io9

  • io9
  • science
  • overmind
  • kotaku
  • gizmodo
Profile logout login
Neither Snow Nor Sleet Can Stop This Week's Comics - Or Can They?

Neither Snow Nor Sleet Can Stop This Week's Comics - Or Can They? #comicswecrave #xmen

Dark Knight's Nolan To Reboot Superman?

Dark Knight's Nolan To Reboot Superman? #superman #thedarkknight

The Complete History Of Pandora, According To Avatar's Designers

The Complete History Of Pandora, According To Avatar's Designers #exclusive #avatar

This Week, io9 Plunges Into The Throbbing Future Of Love

This Week, io9 Plunges Into The Throbbing Future Of Love #specialfeature #romance3000

Goodbye, Heroes, Goodbye

Goodbye, Heroes, Goodbye #heroesrecap #heroes

Couch is Benjamin Parzybok's Slacker Odyssey

Couch is Benjamin Parzybok's Slacker Odyssey #bookreview #couch

The End Of Heroes <em>And</em> Humanity In This Week's Television

The End Of Heroes And Humanity In This Week's Television #whattowatch #lost

io9

FAQ. Include # before tag:
#observationdeck, #tips, #calendar, etc.

San Francisco, 2:49 PM
Tue Feb 9
27 posts in the last 24 hours

IO9 TEAM

Tip your editors:

Editor-in-Chief:
Annalee Newitz |

News Editor:
Charlie Jane Anders |

Associate Editor:
Meredith Woerner |

Assistant Editor:
Lauren Davis |


Weekend Editor:
Graeme McMillan |

Contributors:
Joshua Glenn
Stephen Goldmeier |
Ed Grabianowski |
Austin Grossman
Paul Hogan |
Lauren Davis |
Chris Hsiang |
Lynn Peril |
Ann VanderMeer
Alasdair Wilkins |

Graphic Designer:
Stephanie Fox |

Interns:
Tim Barribeau |
Julia Carusillo |
Alex Eichler |
Cyriaque Lamar |
Caitlin Petrakovitz |
Mary Ratliff |
Josh Snyder |

More:
io9 on Facebook
follow io9 on Twitter

SUBSCRIBE TO IO9 RSS

New: Breaking news and daily top stories via email
1428 Subscribers


Please confirm your birth date:

Please enter a valid date
Please enter your full birth year
This content is restricted.

President Obama Welcomes the Cyber State

Today US President Obama announced plans for a "cyberspace strategy" that includes everything from possible offensive cyberwar strategies to education. It also contains a little-discussed "identity management" plan that makes me wonder if Facebook profiles are about to become the new Social Security cards.

The big news right now is who will be running Obama's broad new cyberspace programs - in particular, who will manage the cybersecurity and cyberwarfare aspects. Right now, it appears that there will be a "cyberczar" (as yet unchosen) who will report to the National Security Council and National Economic Council (the latter because part of this role will involve bank security). The Pentagon may also be setting up its own cybersecurity division.

These are the immediate issues, but when I read through Obama's Cyberspace Policy Review (released today with his announcements), I found an odd nugget of information buried at the bottom of his "near-term action plan":

Build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the Nation.

It sounds innocuous, but in fact it has profound implications that touch on security issues that have been giving the government (and industry) headaches for years.

Here is what a "cyber-security identity management vision" really is: A plan for how the government will establish and track your identity online. One of the biggest problems for law enforcement and business has been the way people can take on many identities online, which are very difficult to verify. This has allowed people to become prolific spammers (because you can send mail under any name you like), as well as fraudsters on sites like eBay. All of this is a result of the way web services "manage" identities - you can pick any name you like when you sign up for email or Paypal or whatever.

The government and its various federal agencies have been trying for years to figure out how to deal with this. Several years ago, I participated in a meeting at the Federal Trade Commission to discuss the possibility of creating an email system called "sender authentication" (to be implemented nationally) where you would have to verify your identity in a fairly rigorous way before being allowed to send email. No more fifty mailing addresses. The idea was to discourage spam and phishing, which is an understandable goal. But I and many others argued that this system would also crush free speech. No longer could you send an anonymous email, or participate in a mailing list under a pseudonym to protect your privacy.

I think Obama's "identity management vision" falls squarely into this history of debate over how to prevent crime by rolling back the proliferation of identities online. Yes, the "strategy" as described rather vaguely in Obama's "near-term action plan" involves a lot of hand-waving about privacy and civil liberties. But the fact is that if the government is coming up with an identity management plan, that means the government is trying in some sense to manage your identity or identities online - essentially to trace back your hottie77@gmail address to a real name, just in case hottie77 starts doing something illegal. Or allegedly illegal.

And here's where my not-so-wild speculation about Facebook identities comes in. Many companies have turned to Facebook as an "identity management" system (including Gawker Media), allowing people to log into their services using their Facebook identity. The reason is simple: Most people only have one Facebook identity, and they stick with it. There's a general notion that your Facebook identity is your authentic identity, or at least an identity that you keep over time, and that its characteristics can be traced back to who you are in real life. Therefore, having you log into every web service, from io9 comments to Digg to (possibly in the future) Paypal, is a way of managing your identities. Instead of having a separate identity for each of those services, you have one. Easy to manage, easy to trace.

Why shouldn't Obama's cyberczar just cut a deal with Facebook (and maybe a few other social networks like LinkedIn) and turn those profiles into your authentic identities? So you can send mail and buy things using your Facebook ID, and that's how you'll be tracked. Hey, you're already on Facebook right? And you can set your profile to "private." So it's easy and "privacy enhancing." (Never mind how easy it is to get around those privacy settings - pay no attention to that black hat behind the curtain.)

The scenario I'm describing is, in essence, how the Social Security Card became the twentieth century's identity management system starting in the 1930s. These cards were not originally intended as ID cards, or as a way to authenticate your true identity. They were just a way to manage government assistance to those who needed it. But they became an ID card simply because everyone in the US had been issued one. When the government and businesses needed a way to track people's identities, it became the easy choice. Showing your social security card meant that you couldn't just come up with random new names for yourself every time you signed a form or took a job.

Though people in the US now think of the Social Security Card as the "obvious" form of ID, it took years for it to evolve from a simple social assistance card to an "identity management vision."

You heard it here first: The next evolution of identity management in the US will grow out of Facebook. So watch what you are putting in your profile. You may be using it to open bank accounts in years to come.


Send an email to Annalee Newitz, the author of this post, at annalee@io9.com.


Upload an image | Add an image URL ×
×
×
Choose a file to upload:
×
Dsmvwl  Admin  Promote to frontpage Approve user Ban user ×
Loading comments ... -/|\
Earlier discussions Paging in progress... | Other discussions | Show all discussions | Show featured discussions only | Expand all threads Collapse all threads
Start a new discussion
By Annalee Newitz
May 29, 2009 10:15 AM 3,287 82
Edit » Set to Draft » Invite » Syndicate »

Syndicate this post


Site:
Mode:

sending request
cancel
more about #cybersecurity
read more: #futuristrant, #cybersecurity, #idcards, #facebook, #cyberczar, #gawker
 
  • Archives
  • About
  • Advertising
  • Legal
  • Help
  • Report a Bug
  • FAQ
Original material is licensed under a Creative Commons License permitting non-commercial sharing with attribution.

Login

Enter your username and password.

Please enter a username.
Please enter your password.
logging in
Login via Facebook | Sign Up | Forgot Password?

Reset Password

Please enter your email address to have your password reset.

Please enter your email address.
Please enter a valid email address.
requesting password reset

Register

Registering will give you a user profile and the ability to add other users as friends. To become a commenter, however, you need to audition.

Want to know more? Consult the Comment FAQ and legal terms.

Please enter a username.
Please enter a password.
Please confirm your password.
Passwords are not identical.
Please enter a valid email address.
registration sent, waiting for reply

Submit Your Comment

You don't need to login to comment. Just enter your email address below.

See how your address will be displayed in the Comment FAQ.

Please enter a valid email address.
Please enter a valid email address.
logging in

Login with your Facebook or io9 account.

Sign up here.



Send An Invitation

To invite commenters to this page, paste in a list of comma-separated email addresses, and then select send invites.

Please enter at least one email address.
Please use valid email addresses.
Please use unique email addresses.
Please enter fewer addresses.
requesting invites

Send a link

Send a link to this post 'President Obama Welcomes the Cyber State' via email:

Please enter your name.
Please enter your email address.
Please enter a valid email address.
Please enter your recipient's email address.
Please enter a valid email address.
Please enter your message.
Sending message