The Register Home Page

back to article UK digital ID may be dead, but its legacy IT problem lives on

Legacy government systems would have posed a significant barrier to the UK's abandoned national digital ID scheme, according to the country's spending watchdog. The National Audit Office (NAO) has published a review of the digital identity landscape and the lessons that should inform any future attempt to introduce a government- …

  1. Doctor Syntax Silver badge

    There are ~70m people in the UK. Good luck with getting 100% accuracy on that many. Even more good luck to the 700,000 trying to get out from under the errors of a 99% accurate system.

    1. Like a badger Silver badge

      Digital ID systems seem to work acceptably in some other democratic countries, and are often associated with a more efficient public sector.

      We're already "identified" by a range of digital government tags that weren't mostly weren't designed for the purpose and often permit a single individual to have multiple entries, such as Passport number, NI number, NHS number, Unique Taxpayer Reference, Government Gateway ID, Driving Licence number etc. I really can't see why people are so busy objecting to a proper national ID system. As soon as it was raised, it seemed most of the population defaulted straight into Daily Heil objections, "I didn't fight in two world wars..." and similar crap, followed shortly thereafter by moaning about how bureaucratic, slow and inefficient British government is (based largely on zero facts).

      1. AMBxx Silver badge

        >> often associated with a more efficient public sector

        Think there may be a problem with causality there!

      2. Adair Silver badge

        We're already "identified" by a range of digital government tags that weren't mostly weren't designed for the purpose and often permit a single individual to have multiple entries, such as Passport number, NI number, NHS number, Unique Taxpayer Reference, Government Gateway ID, Driving Licence number etc.

        And if that fuzziness and 'inefficiency' helps protect individual people from the overweening power of a 'government' that has some misbegotten idea that it's job is to be in control of everyone and everything, then what's the problem?

        Since when was 'being human' about 'perfect efficiency', or anything remotely approaching that? Sometimes 'good enough' really is all we need to be released to get on with life. And, in the light of that, being 'good' in the ethical and moral sense, is enough when it comes to the powers of the state being able to serve the needs and well being of people.

        1. JC_

          A unified system really would help people. For example, when moving, record once a change of address and no need to do it on multiple systems (council, driver's licensing, etc.)

          The information is there, there's no privacy benefit from pretending it isn't. Indeed, unifying the storage so access can be reliably controlled would offer more privacy benefit than what we have now.

          But for some reason the British public is convinced that the only right and proper way to prove they are who they say they are is to possess a tatty print out of a council tax bill...

          1. Tron Silver badge

            Because...

            ...the British people know that any system their government set up would be a disastrous and expensive failure, and would get hacked (like the French ones were recently). You want the police to police access? How many coppers illegally accessed data on police systems this year, last year, and will next year. And those stats are just the ones that got nabbed.

            We trust our government about as much as Americans or Russians do, which isn't very much. So having STASI level data on us is not a good thing. Better to muddle through using old utility bills.

            1. Like a badger Silver badge

              Re: Because...

              So having STASI level data on us is not a good thing

              Having a single identifier instead of ten, how exactly is that "STASI level data"?

              1) We already need to go through multiple levels of pantomime to prove who we are for many, many things, they already have all the data. All that's being talked about is having a single reference number for a unique individual.

              2) You're as much at risk of abuse and data protection failures with the existing systems, and those systems wouldn't be linked just because they use this unique identifier.

              1. Missing Semicolon Silver badge
                FAIL

                Re: Because...

                Uniquely identifying you is exactly "STASI level data".

                Plus, as other commenters point out, the new system would be built by the usual suspects, so would be late, slow, bug-ridden and insecure. And, given what happened with just about every security-related law, would be used for all of the uses that they claim it won't be used for.

                At the moment, the current fragmented, obsolete system works for us. The new system would work for them, and we would be crushed underfoot by the errors, security failures and misuse. If your ID gets broken, you could not do anything with state services, and might find yourself subject to random traffic stops if your ID gets linked to a miscreant ID (a useful feature for miscreants aiming to slide through the system).

              2. doublelayer Silver badge

                Re: Because...

                You're leaving a few parts out, including that the ID isn't just a value identifying you but software you must put on a device and keep active so you can supply it to others. I think you'd also get opposition if it was a unique identification document or even a unique identification number, but unsurprisingly, the more invasive the ID method, the more objection you'll get and for good reason.

                Of course, a major part you also left out is the use of that, both the stated uses and the ones the public has a reason to expect. It was already confirmed that you'd have to show the ID to employers in an attempt to pretend it would help with immigration when it clearly wouldn't. It was proposed as a method of age verification online, and since the existing methods supported by the Online Safety Act don't actually work, it would have been quite plausible for them to adopt this which would work but would also give them a database of your browsing history. These things are very relevant, because if people don't trust you to act honestly, they'll try to limit your powers because they expect you to abuse them. It would seem that, at least among the UK readers here (I'm not in the UK) and the more general response, the UK government doesn't have that level of trust from its citizens. Maybe proponents of this system should work on that.

            2. JC_

              Re: Because...

              This is just learned helplessness and there are successful government IT projects, for instance, GOV.UK.

              The system we have now is ridiculous. To prove identity we are relying on private companies, e.g. Thirdfort, forcing Brits to send them sensitive information. Our government could easily use the information it already has and confirm instantly, and securely, whether a person is who they claim to be.

          2. Anonymous Coward
            Anonymous Coward

            A unified system really would help people.

            But it would really fuck them up in far, far more ways than it might make it slightly more convenient to move house.

      3. R Soul Silver badge

        I really can't see why people are so busy objecting to a proper national ID system

        Ever heard of wilful blindness?

