Identity

Identity is binary, not risk-based. Systems that treat it as a probabilistic assessment build in the opportunity and demand for the fraud that follows. A different architecture, from the individual person outwards.

May 2, 2024

A person's identity is precious, but because of the way technology and identity have evolved, today's systems don't treat it with the care it deserves.

That is not just a problem for the individual. It is at the root of hacking, account takeover, and fraud.

The issue is straightforward. Systems take a risk-based approach to identity when identity is actually binary. In isolation, a particular use case may not feel like it warrants strong identity verification, but the risk has to be considered through the lens of the user, not the use case.

A user's data is not used only in your interactions with them. They use it everywhere, because it is how they identify themselves to everyone. Bad actors exploit that ubiquity, correlating legitimate and stolen data to commit crime. A risk-based approach to identity provides the opportunity and creates the demand for the criminal activity that follows. The fact that a service does not always know who its user is, is both why it is hacked and how it is hacked.

The best identity systems are reserved (by virtue of cost) for banks and governments. Even those are flawed enough that money can still be stolen and identities compromised. That is not an argument for stronger versions of the same architecture. It is an argument for a different architecture altogether.

Companies should not be the arbiters or holders of a person's identity. The only viable universal context for a digital identity system is the individual person themselves. Everything else, from nationality to employment to qualifications, is a credential related to that person, not the identity itself.

Treating a person's identity with the care and respect it deserves looks like it might actually bear unexpected fruit. If the data isn't there to steal and the credentials can't be compromised, the problems caused by their presence also go away. Identity treated properly reduces cybercrime.

Encrypted, but to whom?
Prime Minister Andy Burnham exchanged messages with someone impersonating Trump's chief of staff. He worked out the impersonation. The problem is that they could reach him at all. The device in a public official's pocket has no identity layer.
Authentication
Authentication is meant to establish that a person is who they say they are. In practice, the mechanism checks a credential — and adding more factors does not change what is checked. The research asks how authentication can check the person, not just the credential.
Digital signatures
Digital signatures inherited the name from wet ink but the mechanism is actually cryptography. Digital signature tiers are honest accommodations for an identity gap they cannot close. The research asks what a signature is, once the document is no longer the point.