unauthorized parties. There also no way to protect how those parties store and safeguard them.

    So while I hate the idea of our government issuing IDs, its too late to really change that. But please for the good of every citizen do it right.

  10. Riiiiiight. by Mr.+Underbridge · · Score: 4, Insightful

    I don't have to get a credential if I don't want to,' says Schmidt.

    Oh sure. Just like I don't have to get a state-issued ID card if I don't want either, right? Except once these gov-sanctioned IDs come into play, they do become standards (even when it's explicitly against the law, like with SSN).

    And they know it. Hey, tell me which candidate it was again who was going to stand up for the little guy?

  11. 'Trusted identity' == 'national ID' by John+Hasler · · Score: 3, Insightful

    > 'We are not talking about a national ID card,'

    Yes you are.

    > 'I don't have to get a credential if I don't want to,'

    Unless you want want to engage in any sort of non-cash transaction. Of course, if you try to live entirely on cash, you will eventually be accused of "money laundering"...

    > 'There's no chance that 'a centralized database will emerge,'

    No. It will stay hidden.

    > 'we need the private sector to lead the implementation of this.'

    Because that way when things go wrong you can blame the "evil corporations".

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  12. Re:Security and profits? by goodmanj · · Score: 4, Interesting

    It's NOT the private sector. It's the government, which is worse.

    I'll be honest here: *If* we do something like this, I'd rather have the federal government managing it directly. Large corporations are just as cooperative with the cops as your average branch of government, and at least the federal government doesn't have a profit motive for sharing the information it has about me.

  13. To the Regime: NO by WCMI92 · · Score: 3, Insightful

    Get used to that word.

    No you cannot regulate the Internet. No you cannot create national Internet ID, so you can identify and intimidate your critics.

    You cannot do these things because the courts have already said you can't and the new Congress is acting to prevent you from trying.
    Not that this will stop him good fascist Soros sockpuppet he is. 2012 will though.

    --
    Corporatism != Free Market
    1. Re:To the Regime: NO by WCMI92 · · Score: 3, Insightful

      Slashdot is extremely hypocritical on stories like this. It only took any mention of the very un patriotic PATRIOT act to get 500 posts railing about how evil and fascist BushHitler was. Though I am a conservative and a Republican I was (and still am) amongst those who believe that law was a thousand page abomination against the Constitution, and said so here. Liberals seem to have a lot bigger problem than conservatives do criticizing "their guy" when he engages in anti freedom behavior that they constantly go to sites like this to rail against.

      If electing liberal democrats was supposed to be the solution to constant government attempts to control and squelch the Internet why is it that the majority of the worst ideas seem to come from democrat administrations? It was Bill Clinton who signed into law the DMCA, the communications "decency" act, COPA amongst many failed attempts by an administration that was embarrassed by the Internet (no one would have ever known about Monica Lewinsky had it not been for Matt Drudge and the Internet) to get some wedge of control into it.

      Now, I know Bush wasn't exactly a paragon of liberty and freedom, but I don't recall similar thrusts during his 8 years.

      Now we have the Obama Regime which isn't even going through the motions of getting his Internet power grab through Congress (though the recent democrat Congress did manage to give him the Internet "kill switch" authority before being voted OUT in record numbers), and is acting through a proxy, an unelected crony who is the head of the FCC, which has recently declared itself master of the Internet. This despite warnings from Congress (which created the FCC) and one court ruling telling them NO, you don't have this authority, they are pressing ahead anyway, telling owners of PRIVATE NETWORKS how they must run them.

      Add to this, a proposal for an "optional" (yeah right) national internet ID, which will of course be secure because the government is well known for competence and efficiency (the only competent government operation is the military). This ID if it ever comes to fruition (and it won't, there will be pitchforks and torches surrounding the White House before this would be allowed to happen) will, like everything else, be perverted into the worst possible abuse almost immediately.

      You see, like the Clinton Regime, Obama has found the Internet to be a thorn in his side. The "new media" is more powerful than ever, making it impossible for his fellow travelers in the left wing "mainstream" media to alter reality for him. You wanna bet that Obama won't go after his critics? He already IS doing so, go read up on the airline pilot who dared speak up about the bullshit TSA practices and their utter incompetence and how quickly goons from the Regime stormed his home and seized his firearms and computers.

      This administration even buys search results on GOOGLE for crying out loud, to make their propaganda on the health care boondoggle the first thing you see...

      Tell me they won't abuse a national Internet ID...