        A single over-arching national ID means pervasive 24x7 surveillance of everyone. The harvested data will be abused by the state in a far more pernicious way than it is done currently: the snoopercams already on our streets for instance. That data will also get sold to the likes of Palantir, Oracle, google, M$ and Facebook. HMG's carefully chosen marketing partners will get in on the action too: stop buying beer on your weekly trip to Tesco Mr. Soul - use this 20% off coupon at Lidl instead. Only the most deeply stupid could possibly choose to sign up for that dystopian Orwellian nightmare.

        It's also improbable this over-arching national ID could be made to work reliably and interact sensibly with the diverse databases run by the police, DVLA, HMRC, NHS, local council, Passport Office etc. Those databases BTW are run by the likes of Fujshitu, Crapita, Palantir, Serco, Accenture, etc. They'll make billions trying and failing to make all this crap work from contracts that will go on forever.

        Now suppose we suspend reality and assume this over-arching national ID and database existed. Imagine what our Poundland Fuhrer would do with that database if he somehow got elected? Well OK, I did suggest we suspend reality.

        Next, each of those ID tokens you mentioned have a clear, narrowly scoped purpose. Which is perfectly sensible. After all, compartmentalisation a fundamental security principle. If your Blunkettcard/Tonycard/Starmercard got lost or stolen or cloned you'd be fucked. Losing a passport (say) would inconvenience your overseas travel plans for a while. But it wouldn't affect your ability to hire a car or pay tax or visit a doctor or open a bank account or get served in a pub or... Once these things depend on having a Blunkettcard/Tonycard/Starmercard - and they surely would - you'll be fucked until the local gestapo, sorry ID card processing centre, issues a new one. Have a nice day citizien!

        Do you have exactly one key for all the locks in your house, car, office, piggy bank, garden shed, gym locker? If not, why not?

        1. Goodwin Sands Bronze badge

          Re: I really can't see why people are so busy objecting to a proper national ID system

          >Imagine what our Poundland Fuhrer would do with that database if elected

          That's an odd thing to think.

          Agree with all you've said except for where you think the future danger lies.

          The Poundland Fuhrer is a free marketeer who believes in hands-off small statism and individualism. Seems unlikely he'd become big brother.

          Current Labour, on the other hand, manifestly believe in big, cradle-to-grave interfere-with-everything all encompassing state socialism. Two-Tier Keir has already taken us a good way down the road to totalitarianism, and after hearing what the new Bus-Conductor-in-Chief Mr Burham said ydy he is clearly going to take us even further.

          1. Anonymous Coward
            Anonymous Coward

            Re: I really can't see why people are so busy objecting to a proper national ID system

            "The Poundland Fuhrer is a free marketeer who believes in hands-off small statism and individualism. Seems unlikely he'd become big brother."

            I wouldn't count on it. All bets are off if he somehow seizes power. Except this one: he'd use the ID database to round up all the Patels, Khans, Mohammeds, Singhs, etc. And then go after everyone else who isn't a blond Aryan.

          2. Anonymous Coward
            Anonymous Coward

            Re: I really can't see why people are so busy objecting to a proper national ID system

            Bless your simple heart, free marketeers are the ones who have the most fingers in the pie so a huge trove of data like that would be crack cocaine for them.

        2. Fred Daggy Silver badge
          Meh

          Re: I really can't see why people are so busy objecting to a proper national ID system

          Alternate view (a proposition).

          What if said National ID had the ability for you to audit all access to your own ID. Every time a human has to access it, they need a reason. Whether that be a case number or a text description. Then the ID of the person doing the accessing, name and department.

          "The honest copper/bureaucrat has nothing to fear." Fat fingers can be protected against with some good check digits, so that excuse should just go.

          Still not saying a national ID is a good (or bad) idea. Just that protections can be built in to the system.

          1. doublelayer Silver badge

            Re: I really can't see why people are so busy objecting to a proper national ID system

            If criminals can audit their identity for case numbers, that gives them the opportunity to detect police interest when the police are still early in the investigation and hide evidence or themselves. To stop that from being an issue, we'll need a way to keep that audit log closed, but we can access it later if it becomes an issue in court. That means that there's no oversight about what gets put in the text description for quite a while, so in practice they can do whatever they want. Oh dear, I think we're back where we started, even if someone did try to put that auditing in place which I don't remember being a part of any of the stated plans.

          2. SundogUK Silver badge

            Re: I really can't see why people are so busy objecting to a proper national ID system

            They will never allow that. Breaks the primary purpose of introducing ID in the first place.

        3. Anonymous Coward
          Anonymous Coward

          Re: I really can't see why people are so busy objecting to a proper national ID system

          A single over-arching national ID means pervasive 24x7 surveillance of everyone.

          My god, the rampant luddism, the logical fallacies, and the wilful ignorance in those few words! An impressive achievement. You chose your username well.

          1. JimboSmith

            Re: I really can't see why people are so busy objecting to a proper national ID system

            What amuses me is the idea that this ID card data wouldn’t be abused in anyway at all. I’m currently in the USA and Flock cameras are the very hot to potentially radioactive topic at the moment. For those who don’t know, these are the Automatic Number Plate Recognition cameras that have sprouted up everywhere with contracts that range from city councils to police departments. To say they are unpopular is like saying there was a small outpouring of grief when Princess Diana died. They’re hated and not just by those who break the law, I haven’t spoken to anyone who thinks they’re a good idea.

            The data they collect is available nationwide to those who have a contract. They don’t work with the Immigration and Customs Enforcement (ICE) but some police will run searches for ICE instead. Even better some just give full access to the Customs and Border

            https://jsis.washington.edu/humanrights/2025/10/21/leaving-the-door-wide-open/

            Records obtained by UWCHR researchers via public records requests reveal that at least eight Washington state law enforcement agencies enabled direct, 1:1 sharing of their networks with U.S. Border Patrol at some point during 2025; effectively opening the “front door” for searches potentially related to civil immigration enforcement activities.

            Flock audits reveal apparent “back door” access by U.S. Border Patrol to the networks of at least ten Washington police departments which did not explicitly authorize Border Patrol searches of their network data.

