back
93 comments
We had these electronic identity cards in Finland for quite a while, but I think they've been considered a failure:

It was initially planned as a general network authentication device for both public and private sector strong authentication needs. In 2009, however, the card was viewed by a government committee as a failure. There has been less than 300000 cards around by 2011 out of population of 5.3 million. The rationale to apply for a card has mostly been traveling abroad. Only few dozen government services have adopted it, and only one bank adopted it as login card to their netbank. All banks in Finland use a national standard called TUPAS, which uses one-time passwords. Banks also provide TUPAS authentication to other Internet-enabled businesses. Since TUPAS requires no dedicated hardware, cost of a card reader and card itself have been main causes in the failure of the eID card.

http://en.wikipedia.org/wiki/Finnish_identity_card

The problem is simply that smart card readers never got integrated into computers, and people didn't want to buy a USB dongle for that just to be able to authenticate with some government websites.

Instead, what happened was that the two-factor authentication system provided by banks became the dominant "secure authentication" method. By now it is supported by most sites that need such a thing, like banks, insurance companies, postal services, and several government sites.

I can for example authenticate with my bank user credentials to file my taxes (or could, when I was still living in Finland).

An additional benefit of the ID card is that you can use it for travel inside the European Economic Area. But I'll rather carry my passport with me, as that way I don't have to wonder whether the ID card is enough for my itinerary or not.

edit: ID cards are valid travel documents inside EEA (which is a larger area than Schengen)

In Belgium the electronic card took off ~10 years ago but it is seldom used outside of official state matters (on the top of my head: when you move in/out, when you get married, etc. Basically used for anything that the state has to formally identify you). Administration are well-equipped with readers and you can file your taxes with it if you have a reader (everyone that I know and own a reader bought one for that sole purpose).

We have two-auth for banking as well.

edit: oh and some public transport use it to fill in addresses field faster when creating bus or train card.

Basically it's a glorified unique address memento. It's not considered a failure though.

edit2: Most importantly: id cards are mandatory in Belgium and most entities have switched to electronic card.

Administration are well-equipped with readers

I think I've seen the same in police stations in Finland... some kiosk PCs with a card reader and access to the various forms you might want to file there. Can be used to skip the line when applying for a driver's license, gun permit, or something like that.

IMO, the couple of times you might do that in a decade are not quite worth buying and carrying the electronic ID.

The picture on the site is Estonian ID card. Being an Estonian I'm pretty sure that unlike our neighbours Finns our card is actually used a lot. The main driver is the ability to do your stuff from home, without going to some office during business hours. Given the size of Finland I'd expect it to be very useful in northern parts of the country.
Being able to interact with the government via web was indeed the main reason why electronic IDs were initially created. But because they require additional hardware we've ended up using OTP auth provided by banks (TUPAS) instead.
> Since TUPAS requires no dedicated hardware ...

Can you explain this bit? My bank here in the UK has an OTP mechanism for internet access, but it uses a small key generator card provided to each customer, controlled by a PIN on each use.

Does the TUPAS card itself generate the key?

Think of TUPAS like OAuth/FB Connect as envisioned by banks. Typically TUPAS uses a printed card of single-use passwords.

Here in Germany you instead get an SMS with a single-use password every time you have to authenticate (for example, to pay a bill).

As an alternative German banks also provide smart card reading OTP generators that interface with your bank card:

https://www.sparkassen-shop.de/sfp/shop/tan-generatoren,375/

In Finland universities also have the need for federated authentication, as students can take courses in different schools. Instead of TUPAS they standardized on Shibboleth and SAML.

As I understand it, TUPAS is more of a protocol for providing authentication. Every authentication provider is allowed to implement the authentication at their end however they please. I think some have keyfobs, but afaik majority rely on printed list of OTP codes[1]. If you are familiar how 3-D Secure (eg Verified by Visa, MC SecureCode) works, the process is somewhat similar. So there is no "TUPAS card".

[1] example pic: http://imgur.com/Bi5LB06

"A proposition for a standard digital signature in every EU citizen's identity card. .... No extra cards - it will just replace your existing ID card when it expires"

Well unlike most of the continent, Britain and Ireland have no mandatory I.D. card (thankfully) so this doesn't cover the whole EU...

I allways wondered about the aversion to id-cards. Doubly when I heard the story about catch-22 style schenigans I heard you need to go through in GB, if you want to open a bank account, and rent a flat at the same time (or so I heard, that most of the time bank accepts as proof of identity utility bills from place where you live, and landlord accepts similarily a proof of existence of a bank account) ... in czech republic I just show them my id card, and everyybody is hapy. I could even pay a little bit extra to have digital signature embedded, which would allow me to fill my taxes via web ...
Why the "thankfully"? I'm in a country where the ID card is mandatory and don't see any problem with it. Can you enlighten me?
A lot of things end up being tied to your ID number, and it becomes very difficult to limit the collaboration of companies to create a dataset about you, never mind making it easier for the Government to track people en masse.
I don't see the need to have mandatory ID. The thought of being fined for not "showing my papers" while walking down the street is disturbing.

Can't speak for the UK, but I think a lot of the resistance to the idea in Ireland is due to a long history of distrust of the authorities.

Case in point: HMRC (UK Taxman) is about to sell 'anonymized' taxpayer data. With enough 'anonymized' data-dumps and CPU power, at some point, it will become trivial to correlate an ID Card ID with datapoints.
Same issue as with SSN in the USA. Lots of things requesting it what should not ever have access to it, opening people up to everything from privacy intrusion to identity fraud.
You need to be wearing a tinfoil hat to understand.
U'll join in with the chorus and point out that this point of view is an outdated relic of the national identity card debates of the 80s and 90s. Back then it was possible to imagine a world where we weren't tracked permanently. With the advent of ubiquitous mobile phones, the Web (with cookies!), public transport electronic passes, license plate readers for cars, face recognition linked with CCTV networks, that era has gone. In my opinion, if we can't have privacy, then we should at least get some of the potential benefits that are possible when privacy is removed, and national ID cards give you just that.
Finland doesn't have a mandatory ID card either, but you've been able to get an electronic ID like the one described for quite a while if you want one.

https://news.ycombinator.com/item?id=7626555

So the govt really doesn't have records about every citizen? (or you just don't have a physical Card against that record?)
It has tax records, which have a link to my NHS records. My tax number isn't used for anything aside from taxes, though, and only organisations which have to report tax-related information about me to the Government have it.
I thought UK wasn't part of EU in the first place.... (Hence it DOES cover all of EU, no?)
They are (for now). They are just not part of the Euro or Schengen.
It's... complicated. See The European Union Explained* for how deep that rabbit hole is: https://www.youtube.com/watch?v=O37yJBFRrfg
It's part of the EU, but not part of the common currency (Euro).
Ahem, Ireland is also a member of the EU!
What a joke. So you have no DL, no passport, you don't have any bank accounts or credit cards, no internet account or phone account, no national health insurance account, and no address?

Thats great! Since you're not required to have an ID card then you can't be identified and your privacy is secure.

Also you're homeless, probably destitute and unable to live or participate in society.

Portugal already has these. Our ID card is a smartcard, and contains a personal X.509 certificate, issued by a national certificate authority (and a bunch more stuff, like my address or photo). You can use a card reader and standard software to sign legally valid documents. You can login into government websites with it.

I'd wager about 80% of ID cards already use the new model.

It looks like this:http://4.bp.blogspot.com/_4kQttk9aLQI/TT7-nale3lI/AAAAAAAAAC...

Its site is: http://www.cartaodecidadao.pt

Unfortunately, there are too few countries. Portugal, Spain, Estonia, Finland, Belgium, India and a few more. Everyone solves the problem in their own way, sometimes incompatible with the others, and not taking into account all privacy concerns. Hence my suggestion for a standard, interoperable solution
The FAQ is really helpful:

"Will it hurt our privacy?

No"

Oh, OK then.

You can't hurt what's already dead.
It's a QAA (quickly answered answer).
The description of this card's features are a little too basic to my taste. Based on the "anonymous credentials" they mention it seems to imply that they're using attribute-based cryptography* to preserve privacy, which would be awesome. Can anybody shed some extra light on this?

* = See https://www.irmacard.org/. It allows your card to reliably answer questions like "Am I allowed to enter this country?" and "Am I old enough to buy liquor?" without you having to communicate all your personal data (like full name, exact age, exact country of origin) to the party who needs to check it. In fact, that party would not even be able to gain more information. It just communicates parts of your identity on a need-to-know basis.

In germany we have the EPA or nPA or how this is called. Thank god we can opt out the functionality of these features.

Good luck proving you didn't electrically sign that contract. Forget decrypting pay-TV this is the new shit.

I thought it was easier to replicate handwritten signatures than digital ones, no?
Note: This is just a page created by a random guy on the internet, with no connection to any official EU entity or authority.
Its the first step to the EU mandatory-sex-offender-registry-for-everyone that most continental Europeans call the "resident register" or "population register". For all you uninformed, that's where you must register with the police whenever you stay someplace. (Which is why I'm so derisive.) And they are starting to use national ID cards for this purpose now.

So in that respect this makes perfect sense. An electronic EU ID makes (for example) mandatory registration with the police so much easier.

https://en.wikipedia.org/wiki/Resident_registration

https://en.wikipedia.org/wiki/Resident_registration_in_Russi...

https://en.wikipedia.org/wiki/Propiska_in_the_Soviet_Union

https://en.wikipedia.org/wiki/Hukou_system

(Note the latter systems are your ID.)

It's still a card. Why not go for a full software solution as the one used by banks and government agencies in Sweden?[1]

[1](http://www.bankid.com/en/what-is-bankid/)

I can't wait to be added to yet another database ...

I wonder what countries are left where you can mind your own business without being tagged like some vulgar cattle.

Do you have any more information? At the moment it looks like a design project showcase with a few links to wikipedia.
> At the moment it looks like a design project showcase with a few links to wikipedia.

Because that is exactly what this is. This is just an unofficial proposal by some random guy: "Page created by Bozhidar Bozhanov".

I fully support something like this, but it should be optional.
> It will preserve privacy - no one can trace when and how citizens use their identity cards.

Haha. I like such statements, and I'm waiting for the first massive leak years down the road.

Read about "anonymous credentials"
Some EU countries don't have an ID card, e.g. the UK.

Edit: Just saw it's some eurocrat's proposal, thankfully not an actual new imposed law. Not that it really matters once the referendum comes up as the UK will likely be out of the EU after that.

What is the problem with the idea of an ID card? There are situations where you need to prove your identity, and a government-supplied card can be useful in those cases.

The alternative is using a driver's license or a passport, both of which are also cards (or booklets), and government-supplied.

It is not like you'd be forced to get one, or carry it around. Finland has had ID cards as long as I can remember, and I never had to get one.

I had my passport stolen once, and identifying myself to the government to be able to get a new one was a bit of a pain in the ass, since I didn't have any other valid national ID (driver's license isn't considered one). The alternative way of authenticating involved maybe fifteen minutes of questions like What was your street address in 1987?

Lol, talk about making it easy for UKIP.

I swear sometimes it's like they actually want us to leave.

"Not that it really matters once the referendum comes up as the UK will likely be out of the EU after that."

That's actually highly unlikely. Much as the Brits value their independence, the economic cost would be too high.