• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Should we have a universal ID card?

Should the UK have a digital ID scheme

  • Yes I think so

    Votes: 91 47.9%
  • No I don’t think so

    Votes: 92 48.4%
  • I’m not sure

    Votes: 7 3.7%

  • Total voters
    190
Status
Not open for further replies.

Tester

Established Member
Joined
5 Jul 2020
Messages
1,706
Location
Watford
Surely that can work the other way though? Any of us can fly or get the ferry to Belfast then just stroll across the border and into the EU with no checks. And then if we wanted to avoid all the biometric checks for non-EU people that have just come in we could fly to our EU destination from Dublin airport. As it would be EU to EU we could skip all the fingerprint checks that we would have to go through if we were flying from the UK (non EU).
Ireland is not in Schengen
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

bleeder4

Member
Joined
19 Jan 2019
Messages
792
Location
Worcester
Ireland is not in Schengen
Fair enough, I hadn't realised that. As long as they stay in Ireland then, it would still be quite possible for a UK national to enter the EU via the Irish land border with none of the usual EU entry checks and, potentially, stay there for some time without encountering a situation where they got prompted for ID.
 

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,466
Location
LBK
Fair enough, I hadn't realised that. As long as they stay in Ireland then, it would still be quite possible for a UK national to enter the EU via the Irish land border with none of the usual EU entry checks and, potentially, stay there for some time without encountering a situation where they got prompted for ID.
So? Ireland is part of the Common Travel Area. That is how it works and how it is intended to work. That is why Ireland isn't in Schengen, too.
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,100
Location
Redcar
Fair enough, I hadn't realised that. As long as they stay in Ireland then, it would still be quite possible for a UK national to enter the EU via the Irish land border with none of the usual EU entry checks and, potentially, stay there for some time without encountering a situation where they got prompted for ID.
Yes but that's not quite the same situation because Irish and UK nationals, separate to anything to do with EU membership, have the right to live and work in each others countries. It's one of the reasons why Ireland isn't in Shengen. So a UK national who walked over the Irish border (or flew into Ireland, you don't need a passport to do so) can perfectly legally work there as soon as the arrive. This is known as the Common Travel Area and pre-dates even the EU though it wasn't really codified at all until 2019 due to the whole Brexit process and even now is just a memorandum of understanding between the relevant governments.

The Common Travel Area (CTA) is a long-standing arrangement between the UK, the Crown Dependencies (Bailiwick of Jersey, Bailiwick of Guernsey, Isle of Man) and Ireland.

The CTA established cooperation between respective immigration authorities enabling British and Irish citizens to move freely between, and reside in, these islands.

British and Irish citizens enjoy additional rights in Ireland and the UK. These include the right to work, study and vote in certain elections, as well as to access social welfare benefits and health services.

If you are a British citizen or an Irish citizen, you do not need to take any action to protect your status and rights associated with the CTA. After the UK leaves the EU, you will continue to enjoy these rights, no matter what the terms of the UK’s exit. Both the UK and Irish governments have committed to taking all necessary measures to ensure that the agreed CTA rights and privileges are protected in all outcomes.


Now if that UK national attempted to leave Ireland and go to an EU state that wouldn't work because they'd be subject to entry checks on arrival (or in reality at the gate departing Dublin) at the Shengen border in the EU state they flew into and would be turned away there becuase even though you're in the EU when you're in Ireland, you are not in Shengen so the full border requirements are still carried out when you arrive in another EU state.
 

etr221

Established Member
Joined
10 Mar 2018
Messages
1,597
What is the position for Irish (Republic) citizens travelling to the Schengen area? My assumption is that they have to go through Schengen 'for EU citizens' entry procedures (does this now include the new EES ones?). And that UK citizens - like any other third county ones - entering the Schengen area from Ireland will have to go through standard Schengen 'non EU' entry procedures, in the same way as coming from any other non-Schengen country.
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,100
Location
Redcar
What is the position for Irish (Republic) citizens travelling to the Schengen area? My assumption is that they have to go through Schengen 'for EU citizens' entry procedures (does this now include the new EES ones?). And that UK citizens - like any other third county ones - entering the Schengen area from Ireland will have to go through standard Schengen 'non EU' entry procedures, in the same way as coming from any other non-Schengen country.
Exactly so. Irish citizens use EU lanes/e-gates. UK citizens use non-EU lanes/e-gates. Which is why getting into Ireland doesn't really help you as a UK citizen trying to illegally enter the EU. You don't go through the EU border (for people anyway) until you arrive in your non-Irish EU destination. Until then you're covered by the CTA which allows you to move between Ireland and the UK freely.
 