            That’s before we come onto people who legitimately have access abusing it. Such as a Sheriff’s Deputy who stalked his girlfriend searching her licence plate 2055 times.

            ttps://fox59.com/news/jackson-county-deputy-allegedly-used-flock-cameras-to-search-same-license-plate-2055-times/

            There is a list of over 100 other abuses listed here https://ij.org/the-ij-database-of-alpr-abuse/

            There are as reported on this esteemed site people who have been arrested for deciding to de-flock their neighbourhood. In Florida a man was arrested after a police officer made at home a 3d printed replica of a flock camera and put it up. They then sat there and waited for someone to damage it and it apparently didn’t take long.

            https://www.nytimes.com/2026/08/26/us/flock-camera-decoy-vandalism-arrest-florida.html

            A lot of access creep there, abuse and misidentification which is obviously perfectly fine

            Now in the UK what would I have done with a Digital ID when I don’t have a phone that has a wallet on it? My financial advisor has known me for at least 20 years (possibly as much as 30) and he’s a very nice bloke. He asks me for normally a utility bill and a passport that he can copy every so often for Know Your Client regulations. Someone who was in favour of the Digitsl ID said it can be used to help stop money laundering which made me laugh. I asked how that would work and he then seemed lost for a bit before mentioning opening a bank account would need a Digital ID.

            So what happens with overseas students who need a UK bank account? When they go home some of them sell their accounts to Launderers aka Money mules. What about the Informal Value Transfer System or the Trade Based Money Laundering What about Cryptocurrencies and their ease at transferring funds around the world quickly without any scrutiny? That floored him and he didn’t know any of those (with the exception of cryptocurrency) happened. I asked how much he really knew about money laundering and he admitted to actually not knowing a fat lot. He tried again with the NHS and you could prove who you are when seeing a doctor. I came back with oh goody so with a centralised database it wouldn’t take someone and possibly AI to get a digital picture of your life. Would you be comfortable knowing that your hypothetical visit to the clap clinic was recorded, followed quickly by you using your ID to prove who you are, to pick up a prescription from the local pharmacy? He persisted he was in favour but a bit more half heartedly now.

          2. Anonymous Coward
            Anonymous Coward

            Re: I really can't see why people are so busy objecting to a proper national ID system

            Your own achievements in the field of wilful ignorance are even more impressive. A single over-arching national ID will be (ab)used for everything. Try thinking about it.

            If you want to live in an ID cards for everything Orwellian nightmare, the likes of North Korea or China will he happy to oblige. Try living there.

      4. Kraggy

        All those numbers would be irrelevant if there was joined-up IT instead of a vast number of silos where careers are built by doing something other departments don't making you indespensible.

        IMO the UK has some of the worst central governement bureacrats in the world and their abysmal record of IT failures speaks volumes on that.

      5. Lee D Silver badge

        It's not the ID that I object to.

        It's the usage of it.

        Even in the Manchester ID card trials, and in all kinds of other "database links", we had all kinds of nonsense where councils were hunting down people who put their bins out on the wrong day using databases that were nothing to do with that.

        Do it badly, and it becomes a cash-cow for government, not to mention a prime tool for fascism (look at Trump with the whole Musk / DOGE thing, the immigrant hunts, the trans bloodhounding, etc. etc. etc.).

        I have unique identifiers for all kinds of things, and you can link them together quite simply. Government can already link my credit card to my national insurance number if they want to. The problem comes when you let ANYONE with access to one of those do it to all the others. Which ALWAYS happens because the purpose of many people opening up their databases like that is to monetise them (e.g. Palantir, etc.).

        There's nothing wrong with it in theory until you consider human nature, and capitalism, being thrown into the mix. Do I want the guy at the council offices knowing what I had for dinner, the doctor in hospital being able to look up what media I downloaded last night, the council using face recognition to fine me for putting something in a bin or - another recent US example - picking up a note from the floor? That's where the problem lies and it's endemic. Celebrity incidents? NHS lookups of their data from all over the country by supposedly authorised and trusted people. Cops getting access to ANPR directly? Now you have American cops literally stalking their ex's to see where their car went. NHS data on you? Well, now you can be targeted for advertising for those incontinence pads on Facebook. And guess how much the press would pay to get access to, say, a politician's private browsing records? And so on. It's worldwide. It's inherent. It happens all the time. These are literal, real-world, scenarios that have been facilitated not by "having ID cards", or even by "joining databases", but because whenever we join databases, people get access to information that they ABSOLUTELY SHOULD NOT have, in breach of GDPR and DPA (which openly state that the POTENTIAL for access is the exact same thing, legally, as having access... and access should be only that minimal amount necessary to complete the task at hand).

        Nobody cares about the card. It's about who's pushing the card, for what purpose, and what misuse will that enable?

        Read behind the headlines and people don't give a damn about having a card that identifies them so they can buy alcohol before they get a driver's licence. They care about a landlord demanding to get access to your ID and then performing all kinds of checks irrelevant to the necessary elements of renting a house - maybe looking up your public criminal record, or your credit score without your consent, or even checking a "landlord's ID database" of people that other landlords have refused to rent to, or even just seeing if you've been a bad driver, and so on.

        And the more you normalise ID cards, the more those kinds of 3rd-party databases crop up, the more official databases get sold on, and lost, and leaked, and abused, and the more you lose any kind of ability to lead a life where someone doesn't know everything about you at the click of a button.

        It's none of my council's business if I've paid my income tax, or if I have points on my licence, or if I use the NHS sexual health services, or whether I'm up to date on my state pension, or where I went on holiday this year. Similarly, it's none of the DVLA's business for most of that, or whether I've paid my council tax. If they want to know that, for legally-required purposes (e.g. to detect fraud), they can ALREADY ask a court to give them access to that information for the purposes of detecting crime, for example. So why would they ever need more than what they already have? Convenience, that's all. The problem is that security and convenience are often polar opposites.