      --
      Corporatism != Free Market
  14. Might want to read the draft before commenting. by ghelleks · · Score: 5, Informative

    Comments on this draft closed in July, and it's been changed since. But this should give you a sense of what they're actually proposing. http://www.dhs.gov/xlibrary/assets/ns_tic.pdf

  15. Re:Ahem, democracy? by Dunbal · · Score: 5, Insightful

    When are we going to graduate from this democracy myth and start calling the US the plutocratic oligarchic republic that it is?

          Never, thanks to an education system that ensures that 99.9% of the population don't even understand what plutocratic oligarchic means and parents too busy watching ESPN or American Idol to compensate for said system's deficit.

    --
    Seven puppies were harmed during the making of this post.
  16. Profit motive of public servants by mangu · · Score: 4, Insightful

    at least the federal government doesn't have a profit motive for sharing the information it has about me.

    Do you really believe this? As Robert Heinlein said in "The Moon is a Harsh Mistress", "My point is that some person is responsible. Always. If H-bombs exist - and they do - some person controls them. In terms of morals there is no such thing as 'state'. Just men. Individuals. Each responsible for his own acts."

    The profit motive of the federal government is that of thousands of people who would be without a job if the government didn't have all those agencies controlling every detail in your life.

  17. Playing the long game.. by ka9dgx · · Score: 3, Interesting

    Wow... all of this to stop the internet as a threat from happening. Eliminate anonymity as a possibility on the internet, wait a few years until everyone is complacent, and they use it to mop up any stragglers who don't bend to the will of The Powers That Be.

    Good thing they aren't doing anything to fix the security model we all rely on, which would leave viruses and botnets as a plausable denyability... oh... wait... they are.... "The App Store", which means no local filesystems, and no way to propagate information outside of what is allowed by the OS.

    And then there is the push towards cloud computing, again no local storage.

    We'll be ok... but our kids won't... because they will see local storage as a vulnerability, and shun it at all costs.

    I think this will all play out in 10-20 years...at least I hope it takes that long.

  18. You Lie by Culture20 · · Score: 3, Insightful

    'We are not talking about a national ID card,' says Commerce Secretary Gary Locke, whose department will be in charge of the program. 'We are not talking about a government-controlled system'

    You Lie.

  19. Re:I've already got one, you see by laughingcoyote · · Score: 3, Insightful

    You could set up a login mechanism using GPG. Wouldn't even be that hard. All you'd have to do is automate the following:

    • My system connects to the host. The host requests my public key, my system sends it (in cleartext, since it is, well, the public key after all).
    • The host encrypts a randomly generated string of characters (the "challenge string") using my public key and sends over the encrypted data, as well as its public key in cleartext.
    • If I have the appropriate private key, my system decrypts the challenge data, re-encrypts it to the host's public key, and resends it. Since the challenge data would be randomly generated every time, there would be no use in saving or intercepting it—the next login would be a different challenge string anyway.
    • The host decrypts the data. If I've returned the right challenge string, it logs me on.
    --
    To fight the war on terror, stop being afraid.
  20. Re:Security and profits? by goodmanj · · Score: 3, Informative

    You've missed my point. I'm not saying that there *should be* a government-run identity system, I'm saying that *if* we have one, we'd be better off if the government ran it.

    If you believe the government will do nefarious stuff with your data, since corporations will hand over their data the moment some guy with a suit and a badge shows up and says "national security", giving your data to a corporation is the same as giving it directly to the government.

    And while it's true that some government officials might be persuaded to become corrupt and sell your data for profit over principle, corporations *by definition* are in the business of putting profit motive first.

    So corporate verification of identity has all the drawbacks of government verification of identity, plus more.

    In essence, when personal privacy is on the line, corporate officials are just government officials who are *guaranteed to be corrupt*.

  21. Re:You don't have to have one! by markdavis · · Score: 5, Insightful

    Are you wacked? Of course you will have to have one. One by one, sites and services would be denied to you if you didn't have one. Eventually, you couldn't do ANYTHING without complying. Remember Social Security numbers- how they were supposed to be used ONLY for SS and never used for any other purpose. Tell you what, you just try to do anything now without being forced to give your national ID number- credit card, loans, electricity, health care, taxes, driving, ANYTHING useful.

  22. Re:Security and profits? by turkeyfish · · Score: 4, Informative

    The notion that you can use a competitor is laughable, since most "competitors" are now owned by the same few people that own virtually everything else. Don't you know that the wealthiest 1% of the people already own 85% of everything there is to own? Don't you realize that the only national debate going on now is just how much of the remaining 15% they will be allowed to own as well? I guess they've lulled you into a false sense of security.