Cloud Strife

Established Member
Joined
25 Feb 2014
Messages
2,964
Surely that can work the other way though? Any of us can fly or get the ferry to Belfast then just stroll across the border and into the EU with no checks. I would imagine that people living in the Northern Ireland/Republic of Ireland border go in and out of the EU dozens of times a week just when they're driving around in their daily lives. And then if we wanted to avoid all the biometric checks for non-EU people that have just come in we could fly to our EU destination from Dublin airport. As it would be EU to EU we could skip all the fingerprint checks that we would have to go through if we were flying from the UK (non EU).

Just to add to what others have said:

The UK and Ireland (and the Isle of Man/Channel Islands) have a Common Travel Area, meaning that for the purposes of the law, neither British nor Irish citizens are 'foreigners' in the eyes of the law in any of the jurisdictions covered by it. You can travel freely as a British/Irish citizen between the two countries and Crown Dependencies, although there are some specifics such as Ireland requiring some form of photo identification (although a bus pass is enough for British/Irish citizens) when you arrive at a port, or the Isle of Man planning to introduce ID checks on entry.

So, while Ireland is part of the EU, British citizens have the right to stay there freely and without formalities based on a different set of laws. While the modern day law is based specifically on the Aliens (Exemption) Order, 1999 (S.I. No. 97/1999) in Ireland which exempts British citizens from the Aliens Act of 1935, the initial exemption was based on the Aliens Act of 1935 itself, which gave the government the power to decide which citizens were exempt from the act. As the Act defines an alien as 'anyone who isn't an Irish citizen', what happened in Irish legal theory was that British citizens were simply not considered aliens in Ireland.

The CTA itself is based on a very odd patchwork of legislation, but it came about because while Ireland established citizenship of the Irish Free State in 1922, they also didn't introduce any laws defining what an alien was until 1935. As a result, there was no need to introduce identity/immigration control in 1922, and then the border had become well established by 1935 as one that didn't require identity controls. There were also other practical considerations, such as Ireland not recognising the UK's jurisdiction in Northern Ireland, and establishing identity controls would have undermined that.

However, Ireland aren't in Schengen, and anyone travelling from Ireland to Schengen is only exempt from customs control, not police/identity control. EU citizens arriving in Ireland go through the same identity controls as anyone else as well. All the EES checks are carried out exactly in the same way, that is, EU citizens/residents are exempt while everyone else has to go through them on arrival at a Schengen airport or ferry port.

What is the position for Irish (Republic) citizens travelling to the Schengen area? My assumption is that they have to go through Schengen 'for EU citizens' entry procedures (does this now include the new EES ones?). And that UK citizens - like any other third county ones - entering the Schengen area from Ireland will have to go through standard Schengen 'non EU' entry procedures, in the same way as coming from any other non-Schengen country.

They go through police/identity controls for EU citizens, just as if they were arriving from the USA or anywhere else. There's no need for EES registration and so on, as they have freedom of movement in the EU. It's exactly this 'backdoor' that makes a mockery of Brexit, because the Irish immigration authorities can't and won't stop EU citizens from entering Ireland. With the open border, EU citizens can effectively walk into the UK and stay indefinitely as long as they don't draw attention to themselves. On the other hand, Ireland and the UK do cooperate when it comes to non-EU citizens, and it's quite routine for both countries to deny people entry if they think that immigration regulations will be broken in the other jurisdictions.

This is why an identity card solves many problems, because it abolishes all the insecure forms of identity currently used. As it stands, someone with a neutral accent from somewhere like The Netherlands can easily get away with staying in the UK indefinitely with a fake birth certificate, and there's certainly plenty of them in the UK who pass for locals.

Fair enough, I hadn't realised that. As long as they stay in Ireland then, it would still be quite possible for a UK national to enter the EU via the Irish land border with none of the usual EU entry checks and, potentially, stay there for some time without encountering a situation where they got prompted for ID.