        The world moves on and functions just fine without ID cards or digital ID systems. So they aren't vital at all. They're convenient. However, every implementation has had some scandal or flaw which, for a system purely of convenience, is one potential risk too many.

        FYI, I have "nothing to hide". No convictions (I work in a school, so subject to an Enhanced DBS check and immediate notification if that changes). No driving offences. No tax evasion. No embarassing health problems. I don't fly to risky countries. Nothing like that. I even had a digital ID for tax submissions at one point (it was then later obsoleted and replaced with something else, so that was a waste of time). The thing is... the digital ID adds nothing to my various methods of other identification.

        Now think back to COVID where the government wanted you to run an NHS app 24/7 with not just your location, but the identifiers of everyone near you at the time, so that they could put you out of work temporarily and alert the health authorities. How much stuff was that joining together? And did you read the T&C's? Because they were allowed to do a LOT with that data. Fact is, it could go off because someone in the flat above yours or the office adjacent to yours, but separated by 9 inch of brick and concrete, got COVID. And it could then advise you to not attend work because of your proximity to such.

        If you don't see how that can not only be misused normally (by the government of the time that were doing billions in fake-PPE scandals, and partying in Downing Street), let alone misused when someone like Trump gets into power (who is being stymied at most turns by Supreme Courts knocking back his demands for access to that kind of data for immigrants, trans-gender people, etc. etc.)... then I don't know what to tell you. Maybe read a book or two about what happens in those kinds of regimes. And we're not talking about some backwater African banana republic, but the USA.

        It's not the card. It's not the ID. It's not even the existence of the databases. It's the LINKING of them, and the ACCESS between them. That's where all the danger lies. And that's precisely what every ID card scheme targets - "we'll just join all these disparate systems and homogenise them so everyone can see one set of data".... it's never done the way it should be done.

        1. R Soul Silver badge

          +10000 to all of the above.

          Though you could have added something about "if you've nothing to hide, you've nothing to fear" - that depressingly common trope from the hard of thinking.

          1. Missing Semicolon Silver badge

            "If you give me six lines written...."

        2. Anonymous Coward
          Anonymous Coward

          But I don't know why the current party in power in the UK would be let off the hook, it's largely them that have pushed it in the last 30 years, even if the current PM knocked it on the head because of cost.

      6. Anonymous Coward
        Anonymous Coward

        moaning about how bureaucratic, slow and inefficient British government is (based largely on zero facts).

        Based entirely on direct personal experience.

        From your previous posts it is clear that you are a civil servant. That you can't see the problem is the problem.

    2. Anonymous Coward
      Anonymous Coward

      I've said before that the whole demand for perfection is idiotic - there's no such thing. The reason the EU-wide scheme works is because there is a risk margin that has been accepted and managed.

      That's exactly what risk management is for.

      1. Dan 55 Silver badge

        What EU-wide scheme? Depending on the country in question, ID cards are either mandatory, optional, or don't exist (Denmark, Ireland).

        1. Anonymous Coward
          Anonymous Coward

          Ireland has a digital public services card for verifying with public services online, i.e skipping the inperson visit to the department's office...

          Basic version which only needs and email "Basic MygovID"

          SAFE2 verified in person "Verified MyGovID"

          https://www.citizensinformation.ie/en/government-in-ireland/how-government-works/egovernment/mygovid/#dcd9ee

          Supposedly €8.1 million to develop and maintain between 2014 and 2020.

          For Revenue, Passport applications, Student grants,, vehicle ownership changes

        2. Anonymous Coward
          Anonymous Coward

          For me it makes it possible to sign a document and have it digitally verified anywhere in the world as there is an EU root cert from which the national certs are drawn so there's a validation path. In Europe it also carries legal validity. There are also signs that the EU is moving towards making the ID card work like a passport inside the EU as it now carries both the ID chip and a separate chip and RFID loop with the exact same biometrics as the chip in your passport.

      2. Tron Silver badge

        You presumably don't mean the EU-wide airport entry.

        Which has resembled a chocolate teapot in a heatwave since they launched it.

        1. Anonymous Coward
          Anonymous Coward

          Re: You presumably don't mean the EU-wide airport entry.

          That's unfair to chocolate teapots. They're yummy => they have a use, even when they've melted.

    3. Anonymous Coward
      Anonymous Coward

      The logical way to do it would be to confirm the one's that are correct based on all the systems matching. NHS, Tax, DVLA, Passport and so on. Didn't they recently get access to banking systems as well?

      Then you would send letters to the rest to confirm through government ID online. Once they confirm you get all the government systems to match.

      Not that it matters anyway because it's what all those shiny new AI data centres are going to be working on. They won't need a digital ID because nearly everyone will already be identified with added biometrics and data from everywhere with Palantir. We are pawns walking into a new world.

      1. Anonymous Coward
        Anonymous Coward

        So, let's add this up. Idiocracy became a documentary with Trump I, Terminator is heading that way with AI and the war in Ukraine and now even the access control scene in Monsters vs Aliens is becoming a reality.

        Christ.

    4. phuzz Silver badge
      Stop

      There are ~70m people in the UK. Good luck with getting 100% accuracy on that many.

      You could say the same about practically any part of the government, the tax office, the DVLA, passports Land Registry, National Insurance etc etc.

      None of them are 100% accurate, but all of them are better than 99% accurate.

      1. Adair Silver badge

        99% accurate isn't anywhere near good enough if you are talking about a system that you depend on for 'all' the basic essentials of living in a functional society. Do the maths on a 1% failure to work scenario on the billions of 'transactions' a year that ~70M people would generate.

        1. Anonymous Coward
          Anonymous Coward

          It appears that quite a few countries in the EU manage just fine. Weird, huh?

