Comment by cute_boi

6 hours ago

I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

> They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

Because then that website would get compromised and lose the data on 350 million people instead of 153.

Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.

People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.

Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.

In Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)

You'd think that 80 million people from a rich first world country would be enough of a market to use this.

No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.

You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.

So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.