Ireland has their own immigration regime, separate to Schengen. They participate in some aspects of Schengen (just as the UK did before Brexit), but in general, Ireland is responsible for her own immigration affairs, as is Cyprus. So, as mentioned above, British citizens are not considered aliens in Ireland, and they can stay as long as they want without doing anything. I don't even think Ireland has any formal registration process for British citizens, just as the UK doesn't have any for Irish citizens.

and even now is just a memorandum of understanding between the relevant governments.

From what I understand of the legal position, it's that the CTA is already defined through various laws, so there was no real need to pass new laws. The UK did amend some laws to make it absolutely crystal clear that Irish citizens are exempt from any/all immigration control, while other laws already covered issues such as Irish citizens being automatically considered 'settled'. There is an interesting legal point in that any child born in the UK to an Irish citizen is automatically a British citizen as a result. The UK also made it even easier this year for Irish citizens to obtain British citizenship by removing the requirement for them to pass the "Life in the UK" test (which was frankly ridiculous to begin with) and also removing the requirement for them to prove their knowledge of English (which was a formality, but still required them to show that they had obtained some qualification in English at school).

The Ireland Act of 1949 explicitly says that the Republic of Ireland is not a foreign country for the purposes of any UK law, so Irish citizens can use their birth certificates to prove their right to work. Now, how many of us would be able to identify an authentic Irish birth certificate from a fake one?

But again: without ID cards, how do we know that someone turning up with an American accent and an Irish birth certificate is, or isn't entitled to work? The documentation says that Brad was born in Dublin to Irish parents. Yes, Border Force can check with the Irish authorities as to whether it's a legitimate document, but in practice, it's very unlikely that they're going to get caught. With a digital ID card, we can then require Irish citizens to either obtain the British digital ID card, or to use a document confirming citizenship from Ireland.

This is before we even discuss the headache of the Northern Irish, many of whom hold Irish passports and yet are considered British citizens by the UK through nothing more than their birth certificates. They often hold Irish and not British passports, so what then?

It's actually astonishing just how many loopholes there are, and it really makes you wonder who might be behind any push to block identity cards that clearly identify someone as a British citizen with the right to live/work in the UK.
 

etr221

Established Member
Joined
10 Mar 2018
Messages
1,597
The CTA itself is based on a very odd patchwork of legislation, but it came about because while Ireland established citizenship of the Irish Free State in 1922, they also didn't introduce any laws defining what an alien was until 1935.
Until 1935, the Free State was a British Dominion (within the Empire), with King George V as its nominal head, so the Irish (on both sides of the border) remained British subjects - until there was the abdication crisis, and the Free State took the opportunity to proclaim itself a republic (but still nominally a Dominion within the Empire).

My understanding is that the CTA came about when - in 1922 - civil servants, from the UK and future Free State sat down to sort out how things were actually going to work when the treaty (and so Free State) actually came into effect, rather dreading having to establish controls along the border (shades of Brexit worries a century later!) - and when the UK side said 'if we give you a copy of our undesirable aliens list, will you keep them out?', the Irish side said 'yes', there need be no controls with a CTA, and everybody breathed a sigh of relief...
 

sor

Member
Joined
15 Nov 2013
Messages
790
Somewhat of a development: https://www.theguardian.com/technol...used-to-test-uk-governments-digital-id-scheme

Former military personnel will be used to test and refine the government’s divisive digital ID scheme from Friday, when ministers make a smartphone-based veteran card available to 1.8 million people.

The proof of service, which in its current physical version gives access to charities, retail discounts and certain public services, will be the first of a series of official credentials the government wants to let people carry in a government app.
Ministers hope the digital veteran card will show how the technology works and quash public concerns about privacy and security. Kendall said it “will help remove barriers, reduce red tape and make it easier for people to access the public services they need”.
Interesting to see explicit mention of the gov dot uk "one login" (which I have mentioned in this thread before, and is already in use to access some online government services).
 

Cloud Strife

Established Member
Joined
25 Feb 2014
Messages
2,964
Until 1935, the Free State was a British Dominion (within the Empire), with King George V as its nominal head, so the Irish (on both sides of the border) remained British subjects - until there was the abdication crisis, and the Free State took the opportunity to proclaim itself a republic (but still nominally a Dominion within the Empire).

According to British legal theory, yes. According to Irish legal theory, they had already established Irish citizenship as something separate with the Free State constitution of 1922, and they no longer recognised Irish citizens as being British subjects. The UK view was that Irish citizenship was a merely internal matter for the Free State, so they simply ignored it.