          1. Adair Silver badge

            Manage just fine - according to whose metric - with the system they have.

            To date the UK proposals have all tended towards the 'all-singing-all-dancing-every-department-wanting-access-and-a-say' kind of system, with all the manifold possibilities for failure and abuse such an approach inevitably brings, including the woeful idea that a 'success' rate of 99% would somehow be anywhere near good enough. It wouldn't unless you really want to live in a hellscape of thousands of failures a week, and how those failures would be managed in reality.

            The old Unix software mantra of 'Do one thing, and do it well' has a very good reason for existance. But the idea of applying it to a national 'ID system', assuming such a thing is even desirable, seems to be unconscionable in the minds of certain power hungry politicians, bureaucrats, and all manner of money-grubbers.

  2. Elongated Muskrat Silver badge

    Use cases

    There may be use cases where a digital ID is beneficial to Joe Public, for example if it can prove someone's age without revealing their identity, or any identifier, pseudononymous or otherwise.

    The risk is that these things can be used to track individuals, and that tracking can be done not just by the government department that issues the "identify", but anyone who can access it.

    ANPR can already be used to track vehicles, and whilst this might be touted as a way for the Plod to track criminals, it also provides a way for stalkers or abusers to track their victims, and you'd be naïve to think that no coppers are bad actors.

    Inventing a new system to identify and track individuals poses a real risk to privacy, and even if not being criminally abused, erodes Article 8 of the HRA (the right to a private life).

    The technical challenge here, if ti is even possible to meet, is to produce something that allows people to identify themselves, or prove an aspect of their identity, in a verifiable manner, but without leaking any other information to anyone, either the person to whom you are idnetifying, or the state-run (or more likely privatised) identity provider. In an ideal world, there's nothing wrong with being able to provide a short one-time "unique" random code to a web site to prove you are over 18, that reveals nothing about you, and is not logged in any way by the provider, but in practice there are so many loopholes an possiblities for this to be exploited.

    For example, even if the provider only returns a "yes or no" answer, they could log that "Joe Bloggs" visited "hairymilfs.com" at 01:15 on Sunday morning and then use this to build a profile of Joe's sexual preferences. A future authoritarian government could then decide to round up and exterminate anyone who has shown an interest in hirsute mothers (for example). It's worth remembering that the Nazis had an easy job of identifying and rounding up their target victims in the Netherlands exactly because the record keeping on their citizens was so good, and this is exactly the threat that this poses; the "it'll never happen here" argument failed then, and it will fail again.

    Then you have the issues of criminal infiltration of the system, corruption amonst those meant to maintain it and controls on unauthorised access. A parallel here is the unauthorised acces of police systems; people semi-routinely lose their jobs in policing for looking people up on PNC when they should not. Yes, there are consequences, but they are post-facto, the information has already been accessed.

    1. Elongated Muskrat Silver badge

      Re: Use cases

      I see the downvote-bot has found me again; I wear it as a badge of honour that someone sees me as such a threat that they have to come and systematically put a single down-vote on every one of my posts. I must be doing something right. I can be pretty sure that this is the case, as well, since I don't tend to get that single down-vote when I post AC.

      I would have thought that imploring people to pay attention to history and to consider unintended consequences would be a relatively uncontroversial opinion, but here we are. I might add that the threat this poses is greater than the one that the last attempt under Tony Blair posed, given that fascism seems to be having a real renaissance at the moment.

      1. Anonymous Coward
        Anonymous Coward

        Re: Use cases

        The Upvote bot strikes again.

        1. Elongated Muskrat Silver badge

          Re: Use cases

          Yet those making the down-votes never seem to actually respond with any sort of counter-point, just with snarky AC drivel.

          I know the modern internet is entireyl geared towards farming engagement from conflict, but really, do try harder.

          1. G Watty What?

            Re: Use cases

            "snarky AC drivel" - If only they had a unique ID

            1. Anonymous Coward
              Anonymous Coward

              Re: Use cases

              They do. You may be anonymous, but in these forums you're not unaccountable (at least, your account isn't) as an A/C post requires an established login. And you accumulate rights, a new account does not immediately have access to all facilities. I can't find the page right now, but it's properly explained somewhere.

              Personally I find it one of the better ways to handle user privacy.

      2. Anonymous Coward
        Anonymous Coward

        Re: Use cases

        I think 'they*' do it with scripts - I had it done for about a year. It didnt stop until I changed my username for a while.

        *they being anyone who disagreed with you once and the chops and general malevolence to do it.

        1. Elongated Muskrat Silver badge

          Re: Use cases

          Yes, pretty sure I know which "they" it is too. Well, it's their own resources they're wasting I guess, but it does make you wonder what their agenda is, beyond sheer pettiness, to make it worthwhile. It's not like the vote counts atually do anything. I don't really care enough to make it worth trying to find out though, I just amuse myself by letting them know they're seen every now and then.

          1. just4this Bronze badge

            I know who they are.

            https://www.youtube.com/watch?v=XVU3KCZnqGc

            Our interdisciplinary team of cognitive architects and social harmony specialists continuously analyse global thought patterns. Contradictory studies filtered out. Fringe perspectives deprecated. Dissenting voices harmonised. At day we don't just follow consensus. We create it. Legacy thinkers may resist. They call it freedom. We call it latency. Your compliance is our compassion. Your individuality is inefficient. Join the sync. <--- taken from transcript of the vid.

            You think better when we think for you.

            1. Anonymous Coward
              Anonymous Coward

              Re: I know who they are.

              That's the sort of word salad I got when I instructed Copilot at work to give me an as verbose and complexly worded analysis of a document. It was *very* entertaining.

              (yes, I was bored)

        2. Jellied Eel Silver badge

          Re: Use cases

          I think 'they*' do it with scripts - I had it done for about a year.

