← Back to context

Comment by cute_boi

5 hours ago

I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

In Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)

You'd think that 80 million people from a rich first world country would be enough of a market to use this.

No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.

You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.

So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.