When Irish Free State adopted a new constitution in 1937 and renamed the state to Ireland, nothing really changed from the UK perspective. The UK had already passed the Statute of Westminster which removed the UK's right to legislate for the Free State (and other Dominions) in 1931, which the Irish Free State recognised as formal British consent to the provisions of the Anglo-Irish Treaty in 1921 which removed the British ability to legislate for the territory then known as Southern Ireland/Irish Republic.

It was quite messy, because until 1948, the UK still considered people of the Dominions to be British subjects and equal to anyone living in the UK. It was only in 1948 that they formally created the concept of a British citizen (separate to subjects), and the law introduced then didn't include the state known as Ireland in the list of Dominions. Without getting very legalistic, the general idea was that the UK recognised the residents of the Dominions (and in some cases, colonies) as being British subjects and Commonwealth citizens, with the name being legally equal. The reason for Ireland being excluded was that they passed separate legislation (the Ireland Act 1949) to recognise that Irish citizens were not foreigners according to UK law. Of course, these British subjects were not British citizens.

Going back to the topic of ID cards, one messy question is exactly what to do with Irish citizens in the UK. The sensible thing would be to have digital ID cards issued to all residents of the UK, which would clearly state their citizenship. It avoids any hassle with Northern Ireland because people would be free (as now) to choose which citizenship they have, and it would avoid the thorny issue of forcing an identity document on them which would make them identify as British against their will.

== Doublepost prevention - post automatically merged: ==

Interesting to see explicit mention of the gov dot uk "one login" (which I have mentioned in this thread before, and is already in use to access some online government services).

This is pretty much how it works in Poland: you obtain the so-called 'trusted profile', which you can get from a wide range of public institutions or through your bank. This profile is then used to log into the mObywatel (mCitizen) app, and all the digital documents are automatically generated for you there. It's absolutely painless, because it's essentially using the data that the government already has for you. You've got an ID card? Then it generates a digital ID card for you. You've got a car? It checks the CEPiK database (which contains everything about drivers and vehicles) and automatically generates a driving licence and car registration document for you. And so on.

I think part of the problem is that people don't understand that the government already has a huge amount of data on people, it's just held in a range of different places that aren't joined up properly from a citizen perspective.

The beautiful thing about the system is that it guarantees that the data is actually up to date.
 
Last edited:
Joined
22 Jan 2024
Messages
588
Location
Yorkshire
I think part of the problem is that people don't understand that the government already has a huge amount of data on people, it's just held in a range of different places that aren't joined up properly from a citizen perspective.

Do you realise how utterly patronising that sounds?

Many objecting to ID cards are perfectly well aware of this and there are two relevant points. Firstly, in many cases it would be preferred that the government didn't have all this information, but we are where we are and there's no realistic prospect of the information being discarded once collected, so the focus is on objecting to further data collection, analysis and centralisation.

Secondly (and related to the above) it being stored in a disjointed, non-aggregated manner limits what governments can do with it. Having everything in one place is significantly more dangerous, and is only likely to lead to further mission creep and additional data collection.
 

Cloud Strife

Established Member
Joined
25 Feb 2014
Messages
2,964
Many objecting to ID cards are perfectly well aware of this and there are two relevant points. Firstly, in many cases it would be preferred that the government didn't have all this information, but we are where we are and there's no realistic prospect of the information being discarded once collected, so the focus is on objecting to further data collection, analysis and centralisation.

This data collection, analysis and centralisation likely already exists, simply not from the citizen perspective. It's incredibly naïve to think that HMRC doesn't have direct access to DVLA records, for example. What changes here is that citizens will have the benefits of having everything in a secure place, where accesses to personal data can be viewed in real time.

Secondly (and related to the above) it being stored in a disjointed, non-aggregated manner limits what governments can do with it. Having everything in one place is significantly more dangerous, and is only likely to lead to further mission creep and additional data collection.

It doesn't limit it at all. It's very easy to pull information together from various databases if you're a government, and very easy with modern IT tools to run large scale queries on those databases to link up data. There's also nothing dangerous about having information available in a joined up form, because this information is already available to the government.