          At least one 'they' certainly does because they posted and boasted about their script prowess in creating their own ignore function and automatic downvote. Simply because I wouldn't agree with them. And if one person can do it, others can as well I guess. And in some ways, highlights one of the risks to natonal ID databases, if skiddies can poison the well.

          1. Elongated Muskrat Silver badge

            Re: Use cases

            Ok, whatever you say, товарищ.

            1. Jellied Eel Silver badge

              Re: Use cases

              Ok, whatever you say, товарищ.

              Oh? You're Russian? I didn't realise. In that case, have an upvote, friend..

    2. Anonymous Coward
      Anonymous Coward

      Re: Use cases

      For "risk" read "will"

  3. Anonymous Coward
    Anonymous Coward

    Let's be clear about this. The reason the government cancelled the digital ID is because they realized how much it would actually cost to implement. Not because it was unpopular with voters, or enabled unprecedented government snooping and control of people's lives (Like the GDR but with modern technology).

    They still want it, they will just work towards it more slowly and quietly. Using existing maintenance budgets to gradually improve compatibility between the legacy systems until they get to the point that integration becomes easier and cheaper. At that point it will rear it's ugly head again.

    1. andy gibson

      I don't think it was anything to do with cost - when has a government cared about the cost of anything or value for money?

      Burnham just wanted to quickly please the electorate.

      1. Adair Silver badge

        Sometimes 'pleasing the electorate' is exactly the sensible and right thing to do. All the more so when pleasing the electorate means dropping a horrendously expensive, incompetent, and divisive project.

      2. Anonymous Coward
        Anonymous Coward

        When has a government cared about pleasing the electorate? Only in an election year, which isn't until 2029.

        1. Elongated Muskrat Silver badge

          We live in a world now where well-funded minority interest parties are constantly in campaigning mode, which left unchecked can bring down a government through drip-fed negative public opinions. Funnily enough, those parties really dislike scrutiny, especially scrutiny along the lines of "where is all your money coming from?" and "cui bono?"

        2. doublelayer Silver badge

          They just selected a new party leader. Pleasing enough of the electorate, or at least enough of the subset they think they should be caring about, is a way to win that smaller election.

    2. phuzz Silver badge

      Referring to 'the government' as a single entity isn't very useful. For starters there's elected politicians, vs the Civil Service, and then the Civil Service itself is split into all sorts of departments, each of which will have some kind of opinion on ID cards (which might be quite different from the opinions of the individuals who work there).

      Different factions of the government want different things, and if your conspiracy theory isn't accounting for this, it's too simplistic.

      1. Kaleyard

        @phuzz

        You're right about the CS. There are several departments each with their own agenda who are interested in digital id. However none of them will move forward on such a contentious policy without approval from the very top.

        And the man at the very top is currently in voter pleasing mode. Anything and everything he can do that wins him voter approval he's actioning, including pausing, sorry abandoning, digital id.

        If his vote share increases enough he'll call an election this year or early next. If he wins that then heaven help us because digital id will be one of the least things we'll suffer.

  4. Roland6 Silver badge

    But will it stay dead?

    As others have noted there are use cases, attractive to some, and thus I doubt we have heard the last of Digital ID. Would not be surprised if the post 2029 GE government tries to resurrect it,

    1. Anonymous Coward
      Anonymous Coward

      Re: But will it stay dead?

      Who was it that said the price of freedom is eternal vigilance?

      The wannabe stasi at the Home Office have been trying to bring back ID cards ever since Churchill scrapped them in the 1950s. They'll keep trying and only have to get lucky once. Expect yet another failed attempt in 10 years or so - just like before. Next time, they'll probably have a cuddly new name for their snoopercards because the recent names have been tagged with failure.

  5. Kraggy

    Trust government departments to come up with umpteen ways of "representing" me! Do they ever employ IT PROFESSIONALS?

    1. Elongated Muskrat Silver badge

      Working as an IT professional, and having known many other such professionals in my long career, I can assure you that if youy take the number of such professionals, n, then the number of ways fo representing that data will be n + 1.

      1. JT_3K

        Obligatory https://xkcd.com/927/

    2. Anonymous Coward
      Anonymous Coward

      Yes, they do, I've been one such person.

      The problem often isn't the IT professionals, it's in some part the tossers at the top, constant shifting goals, some purely because some idiot who's had a sniff of power wants to make their mark.

      Government IT is a disjointed shambles, often in the same department, even something as simple as getting records from one system to another can have a floor of meatsacks manually transcribing printouts from the source to destination complete with the inevitable human errors.

  6. Dan 55 Silver badge
    Boffin

    Where are my consultancy fees?

    For UK citizens (subjects?) there are three main ways of identifying:

    1. Passport (UK Passport Authority)

    2. Driving licence (DVLA)

    3. DWP Account/Card - for everyone else who doesn't have 1) or 2)

    So, make each one of these government departments a CA and get them to issue a certificate alongside the physical proof of ID they already issue which expires the same time the physical document expires.

    Publish a small program/app for Windows/Mac/Linux/Android/iOS could download and install the certificate and store it in the certificate store automatically. The user would type some numbers sent to them in a letter to get it to work.

    Provide a method of cancelling the certificate and optionally generating a new one.

    It would appear to be as simple and as complicated as that? And hopefully reduced scope for mission creep because the certificate is tied to an already-existing physical document.

    1. Anonymous Coward
      Anonymous Coward

      Re: Where are my consultancy fees?

      @Dan_55

      What about people who want a FALSE identity?

      So that they can operate below the government radar.........

      You scheme sounds like a money machine for bad actors abusing the system.............

      ............on behalf of other bad actors!

      1. Dan 55 Silver badge

        Re: Where are my consultancy fees?

        You would only get a digital ID if you had managed to somehow get a false physical ID. So any bad actors are already acting badly with physical ID.

        So a digital ID is no worse in that regard than a physical ID and, if there are improvements made to the checks carried out when verifying people's identity when they apply, then the security of both physical and digital IDs would be improved.

