Following on the theme from my post this morning about how we could protect data about us held by agencies of the state by using a sort of a personal key and PIN like your bank's call centre has to validate with you before they can access your data, my mind wandered onto other uses for such a key.
It has been a recurring theme in this blog that the internet in particular and modern communications in general represent a great threat to the balance of power between states (and incidentally also global "intermediary" corporations) and their citizens. I say threat, but it's only a threat if you are in a position of power in a state or corporation seeking to continue to exert control over your citizens. Indeed, for the individual, it is the greatest potential opportunity, and the vehicle by which Richard Cobden's quote at the top of this blog's front page may become reality: "Peace will come to earth when the people have more to do with each other and governments less."
Many of our institutions - governments, trans-national corporations, even currency - evolved to deal with issues of trust between people who would likely never have personal contact with each other in ever more remote markets. When trading, you've got to be able to trust that you will be paid for example - one person's "IOU" is not as good a guarantee as piece of paper endorsed collectively by an entire state - a national currency.
But we have an ever increasing range of other innovations to help us trust each other; developments that are increasing quickly with the advance of the internet. We can access our credit files, we can buy digital certificates that help give others confidence to trade with us over the web because they guarantee we are who we say we are and so on. So why not shift these into the "real world".
Why do we actually need, say, a passport to travel across borders, issued by a nation state, when we could have just as secure a guarantee of who we are through some kind of personal digital certificate from an organization bearing the risk, with strong encryption embedded in it? The British government keeps trying to sweeten its totalitarian ID card scheme by telling us, amongst other things, that it will make proving our identity to others in all sorts of transactions much easier. But in fact the history of government involvement in protecting the source data of those identities is appalling, and, as the technology gets more pervasive it seems to be getting worse.
How much confidence can you have in a government issued identity mechanism when so much data has gone missing already? Those identities are, thanks to state incompetence, all but worthless. Of course that's why, partly at least, they want to take biometric data. But in computer security it is generally accepted that being able to produce "something you have" (say a credit card or internet digital certificate) and "something you know" - a password, PIN, or private digital encryption key is far better than ony one or other of these pieces of information on its own. So far as I can see the ID card system, or the passport, with or without a national identity register, does not fulfill both of these - only the former. It is inherently weaker than the commercially available alternatives.
So, why not replace the need for passports issued by a state with identity mechanisms authenticated by trusted corporate or social organizations for whom financial success or failure rests on people being able to trust the people they certify. So you could have a personal account with Thawte as the primary guarantor, for example, and that certificate could be counter-signed by a certificate from other organizations, such as governments, who want to "mark your card" as one of their citizens, granting you the protections normally written on a passport.
It's not easy to get some of these certification authorities to guarantee your bona fides. You need often as much verification as you do to get a passport with other trusted people verifying who you are and so on. But you would not need to give these data to the poroous security mechanisms of the state which has proved beyond any reasonable doubt that they cannot keep the information secure, nor does it offer the other benefit of a private contract - the ability to sue the ass off them if they damage your reputation or security by losing your data - or the corporate incentive of only being able to make a profit if you actually deliver on what people expect of you.
And you also get a choice of how strong you want the certification to be. If it's only guaranteeing small personal trades for example, you may only need to spend a few pounds and fill in a quick web form, validate your address and you're in business. If you want to travel overseas, or deal in bigger sums, or trade with distant counterparties, you may want stronger levels of guarantee and pay accordingly. It's a global standard pretty well too. So you'd have no problems using it to prove your identity in all sorts of applications - travel, trade, opening a bank account, starting a company, getting insurance, benefits, accessing what little data about you the state actually needs and so on - none of which would need to be on any single central database owned by a bunch of data-incontinents like the government is proving to be with the attendant dangers of losing all your data at once.
So, you see, we no longer even need governments to help us prove who we are. And in fact they appear to be singularly bad at doing so. The threat inherent in this is that the currently all powerful state needs to be able to do this, or it loses control of its citizens. And they are shit scared of that. If we are not mindful, in their lust to maintain that power they will get immensely more authoritarian and intrusive. The time is coming when we will no longer need them. We must do all we can to hasten that day before they get their claws in too deep into these emerging trust mechanisms.
Trackback URL for this post:
http://www.jockcoats.org.uk/trackback/935