But out of idle curiosity, what is so dangerous about it, given that it's rapidly becoming the norm in the EU to have digital access to various documents and information? Why wouldn't you want citizens to be able to check their entitlement to benefits or for employers to be able to easily and securely ascertain someone's right to work?
 

sor

Member
Joined
15 Nov 2013
Messages
790
This data collection, analysis and centralisation likely already exists, simply not from the citizen perspective. It's incredibly naïve to think that HMRC doesn't have direct access to DVLA records, for example. What changes here is that citizens will have the benefits of having everything in a secure place, where accesses to personal data can be viewed in real time.
As someone (possibly me) has said before. For a very long time you have been able to apply for a driving licence using your UK passport or visa share code as confirmation of your identity, the advantage being that they won't require a countersigned photo & you don't risk losing your proofs of identity in the post. You have to give permission and provide the passport number or share code on the form, but it implies that the Home Office and DVLA have that direct data link.

All that really changes is that a passport number or share code is replaced with a gov.uk one login and perhaps its a bit more automated, and yet people are losing their minds over this concept.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,037
Location
bülach (switzerland)
Do you realise how utterly patronising that sounds?

Many objecting to ID cards are perfectly well aware of this and there are two relevant points. Firstly, in many cases it would be preferred that the government didn't have all this information, but we are where we are and there's no realistic prospect of the information being discarded once collected, so the focus is on objecting to further data collection, analysis and centralisation.

Secondly (and related to the above) it being stored in a disjointed, non-aggregated manner limits what governments can do with it. Having everything in one place is significantly more dangerous, and is only likely to lead to further mission creep and additional data collection.
Could you please post the source where the centralization of data is described and the direct connection to the ID is mentioned? My understanding remains that all data required for verification (as with most systems) is stored in the app and there is no connection to a database. The app is expected to be used for verification when logging in to various services, but this is not mandatory (although it is very useful, especially from a data security perspective).
 

Razorblades

Member
Joined
17 Dec 2021
Messages
453
Location
Copshaw Holm, Scottish Borders
I suggest that instead of whistling with fingers in one's ears, saying 'la la la la la la, I can't hear you,' people simply look and listen to what the government has said, and consider their previous record in problem-'solving' since 2020.

Starmer and his spokespeople are recorded in parliament describing, as though it were a sales pitch, how this initiative will 'help' us. Nothing they have described thus far has provided any hint of improving my life through offering access to anything that I can't access already. Find it on Hansard, look it up on YouTube, it's all there.

I can travel, drive, access my bank account, order a repeat prescription, send a tax return, have a pint, purchase restricted items should I so wish, and generally go about my life unencumbered. By saying 'you will be able to do these things securely in future when you have got Digital ID' my view is that it would be extremely naïve to think that the government won't make it extremely difficult to do things without it.

Digital ID for 13 year-olds has already been mentioned. No-one can satisfactorily explain this, my suspicion is it will be linked to NHS immunisation records.
There is talk of using Digital ID to buy drinks in pubs and bars by December, supposedly making the lives of those of indeterminate age easier.
Forces veterans have had Digital ID made available today, seemingly. Not sure how this will materially benefit these folk.

The petition stands at 2,889,171 and whether the technophiles like to sneer or not, there is a huge suspicion of this move.

The government will hit resistance as it did in 2020-2021. People will be pushed, until their personal line is crossed. The government has form at this sort of thing: don't get a jab and you are antisocial, get a jab or you'll infect someone else, get a jab or you'll kill granny, get a jab or you can't go to a nightclub, get a jab or you won't be allowed to travel abroad. Has everyone forgotten this, or more worryingly, were some people actually supportive of it and thought it absolutely fine and proportionate?
 

Railwaycat

Member
Joined
15 Jul 2023
Messages
277
Location
Derbyshire
The government will hit resistance as it did in 2020-2021. People will be pushed, until their personal line is crossed. The government has form at this sort of thing: don't get a jab and you are antisocial, get a jab or you'll infect someone else, get a jab or you'll kill granny, get a jab or you can't go to a nightclub, get a jab or you won't be allowed to travel abroad. Has everyone forgotten this, or more worryingly, were some people actually supportive of it and thought it absolutely fine and proportionate?

It was absolutely fine and proportionate - what is your problem with it?
 

gabrielhj07

Established Member
Joined
5 May 2022
Messages
1,619
Location
Herts
By saying 'you will be able to do these things securely in future when you have got Digital ID' my view is that it would be extremely naïve to think that the government won't make it extremely difficult to do things without it.
This summarises a lot of the scepticism rather well.


