Comment by didntcheck

3 years ago

> I would love to see government IDs be available as a form of auth on the internet. It would open up the possibility of real-person communities with fewer bots and trolls.

And reintroduce all the chilling effects of knowing everything you say is on a permanent record linked to your name. I know the government wouldn't be running the sites, but they'd have activity metadata, and data breaches could be correlated to work out who the "opaque" ID refers to (perhaps it would be possible to mitigate that by having the IdP identify users to the site as a hash combining the site and the user. Not sure). There are a few types of companies that may have a genuine reason for requiring government auth, but generally we should not make it easy for Facebook or Google to require it

A community with fewer bots and trolls should be accomplished with moderation, and not just allowing a firehose of signups

Can't we have both?

Ideally, the government login/auth would be an opt-in for sites where anonymity isn't important. Facebook, for example, already has a real-name policy but still has fake accounts. Moderation alone isn't sufficient; it's hard to keep up with the number of bad actors. Limiting signups to verified humans, and possibly validating their nationality, can help with that IRT to bots and foreign agents.

It's important that the mechanism be opt-in, though, and yeah, metadata would be a problem. But realistically it's just a matter of degree... they already have access to all of that metadata today with just a subpoena or national security letter. Centralizing the login would make it easier for them to collect it, but also make it easier to audit via government mechanisms (FOIAs, etc.) compared to the opacity of private companies (which are under zero obligation to reveal how things are stored).