Posted in

Digital Identification Can Fight Identity Theft, But its Design Matters

Back at the beginning of 2020, the onset of the COVID-19 pandemic brought with it a sudden rush to digitization in all sectors. Companies built hurried infrastructure to support newly-remote workforces, and governments scrambled to stand up online portals to distribute information and assistance. It was a stunning example of the transformative power of today’s leading-edge digital technologies.

But it also created opportunities for criminal elements around the world to strike. And strike they did.

By pouncing on infrastructure vulnerabilities and legions of undertrained workers, cybercriminals created a wave of identity theft that hasn’t crested yet. And that new threat landscape has privacy experts and government agencies around the world looking for new solutions to the problem. Foremost among the potential solutions are systems of digital identification that allow individuals and governments tighter control over access to identity data.

The right solution, however, is proving elusive. That’s because there are some competing forces at play that have seemingly opposing interests in the subject. Here’s an overview of what they are and a look at three principles of an equitable digital identification system that could lead to a solution to the impasse.

Security Vs. Control Vs. Privacy

The central disagreement about efforts to create digital identification systems is over where to draw the line between security, centralized control, and the individual’s right to privacy. Governments, on the one hand, wish to centralize control over digital identification systems. They argue that they’re the only ones with the reach and wherewithal to build and safeguard workable digital identification systems.

But as the recent controversy over the use of a privately-run facial recognition system by the Internal Revenue Service in the US proves — even governments in wealthy nations tend to outsource their technology initiatives. And that points to the second part of the disagreement: the concern over keeping people‘s identities secure.

Privacy advocates have long questioned the ability of private sector actors to maintain data security. And as the massive Equifax data breach in 2017 demonstrates, those fears are often well-founded. Furthermore, privacy advocates warn that digital identification schemes might give rise to discriminatory practices. And there’s already evidence of it happening within some of the countries that have already adopted digital identification systems.

Overcoming the Challenges

The important thing to recognize about the impasse is that it’s eminently possible to devise a digital identification system that will address the needs of all involved. The key to doing it is to make any prospective system adhere to some basic principles that will guide its design. And here’s what they are.

Access Minimization

To design a digital identification system that will remain defensible and defeat identity thieves, it’s important to minimize who gains access to the data in the system. As anyone that knows the basics of identity theft can tell you, the main problem that plagues today’s identification systems is that gaining access to a single piece of data is often enough to unlock the rest.

For example, an identity thief who gains access to a US resident’s social security number has everything they need to use that person’s identity to wreak havoc. The reason for that is simple — a social security number is used to establish new accounts, replace official identification documents, and do almost anything else a scammer would require. And because of that, people have to disclose their social security numbers to organizations of all shapes and sizes, which increases their odds of victimization. In other words, it’s a problem that feeds itself.

To avoid that, a proper digital identification system must limit information disclosures on a need-to-know basis. That way, when a person needed to provide identity data to another person or organization, they’d only disclose what’s needed. So, if you went to purchase an age-restricted product, the seller would only see your age — not your address, date of birth, and other extraneous information as now happens with present-day identification systems. That would limit identity theft by reducing the number of places that a thief might acquire sensitive identity information.

Transparency

To address the privacy issues that come with any attempt at building a digital identification system, it’s also necessary to build complete transparency into the solution. In this case, this means giving individuals within the system an easy way to see who has access to their personal data and why. That’s the only way to create the trust needed for people to participate willingly.

It also would turn every participant in the system into a safeguard against its abuse and misuse. By allowing complete transparency, it would be impossible for an unknown actor to gather or use data from the system without someone raising an alarm. It would also help to rein in the private businesses that now thrive by buying and selling people’s personal data — some of which now includes identity information.

Universality

The last principle that any prospective digital identification system should adhere to is universality. That means it must be a system that everyone can participate in with minimal barriers to doing so. For that reason, the ideal system should be politically neutral and used to validate identity only. It should also be an entitlement — as in, free to acquire and available to everyone, everywhere.

That’s the only way to ensure that the use of a digital identification system won’t feed inequality and won’t enable discrimination. It’s an issue that plagues traditional forms of identification that could easily get worse in digitized form. And it’s another major barrier to convincing people that a digital identification system is both viable and a good idea.

The Takeaway

The most important thing to recognize about the future of digital identification systems is that they’re going to appear in one form or another — especially at the national level — quite soon. And that means it’s important for all stakeholders to come together now to hash out their differences on how those systems should work.

By building digital identification systems that adhere to the three principles detailed above, it should be possible to achieve the right balance between security, control, and privacy. And what’s more, it should lead to a system that benefits everyone that uses it while minimizing the chance for abuse. At the end of the day, that’s the outcome that all sides should be looking for, and it’s well within reach.

 

My primary focus is a fusion of technology, small business, and marketing. I’m an editor, writer, marketing consultant and guest author at several authority websites. In love with startups, latest tech trends and helping others get their ideas off the ground.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.