        1. doublelayer Silver badge

          Re: Where are my consultancy fees?

          Or if I get some malware on a user's machine and copy theirs for later use or resale. I may not even have to work at that. I can go to botnet markets and tell them I only want UK victims.

          The more important question is why this helps in the first place. I'm convinced your design will never function technically, but if there's no point to it, then we don't have to fix it.

    2. R Soul Silver badge

      Re: Where are my consultancy fees?

      You've really not thought this through, have you?

      Let me count some of the ways.

      1) If DVLA, DWP, etc are already issuing docs - which aren't for identity but let that pass - what's their justification for issuing X.509 certs which would be for identity management/control? Why do it?

      2) These departments are notoriously useless at managing the databases they are already supposed to operate.

      3) DVLA, DWP, etc lack clue to define a problem statement and requirements for a CA. It's well out of scope for them. And far, far beyond their competence.

      4) Do you think it'll be a good idea to have Crapita or Fujshitsu run any CA? Really?

      5) Ask 3 again when that CA has national significance, oversees 10s of millions of certs and has to handle ~500K+ updates & renewals every day. And can't be allowed to go off-line. Ever. BTW the CABF says everyone has to move to X.509 certs with a 30 day expiry by 2028(?).

      6) DVLA and the Passport Office are already in a race to build rival national ID databases by stealth. It's beyond foolish to encourage them.

      7) Government-provided apps or certs will be an Epic Fail. Anyone remember the less than stunningly successful COVID test & trace app?

      There will be plenty more reasons. These are just the first ones that sprung to mind.

      1. Dan 55 Silver badge

        Re: Where are my consultancy fees?

        1) Passports and driving licences are the main ways of proving identity in the UK without fishing out utility bills. The certificate will allow the person to prove their identity to a government website and use online services without resorting to a username/password, SMS, or strings and yoghurt pots.

        2, 3) These three departments issue physical ID and are capable of verifying it. This is an extension to that by adding one certificate to someone's already-known identity.

        4) It doesn't have to be done by Crapita or Fujshitsu, it can be done by bringing it in-house.

        5) If it's a certificate for accessing government websites, then if necessary can have planned overnight maintenance as other government websites do.

        6) So don't let them build rival national databases by stealth. Let them build a digital ID following clearly defined rules and hold them to it. Tying one certificate to a physical document is understandable by the general public so they can be held to it.

        7) You're condemning the UK to being a technological backwater.

        Everything IT is beyond the government's competence so that earns complaints for them if they try. As they don't have competence in IT they outsource it to Capita and Fujitsu and then Capita and Fujitsu screw it up again so that also earns complaints for them when it happens. It's a vicious circle so either they start bringing projects in house (say defined by civil servant BAs/PMs and implemented by contractors) or nothing will change.

        1. IGotOut Silver badge

          Re: Where are my consultancy fees?

          1) Passports and driving licences are the main ways of proving identity in the UK

          My passport expired a decade ago, so that's out.

          I've a driving license, but millions of people don't drive, shocking I know.

          But as I know full well the absolute complete fuck up that is the Government ID / One login, there would be ZERO chance of this being anything other than a 100 Billion Pound cluster fuck.

          1. Jellied Eel Silver badge

            Re: Where are my consultancy fees?

            My passport expired a decade ago, so that's out.

            Why do you think that? It might not be valid for travel due to assorted visa requirements. But if it served to identify you, as an individual 10 years ago, then what's changed? But this is one of the general problems with identity, and the perception of identity. Passport should be sufficient to identify me, as an individual. Metadata linked to that passport might include other stuff. So if I'm visiting say, Patagonia, they can reasonably expect to be certain that I am me, and me is a British national. Patagonian authorities won't need to know my UK address because if they wanted to send me something, they could forward that request via the passport office, home office or whatever.

            But this was one of the problems with the Blair version of the ID Card. On it's own, not necessarily a bad idea and could even be useful. Snag was it wanted something like 70+ additional bits of data, with large fines if you got any of that wrong. So as an example every address you've lived at for the last 10yrs, with the exact dates you moved in and out. I'd moved a lot for college, then work, and had no idea of those dates over than approximate year & town because I'd never previously needed to keep that info.

            Issue me with a UID if you must, just don't expect me to pay for it. Given the obligations for data controllers to hold and process accurate PII, give me everything you think you know about me so I can check, and if necessarily correct it.. Especially when ID theft & abuse is widespread, and neither the person nor the data controller might be aware of the problem. But the data controller is however liable.

            But that's also one of the confidence tests in previous ID proposals. Liability has always been very one-sided with fines proposed for the data subjects. If data subjects were entitled to compensation for errors, fraud or misuse of their PII held in any government systems, then it might focus government's minds about making it both accurate, and secure.

          2. Dan 55 Silver badge

            Re: Where are my consultancy fees?

            Then the third option (DWP) would be for people who don't have a passport or driving licence?

            In any case I suspect my idea as proposed is too simple to turn into a billion pound cluster fuck so it'll never happen.

  7. Anonymous Coward
    Anonymous Coward

    Kier Can Think Three Impossible Things Before Breakfast.............

    Quote: "...Individuals can appear differently across different systems...."

    Well....maybe twenty years ago, my (huge) retail employer decided that

    the 25 customer databases in use needed to be consolidated into one

    customer database.

    When the dust settled, one senior person took a look to see if they were

    in the database EXACTLY ONCE. Hah! No.....there were three instances

    of that single person!

    "Why so?" I hear you ask. Well the person in question had been a customer

    for about fifteen years......and in that time had lived at multiple addresses and

    had used (and abandoned) multiple credit cards......so the software doing

    the "single customer" identification could not determine that these three

    customers were not actually three different people.

    Now just think about how many people are called "John Smith".....or think

    about a woman who has been married multiple times..................

