The Times Australia
The Times World News

.
The Times Real Estate

.

A national digital ID scheme is being proposed. An expert weighs the pros and (many more) cons

  • Written by Erica Mealy, Lecturer in Computer Science, University of the Sunshine Coast
A national digital ID scheme is being proposed. An expert weighs the pros and (many more) cons

In 2018-19, identity crime directly and indirectly cost Australia an estimated[1] A$3.1 billion.

To address such costs, the federal government is proposing a national digital identity scheme that will let people prove their identity[2] without having to share documents such as their passport, drivers licence or Medicare card.

Finance Minister Katy Gallagher opened consultations[3] for the draft bill[4] last week, with plans to introduce the legislation to parliament by the end of the year.

Let’s look at what it proposes, and what it could mean for you.

What would change?

The digital ID scheme would initially be regulated by the Australian Competition and Consumer Commission and the Australian Information Commissioner, with a view to eventually establish a new governing body.

The draft bill package includes strong updates to security requirements for how organisations store people’s IDs, as well as the reporting of data breaches and suspected identity fraud.

In her speech to[5] the Australian Information Industry Association, Gallagher outlined a four-phase rollout.

  • Phase one: establishing the legislation and accreditation of private and public providers.
  • Phase two: adding state- and territory-issued IDs to the scheme for use with federal government services.
  • Phase three: bringing recognition of the digital ID into the private sector. This would, for instance, allow you to use your digital ID to apply for a bank loan without having to provide your identity documents or copies.
  • Phase four: allowing accredited private sector digital IDs to help verify you when accessing certain government services.

How would it work?

For the general public, the voluntary scheme would come in the form of a smartphone app[6], requiring biometric information (such as a face print) to be unlocked.

To prove your identity to a participating organisation, you would log into the organisation’s website and select MyGovID[7] as your verification method.

You would then log into your MyGovID app and give consent for your identity to be verified with that organisation. In this way, you could verify your identity to the organisation without needing to share your drivers licence, passport or similar.

Gone will be the days of 100 points of ID and copies of documents stored all over the internet.

The upside of the proposal

The Medibank, Optus[8] and Latitude[9] data breaches of 2022-23 have demonstrated the lack of regulation and enforcement of identity protection legislation in Australia.

A welcome part of the draft bill is the increased power given to the Australian Information Commissioner, as well as restrictions on how organisations request, store and disclose people’s personal identifying information[10].

The bill also outlines minimum cybersecurity standards, and requires regular review of organisations dealing with identity data.

Unresolved MyGovID security flaws

In releasing the draft bill, the government has highlighted a voluntary national digital identity – the MyGovID – which is already being used by[11] more than 6 million Australians and 1.3 million businesses.

MyGovID is a government-issued authenticator app which verifies your identity using one of three factors: something you know (such as a password), something you are (such as a biometric scan), or something you have (such as a verified phone number, where you can receive one-time codes). Adding additional factors makes verification more secure.

In 2020, security researchers warned the public against using MyGovID[12] due to security flaws in its design. It’s unclear if these have been addressed. The Australian Tax Office declined to fix[13] the issue when raised.

Governments in Australia also have a poor track record[14] of securing our information.

According to Webber Insurance[15], 14 of the 44 recorded data breaches between January to June this year were reported by government authorities. These included the Department of Home Affairs, and the Northern Territory, Tasmania, ACT and NSW governments.

This is on top of data breaches involving[16] the Australian Tax Office, National Disability Insurance Scheme and MyGov, as reported by the ABC last year.

More worryingly, the privacy act[17] has a loophole which allows state and government authorities to remain exempt from compulsory data breach reporting. As such, we don’t know just how many government data breaches have occurred.

The draft bill explicitly maintains these loopholes, stating[18] entities are exempt from data reporting if “the entity is a department or authority of a State or Territory”.

Read more: The government wants to expand the 'digital identity' system that lets Australians access services. There are many potential pitfalls[19]

A honey trap for hackers

Even if the government carries out its end of the bargain securely, the proposed scheme would still only be as secure as your phone. Having a weak password, losing your phone, or having your phone hacked could lead to data being compromised.

Also, streamlining distributed identification systems in this way will create an irresistible target for hackers. In cybersecurity this is called a honeypot[20], or honey trap.

Just as honey is irresistible to bears, these data lures are irresistible to hackers. Failure to secure the data would make it a one-stop-shop for identity theft and extortion.

Perhaps most concerning is how closely the proposed scheme resembles government surveillance. By linking all our personal identification data across federal and state jurisdictions, as well as private entities, we would be giving the federal government complete oversight of our lives.

Small changes to the law, such as those quietly made in[21] the Surveillance Legislation Amendment (Identify and Distrupt) Act in 2021, could mean our locations could be tracked, and all our interactions with public and private organisations recorded.

What can you do?

It’s clear the draft bill has a number of issues. That said, all hope is not lost.

The government has committed to genuine consultation on its proposal. However, you don’t have much time to have your say[22]: public submissions are being sought until October 10.