    At least when the government screws you over, you can vote them out of office. Try that with a phone or cable company. Sure you can "switch to a competitor", but with the same few people owning all the "competitors", do you really think you have shown them? If the market had true competition, how do you explain that 9 times out of 10 prices only go up rather than down? How do you explain that just 5 companies control about 85% of all media outlets and the major shareholders are often the very same individuals? Dream on pal and let Fox News sing you back to sleep.

  23. Nobody here even knows what the story is about. by BobGregg · · Score: 5, Insightful

    Seriously. Almost nobody commenting here even took five seconds to even think about what was actually being discussed. It's all just knee-jerk "jack boots are coming" nonsense.

    "Internet ID for Americans" - Article title FAIL. This has nothing to do with a government identity of any sort. Nor is it a singular identity, credential, or technology. It's for use in commerce - you know, like OpenID? - but actually standardized so that companies will actually widely accept it. That's why the first sentence of the linked article, the whole point of the news of it, is that the Commerce department would head the effort, not Homeland Security. (Declan McCullagh, I like you, but you should be ashamed.) From the article: "This is not about a national identity card." From these comments: "It's a national identity card!"

    "Single point of failure" - Reading comprehension FAIL. The published strategy talks about setting up an identity trust ecosystem where individuals set up any number of identities and credentials, of their own choosing, possibly using different technologies of use as they see fit. Much like the SSL cert ecosystem today provides a means of merchant identification, without there either being a single point of failure or sinister government control.

    "Trying to solve a problem that doesn't exist" - Reality-check FAIL. I just don't know what planet you're from. If you're saying that identity theft on the Internet isn't a major concern, then you're seriously misinformed. It costs our economy millions, if not billions, in lost productivity and fraud. That's a valid government concern - making sure that economic activity can take place safely and thrive.

    For frack's sake, the same people who were screaming about how Microsoft Passport was a bad idea (and it was, because it was monopoly-controlled) are now saying the free market should solve the problem. Or, you know, that there's actually no problem at all. No wonder it's so hard to get anything done in this country.

    Having a national strategy to push towards building a real trust infrastructure is a GOOD idea. Reduces costs, reduces redundancy and waste, IMPROVES security on the Web. Trust infrastructure GOOD. Psycho spasmodic knee-jerk Fox-News "Govmint bad" reactions with no forethought BAD.

  24. Re:Ahem, democracy? by LordKronos · · Score: 4, Insightful

    Never, thanks to an education system that ensures that 99.9% of the population don't even understand what plutocratic oligarchic means

    I always love posts like this...people who get all high and mighty because some people are too stupid to know the meaning of a word which has absolutely no bearing on their everyday life. I'm a college graduate (graduated from a major university with a 4.0 GPA), and I'll admit that I don't even know what the definitions of plutocracy or oligarchy are. I'm sure I learned them in middle school or high school, and in the 20 years since then, I've probably read them a mere handful of times, though I think I've never found the need to use them. I know how to look them up in a dictionary when I see them and need to understand what I'm reading. I just did so and said "oh yeah, ok, that's right", but I can guarantee you that in 2 weeks I'll have forgotten what it means (ok, so since I participated in this discussion, it'll stick in my head a bit more and I'll probably remember for 6 or 8 weeks).

    You know what? Between all the crap I have to remember for my job, for my hobbies, all the stuff I've had to learn when I had my child and over the last 6 months (and everything else I'll learn about children over the next 18 years), all the laws I have to remember, everything I need to know for financial and tax purposes, all the stuff I need to know about automobiles, stuff I had to learn about choosing new carpet or a new kitchen appliances, about electrical repair, about plumbing, taking care of my swimming pool, maintaining my yard equipment, taking care of my garden, and a billion other things......remembering the definition of a couple of words I'll most likely never use really isn't something I give a shit about. I suspect the next time the words will be important to me is when my daughter is learning about them in middle/high school. So I guess that makes me stupid, and probably nothing but one of the sheep, or whatever else makes you feel good about yourself. Whatever. Baaaaaaaaaaaaaa

  25. Hahahahahaha!!!! by SecurityGuy · · Score: 3, Interesting

    They don't even have single sign on for their OWN systems, and they think they're the right entity to create it for 300 million people? That's hilarious. This will be a $100 billion project that will never actually meet its goals.

    Thanks, but no thanks. I actually WANT different passwords on my accounts. I don't WANT my facebook account to unlock my bank, or my slashdot password to unlock my facebook account.

    I'm sorry, but if you really want this, you want someone else to do it. If you're smart, you won't want anyone to do it, or at the least, you want opt out.