The internet’s success as an application platform, communications medium and information distributor has hinged on its distinctive lack of barriers. Until recently, you could browse freely from site to site, reading, writing, researching, posting, and using a wide range of applications, in relative semi-anonymity and generally without the express authorization or control of any particular government (at least in countries with legal protections for free expression). But now we are seeing more and more legal requirements and commercial requests for users to verify their age or other aspects of their identity to access a range of websites, including in the United States and Europe. Vendors are rushing to develop systems to enable websites to verify their users’ credentials with minimal friction.
Perfect online anonymity has been nearly impossible to achieve for a long time, but we are now facing something even more intrusive: a web where online activity is linked to government-issued ID. Tech companies including Google, Apple and Samsung are pushing forward with internet-accessible digital wallets, and, absent further steps to address privacy, security, discrimination and free expression issues, we will find ourselves a step closer to the danger of a “papers, please” web. This is all the more dangerous in the context of sustained assault on civil liberties, the rule of law, and other democratic values in the United States and globally. Companies, policymakers, civil society, and other stakeholders should undertake collaborative work now so that digital identity can be done safely, securely, and accessibly.
A Dangerous Future: “Papers, Please” on the Web
While tracking cookies and email logins have become all too common, permanent legal ID is a much more powerful tool to facilitate total, persistent surveillance of online and offline activities. Once presenting government ID online becomes relatively effortless, it’s easy to imagine governments passing new requirements that people identify themselves to access certain websites, certain kinds of content on sensitive topics, or certain applications, like the ability to post on social media. (This is already the case in some parts of the world.)
Some websites might try to resist or work around those requirements, but others might not, especially as mandates become common or the commercial benefits of almost perfectly identifying visitors become significant. Under those conditions, we might find ourselves using a web where websites frequently demand ID prior to entry, or where we verify our age, gender, citizenship, or home address with a fingerprint or face scan each time we use an app or visit a website. The banners and dialog boxes we are increasingly badgered by today for collecting “consent” for cookies or email addresses for tracking could easily evolve into ID scan banners that will combine the annoyance of cookie banners with more severe and longer-lasting consequences.
Where previously ID verification was slow, cumbersome and therefore infrequent, new tools might make it easy enough that an ID check becomes a common part of account creation, or even requested for sign-in or usage. Barriers, driven by law and friendly technical access, could pop-up so that browsing the web requires different verifications when visiting websites from different countries.
And once websites are either incentivized or required to collect that information, government agencies will inevitably want access when investigating criminal activity, policing health care usage, gathering data on immigration status, or determining the authorship of disfavored speech. Given the widespread attacks on civil liberties and the retreat from respect for privacy or free expression, we should be prepared for these government abuses even here in the US.
ID verification checks may not be too cumbersome for many people, but widespread acceptance would exclude and increase the burden on others. Young people, immigrants, refugees, homeless people, people who use a shared or older device, and people who live in countries that don’t have the required technical infrastructure are all more likely to lack government ID or the ability to access digital ID. Moreover, government-issued digital ID can more easily be altered or revoked by government issuers as a form of punishment or control than physical IDs that remain in someone’s possession.
Online Papers Checks Arriving Now
Changes to technology, law, commerce and policy could combine to lead us towards this ID-verification online future. One significant piece is the technical ability to seamlessly present cryptographically verified digital IDs, stored in a phone’s wallet, to any website that asks for them. To different extents, and with different potential protections in place, Apple, Google and others are already promoting this technology.
Google is testing this functionality on Google Chrome, Google Wallet and digital wallets from other developers, including letting websites ask for credentials for any purpose after a warning message. Apple released this functionality at WWDC, on Safari and iOS, though they currently have some agreements and restrictions in place for websites to access IDs from Apple Wallet.
Unfettered demands for digital ID raise numerous threats to privacy and free expression, especially without the full range of protections (detailed below) that civil society has identified to limit potential abuses.
It’s true that there are even more invasive methods of ID verification that rely on video selfies and pictures of driver’s licenses, or custom URL schemes and QR codes deployed to trigger custom wallet apps. Those methods should also be limited, through both technical and legal means, though most are cumbersome enough that they’re unlikely to be widely deployed. But standardizing methods for easy access from a web browser is an opportunity to meaningfully improve upon privacy, security and free expression in digital ID online, not just to minimally raise a dismally low bar. That even worse options may exist does not excuse refusing to do the work to protect human rights online.
A More Considered Way Forward
Developers and policymakers should address the privacy, security, discrimination and free expression issues of ID verification systems prior to wide deployment. Civil society organizations have been willing, collaborative participants in conversations about protections for safe, secure, accessible use of digital ID online, when they have been invited to participate. Legal protections, technical designs and a slow roll-out focused on particular regulated use cases would enable the improvements that this technology promises, without slipping into a web of ID checkpoints.
But if industry instead rolls out deployments broadly without those protections actually in place, it undermines multistakeholder consensus, sets a dangerous expectation for how digital ID will be used online and directly harms human rights including privacy and free expression.
Companies considering deployment of online digital ID access should first direct their efforts into the collaborative work of mitigating the risks of digital identity so that it can be done safely, securely and accessibly.
Coalition Urges Senate Not to Let Companies Waive Financial Regulations for AI
CDT joined AI Now Institute, American Civil Liberties Union, and several organizations dedicated to tech policy, consumer protection, and civil rights in a letter to Senate leadership and the Senate Banking, Housing, and Urban Affairs Committee opposing the “AI Innovation Labs” language in Sec. 10509 of the CLARITY Act.
Potential Avenues for Redress for AI-related Harms under EU Equality and Non-Discrimination law: A Visual Explanation
In this third instalment of the series, we look at the opportunities afforded by EU equality and non-discrimination law in providing redress for AI-related harms.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.