    ..............and then tell me that the "Digital ID" idea was ever actually possible

    for a population of 60+ million individuals!

    1. Anonymous Coward
      Anonymous Coward

      Re: Kier Can Think Three Impossible Things Before Breakfast.............

      I have a name that's almost as common as 'John Smith', and I know that not only is there tens of other people with the same name in my town alone, there's also at least one person (in the UK) with the same name and DOB.

      And that's why I have several middle names.

  8. unbender

    The passport office seem to have become the base from which digital ID is emerging. The Gov.UK One Login looks an awful lot like digital ID but without a card and I'll bet that every department that requires users to confirm their identity will be using that service to deliver the confirmation.

    1. Anonymous Coward
      Anonymous Coward

      "The passport office seem to have become the base from which digital ID is emerging"

      It's one of them. They're in a race with DVLA. There are bound to be other branches of government jockeying for position to get control of this clusterfuck.

  9. Wargasm

    Sir Keir Dumpster

    It's hard to believe Sir Keir had no idea that public sector is a software dumpster but this country keeps surprising me:

    My first visit there was "oh my god, them locals has spell their surnames in the bank, yes , English surnames, all natives!" Now it's officially acknowledged that they have no idea how many immigrants they have really, including overstayed but it doesn't prevent successive home secretaries to promise reducing immigration to ten thousand. Oh, and ".doc" is still official document format here.

    1. IGotOut Silver badge

      Re: Sir Keir Dumpster

      I have no idea wtf you are jabbering on about. "English names"

      Well my both my first and surnames are French, but have been used in 'England" for about a milenia. Is someone called Hamish Macbeth a immigrant, as they don't have an "English name". What about Sanjay Patel? Must be one of those immigrants you talk about as that's not an English name.

      Oh and the last time I was in a bank was about 30 years ago.

  10. Tron Silver badge

    If we have learned anything from a couple of decades of the net...

    ...it is that all the really important stuff should be kept offline.

    Because everything online can be hacked and faked from anywhere on the planet.

  11. Fara82Light Bronze badge

    Design

    These sorts of issues are all in a day's work for engineers. Perhaps they should just be allowed to get on with it and provide a workable, cost-effective solution.

    1. just4this Bronze badge

      Re: Design

      Does an MCSE count?

      1. Fara82Light Bronze badge

        Re: Design

        No. They are not the sort of engineers I am referring to :)

    2. Fara82Light Bronze badge

      Re: Design

      The downvotes suggest that there are too many Windowsie people involved in these projects.

  12. Winkypop Silver badge
    Devil

    Phew!

    That was close!

    See you all next year.

  13. xyz Silver badge

    2 different things here...

    I live in Spain and we have our "ID" which is a plastic card like a driver's licence. In a sane society you can just use anything (passport, driver's licence etc) it doesn't matter. The Spanish are just anal about ID stuff.

    Then there is your "digital certificate" that when you want to access state or local gov stuff online you use that.

    To get a digital cert, you need an ID in Spain but there is nothing in reality to stop you giving a proof of who you are in a format other than an ID

    They are 2 different things. An ID is an old 1984 "papers" thing whereas accessing online services uses a different "tech".

    1. Anonymous Coward
      Anonymous Coward

      Re: 2 different things here...

      To get a digital cert, you need an ID in Spain but there is nothing in reality to stop you giving a proof of who you are in a format other than an ID

      The guide appears coherent:

      - Spanish ID card or passport.

      - EEA country ID card or passport plus Spanish residency card or Spanish residency certificate or the letter proving you have been granted Spanish residency.

      - Non-EEA country passport plus Spanish residency card or the letter proving you have been granted Spanish residency.

      So if you're Spanish then Spanish ID, if you're foreign then foreign ID plus Spanish residency. They're not asking for your driver's licence, your bus pass, or your library card.

  14. illuminatus

    Never been a fan of the one ring to bind them all form of digital ID, for a whole bunch of reasons, but at this point is it pertinent to ask about the DVLA issuing digital driver's licences? They have full control over the data, and given that both apple and google have facilities in the wallet, this would actually be a fairly easy thing to provide in the grander scheme of things, with some actual utility for a lot of users.

  15. Bob Royal

    It's not HAVING ID, it's NOT having ID

    Here's a conundrum - how do you get a bus pass ( coz you're a real oldie ) when you don't have a drivers license or passport ( coz you're a real oldie )?

    Can't get an ID on Self-assessment web shite either, and how many other things?

    There's much too much european style (Napoleonic) law.

    Landlords need to ID you, employers same, in trouble if they don't. They don't need that bollox!

    Shopkeepers and pub landlords responsible for underage customers. They don't need that bollox!

    People should be responsible for their own actions, those actions should not get others in bother.

    It all comes from european thinking: " Papers Please".

    Time to dump all legacy EU & EU style law.

    1. Dan 55 Silver badge

      Re: It's not HAVING ID, it's NOT having ID

      I think even in the US you'll find much same happens when selling alcohol of tobacco, and checking visa suitability for employment. Not guns though obviously.

    2. Goodwin Sands Bronze badge

      Re: It's not HAVING ID, it's NOT having ID

      @Bob Royal

      I have similar battles. Just bear it all in mind when you next vote.

      But whatever you do, never ever give any branch of government your photograph.

      1. IGotOut Silver badge

        Re: It's not HAVING ID, it's NOT having ID

        "But whatever you do, never ever give any branch of government your photograph."

        So in other words never legally drive or travel abroad.

        Explains a lot.

    3. IGotOut Silver badge

      Re: It's not HAVING ID, it's NOT having ID

      @bob royal

      Really, WTF are you on about?

      The UK has had driving licences since 1903. We've had passports since the middle ages. We had compulsory ID cards in WW2

      So maybe get out a bit more and stop believing all the shit you read on Facebook.

      1. Dan 55 Silver badge

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon