Do You Trust the White House with Your Online Identity?

slfisher 1 Tallied Votes 612 Views Share

Some industry experts are expressing concern about a proposal from the White House to develop a "National Strategy for Trusted Identities in Cyberspace," now up for public comment, saying it is vague, might no longer allow online anonymity, potentially gives government too much access to personal information, and provides a single point of failure for identity thieves.

The plan postulates security tokens such as a "smart identity card," possibly from state government, or a digital certificate from a smart phone, that would contain all sorts of identity information about a person, rather than people having to remember a long string of user names and passwords for different websites. The person would need to possess the token to have access to their online information, which the plan says would make identity theft more difficult.

However, while the plan talks a lot about different security layers, and different providers, it doesn't talk much about who would actually be doing the providing. Indeed, Appendix B -- "Participants" -- is blank.

And in an era when people supposedly posting anonymously are finding out that their postings aren't anonymous after all, some people are concerned that the proposal will eliminate anonymous posting altogether. While the potential smart identity card would allow for anonymous posting, the very aspect of using an identity card makes it inherently un-anonymous, say critics.

"[A]nonymous to what extent?" wrote Lauren Weinstein on his . "Perhaps a blog comment would appear on the Web anonymously, but when the lawyers show up demanding to know who posted that critical comment -- something that's happening with increasing frequency even now -- I'll bet you dollars to donuts that the initial authentication records will be available through some means to unmask the poster, or to correlate pseudo-identities that users may prefer to use for different purposes and "roles" on the Net."

In addition, some people are concerned about giving the government access to all of a person's identity and security information. In 1993, the White House proposed an encryption chip, the "Clipper," that turned out to have a back door that would enable law enforcement to decrypt information on the chip.

Finally, critics point out that should identity thieves find a way to steal or duplicate the security tokens, they could get access to all of a person's information, not just that from a single compromised account -- the same sort of criticism that has been levied against the so-called REAL ID driver's license.

Comments on the plan will be collected through July 19.

Dani AI

Generated

As ’s post shows, the 2010 draft kicked off a real debate. The final National Strategy for Trusted Identities in Cyberspace (NSTIC) was published in April 2011 and explicitly framed the idea as a voluntary, private‑sector‑led “Identity Ecosystem,” not a mandatory national ID. Its stated goals were privacy‑enhancing, voluntary, secure, interoperable, and easy to use — a framework intended to encourage multiple providers rather than a single government credential. (nist.gov)

The criticisms you’ll see in the thread are legitimate: consolidated credentials can create attractive single points of failure and raise lawful‑access and surveillance worries. Civil‑liberties groups pressed for clearer privacy safeguards, and NIST/NSTIC implementation work responded with Fair Information Practice guidance, pilot grants, and a privately‑led steering group to develop governance and technical baselines. Those steps reduced some risks but did not — and cannot — eliminate tradeoffs. (archive.epic.org)

Practical takeaway for anyone worried about anonymity or identity theft (echoing and ): assume public linkability for forum posts, compartmentalize online roles (separate emails/accounts for forums vs. banking), and stop relying on passwords alone. Adopt phishing‑resistant methods (passkeys / FIDO2 / WebAuthn) and enable strong multi‑factor authentication everywhere; WebAuthn creates per‑site cryptographic keys that are not reusable across sites, which mitigates the “one stolen token = full compromise” risk. Decentralized identity (DIDs/Verifiable Credentials) is another privacy‑first approach, but it’s still evolving — evaluate implementations and audits before trusting them. (w3.org)

Bottom line: NSTIC moved the conversation away from a single government ID toward a multi‑actor ecosystem and real pilot work, and governments have since deployed shared solutions (Connect.gov experiments led to today’s login.gov program). The safest course for individuals remains defensive: limit exposure, use unique accounts, enable MFA or passkeys, and prefer services that publish clear privacy controls and independent audits. (origin-www.gsa.gov)

joeleitz 0 Newbie Poster

It's probably best just to assume that anything you post online is not anonymous. Don't put private info on your computer if you can help it.

hallshac 0 Newbie Poster

Well I don't link the government in my business but you can already get anonymous and secured connections with out the government! CHeck out identity theft protection product at SNIP. you can also get anonymous browsing but with out the secure part at SNIP or other proxy services out there.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.