← Back to context

Comment by AnthonyMouse

1 hour ago

> They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

Because then that website would get compromised and lose the data on 350 million people instead of 153.

Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.

People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.

Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.