« Who "owns" your identity and your personal data? | Main | Iranian democracy expires with a Tweet »
TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/56293
This page contains a single entry from the blog posted on June 29, 2009 5:17 PM.
The previous post in this blog was Who "owns" your identity and your personal data? .
The next post in this blog is Iranian democracy expires with a Tweet .
Many more can be found on the main index page or by looking through the archives.
Comments (3)
Philip: It's late and I havent read it carefully. But the whole statement is built on the assumption that goverment should be our identity provider for online services.
But I think there's a strong case to be made that it should not. It concentrates too much power.
Our personal data is our own, and it's valuable. We dont want it to become concentrated in government, out of our control.
We want a competitive market in user-friendly and flexible online identity provision services. This policy is about coercion, not choice. It says its about empowerment, but it's not.
Far better to say:
"People need to access stuff online, including government services. Therefore we're announcing that from today we'll accept a range of independent identifiers for all our various services. But if you want a sensitive service it'll need to be a secure one.
"As new ID services become available we'll be happy to add them to the list of accredited services."
Posted by William | June 29, 2009 10:52 PM
Posted on June 29, 2009 22:52
William - Two points:
(1) We don't want the data to be concentrated anywhere - events have shown that the only sure defence against massive data leaks is not to have massive data.
(2) Who does the accreditation and against what standards?
Posted by Andrew Hardie | June 30, 2009 10:33 AM
Posted on June 30, 2009 10:33
> (1) We don't want the data to be concentrated anywhere - events have shown that the only sure defence against massive data leaks is not to have massive data.
Quite agree. Personal data is best left to the greatest possible extent to those who care most about it and know it best: the data subject
> (2) Who does the accreditation and against what standards?
I guess it's best done by whoever picks up the liability if it goes wrong. The standards will have to evolve and emerge. But today I think we'd say a Google, Yahoo ID is convenient but doesnt provide any security. An Amazon or PayPal one is still quite convenient and provides some level of assurance (but not of uniqueness). A bank logon (esp with card reader) is getting quite good...
Posted by Anonymous | July 12, 2009 10:25 PM
Posted on July 12, 2009 22:25