16.9 - World Identity Day
Today is September 16th, which is recognized as identity day (www.id-day.org). The number comes from SDG 16.9 "Legal Identity For All".This is an important goal. Without a legal identity, who are you?According to the world bank, there are about 800 million people without an official identity. This makes it problematic to get a job, a bank account, or even a mobile phone.
Even in Norway, we have problems
I live in Norway. One of the most digitalized countries in the world, and you would think that we do not have such problems. I use eID (Buypass and BankID) between 10 and 20 times per week. It is very convenient, and I am immediately recognized at the bank, the insurance company, the government, the investor and many, many more.This is fantastic.You would think that a country like Norway has solved this.According to Digdir (the Norwegian Digitization Directorate) around 189 000 adults in Norway have not used eID the last year. Which means they are practically cut off from all services. These are typically foreigners, elderly, people with disabilities and people living on the street.You have a legal right to a bank account. But no such legal right exists for eID, which is a catch-22, because you will need an eID to get a bank account.This is a problem which becomes visible when the eID adoption reaches the level, where the service providers consider this as the main way of identification, and then the non-digitals are left behind, as alternative ways of identification are shut down for cost reasons.
Fraud
Another concern is: who is using your eID right now. While there are biometric checks when onboarding, there is no such check when using the eID. It is assumed that if you have access to the phone associated with the eID, it must be you. But there is no proof of this. The biometric features of the phone are convenience features, not security features. They do NOT prove WHO is using the device at a given time.Almost 1 in 4 have used somebody else's BankID (Norsis 2025 - https://norsis.no/publikasjoner/). The main argument is that "they need help", so maybe we are not good enough at making secure AND user friendly solutions? Are we making them too complex, and thereby pushing users to work-arounds?Sharing your BankID with others opens the door for fraud. Legally, it is the owner of the eID who is bound by any agreements. But what if it is not the owner using it, setting up a credit card or taking out a loan?
The EU Digital Identity Wallet
Let's work for a better future, where everyone has both a legal identity, and access to digital services in a simple way.The EUDIW (EU Digital Identity Wallet) is coming, and the goal is to simplify digital services, also across borders. But unless we ensure that the owner of the wallet is using it, and making it user friendly, we are leaving the door open for even more fraud. With all the potential uses of the EUDIW, this will be an attractive target for fraudsters.
User Centric
As with any security solution, the user is the weakest link. And the more complex the solution, the weaker it becomes.I see a lot of technical discussions around the EUDIW, but not so much about the user focus and making it easy to use and understand.If you have any examples of this, please let me know.