No need to say it, it goes without saying, it should be obvious to all but,
just in case it isn't obvious to all,
IDA is dead.
IDA, now known as "GOV.UK Verify (RIP)",
is the Cabinet Office Identity Assurance programme.
14 June 2012, we discovered that the Government Digital Service (GDS) had joined the Open Identity Exchange (OIX) in order to help with their moribund identity assurance programme now known as "GOV.UK Verify (RIP)".
23 December 2016, OIX published The value of digital identity to the financial service sector, which explores "the reuse of a GOV.UK Verify [RIP] digital identity in a financial service application process".
Does that report help GDS?
Executive Summary (pp.2-4)
In the Executive summary of their report, OIX tell us that GOV.UK Verify (RIP) "currently has 1 million users, with an ambition to scale to 25 million users by 2020" (p.2).
They're wrong.
Note 1 below demonstrates that there were fewer than 800,000 so-called "verified" accounts in late December 2016, not 1,000,000, and argues that these could represent fewer than 112,000 people.
Note 2 reveals that GDS's ambition is unrealistic in that, at the present rate, it could take until October 2074 to enrol 25 million people. Or March 2425.
And Note 3 questions the quality of GOV.UK Verify (RIP) accounts – are they any use to the financial service sector? To be told as we are seven times during the report that GOV.UK Verify (RIP) is endorsed by the government doesn't answer that question.
OIX say the financial service sector needs "an understandable, convenient, safe and trusted solution to manage and protect our identities online". They may or may not be right about that. The sector may need several such schemes, not just one.
But is GDS's GOV.UK Verify (RIP) a candidate? Given their inability to get the numbers right, confidence in OIX's ability to answer that question is undermined before the reader has even turned to p.3 of their 27-page report.
Participants (p.27)
OIX list eight participants in the production of their report
The list includes Verizon. Note 4 below suggests that Verizon is an odd choice by OIX to use to inspire confidence in GOV.UK Verify (RIP) – Verizon have been dropped from the register of approved "identity providers".
The Post Office are included. Their entry says: "The Post Office is proud to be one [of] the first certified providers of the GOV.UK Verify [RIP] scheme" (p.27).
That sounds straightforward.
Note 5 below demonstrates that it is anything but.
The Post Office isn't certified and it doesn't do any identity assurance work. Without telling the users, that work is actually done for it by another "identity provider", probably Digidentity. And what's more, Digidentity's service is governed by Dutch law, not English.
According to GDS, the other two uncertified GOV.UK Verify (RIP) "identity providers" – the Royal Mail and SecureIdentity – also quietly rely on third parties.
A straightforward proposition might be attractive to the financial service sector. A cloudy proposition, where the Post Office is really Digidentity and the Royal Mail is really GB Group, might not be.
Barclays are included in OIX's list of participants: "We're proud to be the only bank to be selected by UK government as a certified company to provide a safe, secure identity verification service" (p.27).
Unlike the Post Office Barclays are certified but, cloudy again, like the Post Office they don't provide their "safe, secure identity verification service" themselves. The Barclays privacy policy states that: "We may share your personal information with ... Verizon, our technical services partner, so they can perform certain parts of the Identity Service on our behalf".
The participant they don't include in the list is OIX themselves. You might expect OIX to be acting as a professional consultancy which maintains its objectivity by being independent. You might be wrong.
The OIX report is written by Bryn Robinson-Morgan. And according to his LinkedIn entry Mr Robinson-Morgan:
- worked for the Royal Mail for 7½ years
- then he worked for the Post Office for 8½ years including over two years on their identity assurance service
- then he put in 17 months on the Barclays identity assurance service
- followed by six months producing the OIX report with Innovate Identity, who are one of the five participants we haven't mentioned so far: "Our team have vertical industry expertise in financial services, payments, technology, telecoms, government, online retail, online gambling as well as breadth of geographical knowledge across multiple global jurisdictions ..." (p.27).
Financial Sector Analysis (pp.17-20)
OIX conduct a SWOT analysis – strengths and weaknesses, opportunities and threats – to assess the advisability of the financial service sector adopting GOV.UK Verify (RIP).
Under Weaknesses (pp.18-19) OIX note GOV.UK Verify (RIP)'s lack of scale, the failure of GDS to educate people with a digital identity public information campaign, the threats to people's privacy and the absence of any attribute exchange. As OIX say: "A central, commercial, driving force for the adoption of a standards driven digital identity scheme currently does not exist".
Under Threats (p.19) OIX worry that it is not certain that GOV.UK Verify (RIP) will succeed and that the scheme faces competition from Google, Apple, Facebook and Amazon.
The Strengths listed by OIX (p.18) are actually weaknesses:
- OIX assume that GOV.UK Verify (RIP) provides "a strong identity that has been verified to the highest standards in comparison to existing methods generally deployed" but that's exactly what it doesn't do. (OIX ought to know that.)
- "With consent and control of the personal data being with the customer", OIX say, "a sense of ownership is established". GOV.UK Verify (RIP) sprays its accountholders' personal information all over the world, out of anyone's control. Like the poor quality low level of assurance identities it peddles, lack of control/loss of ownership is another weakness of GOV.UK Verify (RIP)'s and not a strength.
- "Opportunities exist for financial service providers to reduce their costs by reusing an established digital identity". Really? By how much? No answer. When? No answer. OIX provide a SWOT analysis with no figures. And no logic. Just assertion and hope.
- "Customers who currently abandon the application process can be capitalised upon by removing barriers of privacy ...". How many customers want to be capitalised upon by losing their privacy? No answer.
- "The development of a unified, trusted brand, can be a catalyst to a reduction in fraudulent applications and opportunistic identity theft". Perhaps it can be. How big would the reduction be? No answer. Equally, a single unified service could make it easier to commit fraud and so increase its incidence rather than reduce it. This particular opportunity could just as well be included under Threats.
OIX's hypothesis (p.17) is that: "Financial service institutions would accept an assured digital identity from a third party provider as part of their product application process if an established trust framework met their regulatory and service requirements". They may be right. But they haven't proved that GOV.UK Verify (RIP) is "an established trust framework". It isn't. It's not established. And it's not trusted.
Conclusions (p.25)
"A widely-adopted, fit-for-purpose, trusted, standards-based digital identity scheme could have significant value for the financial services industry ... it could simplify the initial digital engagement with a provider and subsequent transactions ... it could deliver a consistent approach to user identification and management and reduce the cost of onboarding and transactional business processes. It could facilitate the delivery of new services ... it could provide the basis for delivering new user centric industry models ..." (p.25).
Yes. It could. It could do all sorts of things. The financial service sector probably know that and don't need a 27-page report from OIX to tell them.
They might be interested to know whether GOV.UK Verify (RIP) will be notified under eIDAS (Article 9). OIX don't say.
GOV.UK Verify (RIP) has until 25 May 2018 to comply with GDPR. Are GDS going to make it? The financial service sector might be interested to know but OIX don't say.
They might be interested to know how secure GOV.UK Verify (RIP) is but OIX are silent on the matter. (Not entirely silent, please see Note 6 below.)
They might be interested to know what they're supposed to do with GOV.UK Verify (RIP) which can't verify the identity of companies. Payments can't be authorised by companies via GOV.UK Verify (RIP) because GOV.UK Verify (RIP) doesn't know what a company is, the concept doesn't exist. OIX don't mention that Weakness/Risk. (Or is it a Strength/Opportunity?)
HMRC and Companies House use the Government Gateway for transactions with natural persons, companies, partnerships and trusts. It works and has done for 16 years+. Why are OIX reporting on GOV.UK Verify (RIP) and not the Government Gateway?
It can't be for the financial service sector. Who is this report for?
Note 1
GDS tell us that there were 966,767 accounts on 25 December 2016 of which 185,149 were "... ‘basic accounts’ created as part of a trial between May and July 2015. Basic accounts were not verified by certified companies, but allowed access to government services that required a lower level of certainty about identity". These self-certified "basic accounts" don't count, they are unverified Verify accounts, they should be deducted from the total.
That leaves GOV.UK Verify (RIP) with just 781,618 verified accounts in late December 2016. The OIX claim of 1,000,000 overstates the case by 28%. That's a poor start for the report ...
... and it gets worse. DMossEsq, for example, has created seven GOV.UK Verify (RIP) accounts for himself. He remains nevertheless just one person. GDS say there are 781,618 GOV.UK Verify (RIP) accounts. If everyone has done the same as DMossEsq and created seven accounts for themselves, then there are just 111,660 people involved and not OIX's 1,000,000, which overstates the case by 796%.
GDS's GOV.UK Verify (RIP) statistics go back over two years to October 2014. It could be that as few as 111,660 people have a GOV.UK Verify (RIP) account. By contrast, HMRC signed up 6.7 million users of their new personal tax account service in under 12 months.
Note 2
The ambition of GOV.UK Verify (RIP) is to "scale to 25 million users by 2020".
Since going live on 24 May 2016, GDS have been adding accounts at the rate of 1,172 per day. If 25 million users need 25 million accounts, that could take 21,331 days, which brings us to 18 October 2074, 54 years after GDS's ambitious target date of 2020.
Many of us will be dead by then and many new people will need to be registered. More so if everyone needs seven accounts, in which case we're looking at 18 March 2425, four centuries away.
Note 3
Doubts about the credibility of the OIX report set in before you have even turned to p.3. It's not just the number of GOV.UK Verify (RIP) accounts. It's the quality.
GDS admit that the 185,149 "basic accounts" are associated with a "lower level of certainty about identity". The other 781,618 aren't over-burdened with certainty either:
- "... the original plan for Verify was for it 'to provide low to medium security ID assurance for citizens, and this hasn’t changed' ...", according to Civil Service World magazine (see also "wildly unrealistic expectations").
- The US National Institute of Standards and Technology go further. GOV.UK Verify (RIP) doesn't even make it to a medium level of assurance according to them – the 781,618 so-called "verified" accounts are no better than self-certification (see also Table 2-1).
"GOV.UK Verify is a federated identity scheme that uses an approved panel of certified private sector companies to confirm the identity of individuals". That's what OIX tell us on p.6.
Note 6
Updated 1.3.17
Updated 8.4.17
Updated 11.4.17
Note 6
Updated 1.3.17
Updated 8.4.17
Updated 11.4.17
