Digital ID Cards in the UK

It is being reported in the news this morning that the government is planning to introduce mandatory Digital ID cards, initially for a "right to work" purpose.

Forgoing the many legal and civil arguments for and against this; I wondered if people in the IET had opinions on the technical aspects.

Personally I am against what I have heard so far. There are no details on implementation yet, however with schemes like this that will usually not come until implementation long after parliamentary debate is over, so social debate cannot wait for full detail.

My main worry is that they have framed it as based around the smartphone. Saying it will be "like a bank card" (Lisa Nandy on Today). This seems (from admittedly vague and unsure descriptions from not-very-tech-savvy MPs) to be locking us into the duopoly of smartphone OSes, Apple's iOS and Google/Alphabet's Android. Neither is open source, and both are utterly controlled by businesses in the US. Obiovusly there are social concerns around forcing mandatory ID onto smartphones (it makes smartphones mandatory for one thing, despite the other worries about their effects. The same government is looking to ban them in schools!). But techincally how long will they be supported? How secure will they be? I suspect they will be very secure, but support will be expensive and tail-chasing after a while (5-10 years). Making the system web-based would be less secure, more open to abuse like DDoS attacks; but would unlink the system from operating systems. I doubt there will be any other variants, like a Linux-based way of providing your ID.

I am ok with many functions on my smartphone as they are optional, things I chose to do for convienence sake like banking and email. I am do not think this is the same. The mandatory nature should come with other support, be that physical cards for those that want to move away from these devices or businesses, or some other way to ensure that we are not destroying technical freedoms and future innovation by tying our entire society into 2 smartphone makers who already have immense influence and control, and whom the state have no sway over.

What are other people's thoughts? Any other technical issues you have concerns about (forgery, data breaches, verification)?

  • Hi Adrian, as with most things to do with IT, the problem is not when everything is going right, it is how to deal with it when it goes wrong! That aside, this is being promoted as a means to reduce illegal working. At the moment employers have to check people have a right to work, but there is no way for the vast majority of detecting forgeries! I suspect this will remain the case so overall gaining nothing except huge cost (see smartmeters and how much energy they save).

  • Until you said IT, I hadn't thought about the cost and time to implement...government not famed for quick and cheap IT implementations! Would it even be in place before the end of this parliament? And the current number of hack and data breaches worries me (Afgan leak, JLR hack, nursery breach...).

    The lack of checks in an issue they brought up with the minister on the radio (and she fumbled badly in response), but I don't know enough about employment checks generally to comment.

  • In general as UK society we forget that there are many people who don't have smartphones, or indeed any IT access. My mother, who passed away a couple of years ago, never had either, my in-laws have a PC but struggle with more than the simplest task on it, they can't cope with smartphones at all. It is HUGELY frustrating to keep getting the message "just go online" or "just download the app".

    Maybe I'm hugely naive, but I actually don't have a problem with this being on an app for myself, I do very seriously have a wider societal problem if it is only going to be online. (Plus also having a backup for the rest of of us for phone breakages, loss, no battery, no signal, etc etc etc.)

  • Agree completely. It has been an on-going concern for me with my elderly parents. My mother doesn't want a smartphone, and my father has advanced dementia and couldn't use one even if forced too. Recently I tried to open a sole bank account for my mother in a bank branch and was told unless it was setup on a smartphone, we had to call the same "special cases" line did using PoA for my father  as they refuse to do this work in-person in branch.

    The leaving behind of the elderly, poor and less well off though enforced digitalisation is a big concern. I think government should treat their systems like any safety control system, and have redunancy that uses different core systems (like paper files) for any out-of-the-norm cases.

  • "I am not a number, I am a free man!", The Prisoner (#6..) Patrick McGoohan. [Proper TV series]

    'imprisoned in a mysterious place called "The Village," where residents are identified only by numbers'

    We're all being decorporated (opp of being incorporated). If the 'Horizon' computer get's your fingerprints and Face ID wrong you become a non-person.

    What could go wrong?

  • The elderly are catered for by the fact that this system is going to take a very long time to fully roll out, very long if consultants and contractors are involved (certain). But edge cases will always exist - e.g. someone born here, lives here, works here, but a quirk of history enables them to have a foreign passport. HMRC does not recognise anything other than British passports so they have no way of dealing with it (but have no problem collecting the tax!). Yes I know someone like that and these edge cases need to be dealt with.

  • And although I used the elderly as an example (because they are the ones that I have personal experience of) please let us not assume that everyone else has a smartphone and the capability to use it.

  • I remember decimalisation (which caused the UK to drop the gold standard - apocryphal & untrue;-)  which also had the idea that they (the powers..) should wait until the old folks died off before bringing in the change. 

    Oh for the days of the 9-bob note and threepenny bits! On decimalisation I only had 50p pocket money.

  • Labour used to be the party of ::

    the elderly, poor and less well of

    They've gone wrong somewhere. Gross inequality is not a good look.

  • Currently it seems to be marketed as only being needed to prove to an employer that you have a legal right to work in the UK. (I highly doubt it will remain its sole use, and the many ways it can be abused is quite worrying, i.e. I have done plenty of work in China and they have issues... 

    Firstly how often are people really switching jobs.. how often will this be needed if used for what they are describing it as? 

    We already have passports, NI numbers. Of course the argument there is they can be forged.. I would likely think an app is far more easily copied that the security measures put in place within a passport. 

    How much did the government spend on trying to implement a track and trace system during covid.. and we all saw how well that functioned.