This extremely short consultation period doesn’t provide much confidence a fit-for-purpose solution will be created.

While protecting our digital identities is a welcome and well-overdue part of this proposed bill, getting it wrong could lead to harm at an even larger scale.

Read more: Australia's National Digital ID is here, but the government's not talking about it[23]

References

  1. ^ an estimated (www.aic.gov.au)
  2. ^ prove their identity (www.digitalidentity.gov.au)
  3. ^ opened consultations (ministers.pmc.gov.au)
  4. ^ draft bill (www.digitalidentity.gov.au)
  5. ^ speech to (ministers.pmc.gov.au)
  6. ^ smartphone app (www.9news.com.au)
  7. ^ MyGovID (www.digitalidentity.gov.au)
  8. ^ Medibank, Optus (www.afr.com)
  9. ^ Latitude (www.latitudefinancial.com.au)
  10. ^ personal identifying information (www.oaic.gov.au)
  11. ^ being used by (ministers.dese.gov.au)
  12. ^ against using MyGovID (www.itnews.com.au)
  13. ^ declined to fix (www.zdnet.com)
  14. ^ poor track record (www.governmentnews.com.au)
  15. ^ Webber Insurance (www.webberinsurance.com.au)
  16. ^ data breaches involving (www.abc.net.au)
  17. ^ privacy act (www.oaic.gov.au)
  18. ^ stating (www.digitalidentity.gov.au)
  19. ^ The government wants to expand the 'digital identity' system that lets Australians access services. There are many potential pitfalls (theconversation.com)
  20. ^ honeypot (au.norton.com)
  21. ^ quietly made in (www.sbs.com.au)
  22. ^ have your say (www.digitalidentity.gov.au)
  23. ^ Australia's National Digital ID is here, but the government's not talking about it (theconversation.com)

Read more https://theconversation.com/a-national-digital-id-scheme-is-being-proposed-an-expert-weighs-the-pros-and-many-more-cons-214144

The Times Features

How to buy a coffee machine

For coffee lovers, having a home coffee machine can transform your daily routine, allowing you to enjoy café-quality drinks without leaving your kitchen. But with so many optio...

In the Digital Age, Online Promotion Isn't Just an Option for Small Businesses – It's a Necessity

The shift to an online-first consumer landscape means small businesses must embrace digital promotion to not only survive but thrive in 2025. From expanding reach to fostering cu...

Sorbet Balls by bubbleme Bring Bite-Sized Cool Spin to Frozen Snacking

A cool new frozen treat is rolling into the ice-cream aisle at Woolworths stores nationwide. Dairy-free, gluten-free and free from artificial colours, bubbleme Sorbet Balls ar...

Mind-Body Balance: The Holistic Approach of Personal Training in Moonee Ponds

Key Highlights Discover the benefits of a holistic approach to personal training in Moonee Ponds and nearby Maribyrnong, including residents from Strathmore. Learn how mind-b...

How Online Platforms Empower You to Find Affordable Removalists and Electricity Plans

When you move into a new home, you have many tasks to do. You need to hire removalists and set up your electricity.  In this article, we discuss how online platforms empower you ...

IS ROSEMARY OIL THE SECRET TO BETTER HAIR DAYS? HERE’S WHAT IT CAN DO

Rosemary hair oil is a straightforward natural solution that delivers exceptional results for anyone who wants to enhance their haircare process. It maintains its status in herba...

Times Magazine

CNC Machining Meets Stage Design - Black Swan State Theatre Company & Tommotek

When artistry meets precision engineering, incredible things happen. That’s exactly what unfolded when Tommotek worked alongside the Black Swan State Theatre Company on several of their innovative stage productions. With tight deadlines and intrica...

Uniden Baby Video Monitor Review

Uniden has released another award-winning product as part of their ‘Baby Watch’ series. The BW4501 Baby Monitor is an easy to use camera for keeping eyes and ears on your little one. The camera is easy to set up and can be mounted to the wall or a...

Top Benefits of Hiring Commercial Electricians for Your Business

When it comes to business success, there are no two ways about it: qualified professionals are critical. While many specialists are needed, commercial electricians are among the most important to have on hand. They are directly involved in upholdin...

The Essential Guide to Transforming Office Spaces for Maximum Efficiency

Why Office Fitouts MatterA well-designed office can make all the difference in productivity, employee satisfaction, and client impressions. Businesses of all sizes are investing in updated office spaces to create environments that foster collaborat...

The A/B Testing Revolution: How AI Optimized Landing Pages Without Human Input

A/B testing was always integral to the web-based marketing world. Was there a button that converted better? Marketing could pit one against the other and see which option worked better. This was always through human observation, and over time, as d...

Using Countdown Timers in Email: Do They Really Increase Conversions?

In a world that's always on, where marketers are attempting to entice a subscriber and get them to convert on the same screen with one email, the power of urgency is sometimes the essential element needed. One of the most popular ways to create urg...

LayBy Shopping