The government will hit resistance as it did in 2020-2021. People will be pushed, until their personal line is crossed. The government has form at this sort of thing: don't get a jab and you are antisocial, get a jab or you'll infect someone else, get a jab or you'll kill granny, get a jab or you can't go to a nightclub, get a jab or you won't be allowed to travel abroad. Has everyone forgotten this, or more worryingly, were some people actually supportive of it and thought it absolutely fine and proportionate?
Indeed, the Labour Party's general position during covid was that whatever restriction the government had just thought of was a) not enough, and b) not done soon enough. It isn't a stretch of the imagination to see this authoritarian thinking present in this policy.
 
Joined
22 Jan 2024
Messages
588
Location
Yorkshire
Could you please post the source where the centralization of data is described and the direct connection to the ID is mentioned? My understanding remains that all data required for verification (as with most systems) is stored in the app and there is no connection to a database. The app is expected to be used for verification when logging in to various services, but this is not mandatory (although it is very useful, especially from a data security perspective).

Where do you think the data is going to come from? Even if it's cached locally in the app, there has to be a back-end database to pull the data from in the first place and the app has to be securely connected to this. And there has to be a mechanism to push updates to the local cache (e.g. a change of surname to give one example).

== Doublepost prevention - post automatically merged: ==

And therein lies the conundrum.

Where to start?

Yes, indeed!

I think I would start by pointing out that the government trying to bully and coerce people into having an experimental medical treatment which they didn't need, and for which the government were making claims (e.g. that it reduced transmission) which even the manufacturers weren't trying to claim, was unprecedented in modern western societies. It was directly opposed to the concept of bodily autonomy.

You might also want to consider whether, among the people you know, there has been a higher incidence of cancer in the past few years than ever before. I know that this is the case with people I know and many others have reported similarly.
 
Last edited:

Razorblades

Member
Joined
17 Dec 2021
Messages
453
Location
Copshaw Holm, Scottish Borders
Where do you think the data is going to come from? Even if it's cached locally in the app, there has to be a back-end database to pull the data from in the first place and the app has to be securely connected to this. And there has to be a mechanism to push updates to the local cache (e.g. a change of surname to give one example).

== Doublepost prevention - post automatically merged: ==



Yes, indeed!

I think I would start by pointing out that the government trying to bully and coerce people into having an experimental medical treatment which they didn't need, and for which the government were making claims (e.g. that it reduced transmission) which even the manufacturers weren't trying to claim, was unprecedented in modern western societies. It was directly opposed to the concept of bodily autonomy.

You might also want to consider whether, among the people you know, there has been a higher incidence of cancer in the past few years than ever before. I know that this is the case with people I know and many others have reported similarly.

I rest my case m'lud.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,037
Location
bülach (switzerland)
Where do you think the data is going to come from? Even if it's cached locally in the app, there has to be a back-end database to pull the data from in the first place and the app has to be securely connected to this. And there has to be a mechanism to push updates to the local cache (e.g. a change of surname to give one example).
It's not particularly complicated. One possible variant is already being used for e-ID:

Technology

Other variants are also possible.

Any changes require the user to obtain a new verifiable credential from the official issuer. The old credential is then marked as invalid in the public trust infrastructure, and the new one is stored securely on the user's smartphone. This process ensures privacy and security by not updating a central record of the individual's data. The new credential is then stored securely on your smartphone, replacing the old one. The sensitive personal data itself is never sent to a third-party service.
 

JamesT

Established Member
Joined
25 Feb 2015
Messages
4,874
It's not particularly complicated. One possible variant is already being used for e-ID:

Technology

Other variants are also possible.

Any changes require the user to obtain a new verifiable credential from the official issuer. The old credential is then marked as invalid in the public trust infrastructure, and the new one is stored securely on the user's smartphone. This process ensures privacy and security by not updating a central record of the individual's data. The new credential is then stored securely on your smartphone, replacing the old one. The sensitive personal data itself is never sent to a third-party service.
But the data is still coming from the issuers system. Your example has multiple issuers probably because it’s Swiss and they have a federal system. The UK will almost certainly implement this as one central function.

If you want to look at existing implementations, we could take the Danes. They do have a big Central Person Register which their MitID hooks into. Their privacy notice https://www.mitid.dk/en-gb/legal/privacy-notice/ says they may share personal data with service providers.
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,037
Location
bülach (switzerland)
But the data is still coming from the issuers system. Your example has multiple issuers probably because it’s Swiss and they have a federal system. The UK will almost certainly implement this as one central function.
The document "Digital ID in the UK" out of the house of Commons library says:

What will the digital ID system look like?

While the detailed design of the scheme is subject to a consultation to be
published later this year, the government’s official press release, explainer,
and oral statement suggest the system will have the following features:

• Design

– The digital ID will be free and “stored securely on your phone”. The initial press release suggested that it will be a digital document stored in the GOV.UK Wallet app, alongside other digital government-issued documents such as a driving licence.

– The digital ID will contain an individual’s name, date of birth, nationality or residency status, and a photo. The consultation will seek views on whether additional information should be included.

– There will be no central database of everyone’s personal information.

– The system will be built “in-house”, building on existing work on One Login and the GOV.UK Wallet.
 
Joined
22 Jan 2024
Messages
588
Location
Yorkshire
But the data is still coming from the issuers system. Your example has multiple issuers probably because it’s Swiss and they have a federal system. The UK will almost certainly implement this as one central function.

If you want to look at existing implementations, we could take the Danes. They do have a big Central Person Register which their MitID hooks into. Their privacy notice https://www.mitid.dk/en-gb/legal/privacy-notice/ says they may share personal data with service providers.

Indeed - that Swiss system is clearly using one database to verify the ID, which functions as the trusted identity provider for several other databases. Data from each of them is then aggregated in the app.

That certainly isn't a case of no databases - the data is just split across several of them. In a UK situation, it would be a trivial matter for any authorised body (e.g. the police or security services) to perform the same aggregation of data, given that all the databases would be controlled by the government.

== Doublepost prevention - post automatically merged: ==

The document "Digital ID in the UK" out of the house of Commons library says:

As regards this document which 'suggests' that 'There will be no central database of everyone’s personal information.' the most likely explanations are that those doing the 'suggesting' don't know what they are talking about, or that the government is lying (hardly unprecedented!), or that they will simply split it across several databases. A system like this cannot work without one or more databases sitting behind it.
 
Last edited:

AlterEgo

Verified Rep - Wingin' It! Paul Lucas
Joined
30 Dec 2008
Messages
29,466
Location
LBK
What is the actual objection to the government using its own databases here? I mean they have all the data anyway. If the police want to find me today because I said some hurty words or whatever, they can do that. Already. They know where I live, which car I drive, where I spend my money, where my mobile phone is pinging right now - it is trivial for them to find this out. They could send a tank to my house and blow it up if they wanted to.

What theoretical harm is present with digital ID which isn't theoretically present now?
 

bahnause

Member
Joined
30 Dec 2016
Messages
1,037
Location
bülach (switzerland)
Indeed - that Swiss system is clearly using one database to verify the ID, which functions as the trusted identity provider for several other databases. Data from each of them is then aggregated in the app.

That certainly isn't a case of no databases - the data is just split across several of them. In a UK situation, it would be a trivial matter for any authorised body (e.g. the police or security services) to perform the same aggregation of data, given that all the databases would be controlled by the government.

== Doublepost prevention - post automatically merged: ==
No, I really don't know where your information is coming from or if you are just making stuff up. All the information is in the app. All the idendity provider does is to confirm the data in the app is still valid. That is all you need to verify your ID.

If you want to use your e-ID in a bar or supermarket, for example to confirm your age, this is how it works: The bar has a verifier service, for example in an app. This service uses the OpenID for Verifiable Presentations (OID4VP) protocol to send a request, for example asking for your age. This request contains a so-called presentation definition. This is a list of all the data that the verifier would like to have from you. In this case, the information about your age. This request is packed into a URL and displayed to you as a QR code. You can scan this with the QR scanner in the (whatever it is called) app.

Your wallet now checks who the requester is. To do this, it checks the DID (digital identity anchor that uniquely identifies a company or organisation). This also clarifies whether the requester is authorised to receive this information. It also looks at which attributes are included in the presentation definition. You will then receive a message on the Swiyu app, for example: The Rooftop Bar in East grimmelby would like to know if you are already 18. You then tap on ‘Agree’.

The wallet then creates a so-called Verifiable Presentation (VP). This data packet contains the information that you are at least 18 years old. It also contains the government key, which proves that your credential was actually issued by the federal government. And finally, your device signature (device binding) with your private key, which proves that the Verifiable Presentation really comes from your smartphone. In addition, a so-called nonce is incorporated, a unique random number that prevents anyone from simply reusing the presentation later.

The verifier then checks the signature (does the information come from the federal government?), the status (is the e-ID still valid?) and the issuer (is the federal government even allowed to issue e-IDs?). The bar doesn't see any of this, though. It only receives the information: Yes, you are at least 18 years old. Who you are and your exact date of birth remain secret. This way, the bar has the information it needs and you don't have to reveal anything that isn't necessary.

As regards this document which 'suggests' that 'There will be no central database of everyone’s personal information.' the most likely explanations are that those doing the 'suggesting' don't know what they are talking about, or that the government is lying (hardly unprecedented!), or that they will simply split it across several databases. A system like this cannot work without one or more databases sitting behind it.
Please excuse me for not taking such statements seriously when they come from someone who has not deemed it necessary to present a shred of evidence to support their claims. Anyone can stamp their feet and claim that everything is a lie. Doesn't make it true.
 
Joined
22 Jan 2024
Messages
588
Location
Yorkshire
No, I really don't know where your information is coming from or if you are just making stuff up. All the information is in the app. All the idendity provider does is to confirm the data in the app is still valid. That is all you need to verify your ID.

If you want to use your e-ID in a bar or supermarket, for example to confirm your age, this is how it works: The bar has a verifier service, for example in an app. This service uses the OpenID for Verifiable Presentations (OID4VP) protocol to send a request, for example asking for your age. This request contains a so-called presentation definition. This is a list of all the data that the verifier would like to have from you. In this case, the information about your age. This request is packed into a URL and displayed to you as a QR code. You can scan this with the QR scanner in the (whatever it is called) app.

Your wallet now checks who the requester is. To do this, it checks the DID (digital identity anchor that uniquely identifies a company or organisation). This also clarifies whether the requester is authorised to receive this information. It also looks at which attributes are included in the presentation definition. You will then receive a message on the Swiyu app, for example: The Rooftop Bar in East grimmelby would like to know if you are already 18. You then tap on ‘Agree’.

The wallet then creates a so-called Verifiable Presentation (VP). This data packet contains the information that you are at least 18 years old. It also contains the government key, which proves that your credential was actually issued by the federal government. And finally, your device signature (device binding) with your private key, which proves that the Verifiable Presentation really comes from your smartphone. In addition, a so-called nonce is incorporated, a unique random number that prevents anyone from simply reusing the presentation later.

The verifier then checks the signature (does the information come from the federal government?), the status (is the e-ID still valid?) and the issuer (is the federal government even allowed to issue e-IDs?). The bar doesn't see any of this, though. It only receives the information: Yes, you are at least 18 years old. Who you are and your exact date of birth remain secret. This way, the bar has the information it needs and you don't have to reveal anything that isn't necessary.


Please excuse me for not taking such statements seriously when they come from someone who has not deemed it necessary to present a shred of evidence to support their claims. Anyone can stamp their feet and claim that everything is a lie. Doesn't make it true.

You are talking entirely about using an ID for third party verification here. The principal risk as regards data collection is the government's own databases (as I have already pointed out). Do you seriously think that interactions with government bodies will not get recorded back to government-controlled databases? For years, UK governments have never missed an opportunity for data collection so the idea that they will show restraint here is simply not credible.

We seem to have a fundamentally different view of government here - you clearly believe they are benign and act in the interests of the people at large. I view them as dishonest, ruthless and self-serving (for evidence of which, you don't have to look very hard).

== Doublepost prevention - post automatically merged: ==

I fear they are serious, yes.

Yes, and this is why the way in which the Covidian era has been brushed under the carpet is dangerous. The mindset hasn't changed, and if (when?) the next hysterical "emergency" comes along, those people who were keen to start bullying and hassling others on the instructions of the government will be equally keen to do it again.
 
Last edited:

bahnause

Member
Joined
30 Dec 2016
Messages
1,037
Location
bülach (switzerland)
You are talking entirely about using an ID for third party verification here. The principal risk as regards data collection is the government's own databases (as I have already pointed out). Do you seriously think that interactions with government bodies will not get recorded back to government-controlled databases? For years, UK governments have never missed an opportunity for data collection so the idea that they will show restraint here is simply not credible.
So you're convinced that the government is spending money to collect data that it already has. Seriously?
 
Status
Not open for further replies.

Top