The Times Australia
The Times World News

.
Times Media

.

Australia’s new digital ID scheme falls short of global privacy standards. Here’s how it can be fixed

  • Written by Ashish Nanda, Research Fellow, Deakin Cyber Research and Innovation Centre, Deakin University

Australia’s new digital ID system[1] promises to transform the way we live. All of our key documents, such as driver’s licences and Medicare cards, will be in a single digital wallet, making it easier for us to access a range of services.

The federal government is still developing the system, with a pilot expected to run[2] next year. Known as the “Trust Exchange”, it is part of the Trusted Digital Identity Framework[3], which is designed to securely verify people’s identities using digital tokens.

Earlier this year, in a speech[4] to the National Press Club in Canberra, Federal Minister for Government Services Bill Shorten, called the new digital ID system “world leading”. However, it has several privacy issues[5], especially when compared to international standards like those in the European Union.

So how can it be fixed?

What is Trust Exchange?

Trust Exchange – or TEx – is designed to simplify how we prove who we are online. It will work alongside the myID (formerly myGovID[6]) platform, where Australians can store and manage their digital ID documents.

The platform is intended to be both secure and convenient. Users would be able to access services ranging from banking to applying for government services without juggling paperwork.

Think of the system as a way to prove your identity and share personal information such as your age, visa status or licence number — without handing over any physical documents or revealing too much personal information.

For example, instead of showing your full driver’s licence to enter a licensed premises, you can use a digital token that confirms, “Yes, this person is over 18”.

But what will happen to all that sensitive data behind the scenes?

Falling short of global standards

The World Wide Web Consortium[7] sets global standards around digital identity management. These standards ensure people only share the minimum required information and retain control over their digital identities without relying on centralised bodies.

The European Union’s digital identity system[8] regulation builds on these standards. It creates a secure, privacy-centric digital identity framework across its member states. It is decentralised, giving users full control over their credentials.

In its proposed form, however, Australia’s digital ID system falls short of these global standards in several key ways.

First, it is a centralised system. Everything will be monitored, managed and stored by a single government agency. This will make it more vulnerable to breaches and diminishes users’ control over their digital identities.

Second, the system does not align with the World Wide Web Consortium’s verifiable credentials standards. These standards are meant to give users full control to selectively disclose personal attributes, such as proof of age, revealing only the minimum personal information needed to access a service.

As a result, the system increases the likelihood of over-disclosure of personal information.

Third, global standards emphasise preventing what’s known as “linkability”[9]. This means users’ interactions with different services remain distinct, and their data isn’t aggregated across multiple platforms.

But the token-based system behind Australia’s digital ID system creates the risk that different service providers could track users across services and potentially profile their behaviours. By comparison, the EU’s system has explicit safeguards to prevent this kind of tracking – unless explicitly authorised by the user.

Finally, Australia’s framework lacks the stringent rules found in the EU which require explicit consent for collecting and processing biometric data, including facial recognition and fingerprint data.

Filling the gaps

It is crucial the federal government addresses these issues to ensure its digital ID system is successful. Our award-winning research[10] offers a path forward.

The digital ID system should simplify the verification process by automating the selection of an optimal, varied set of credentials for each verification.

This will reduce the risk of user profiling, by preventing a single credential from being overly associated with a particular service. It will also reduce the risk of a person being “singled out” if they are using an obscure credential, such as an overseas drivers licence.

Importantly, it will make the system easier to use[11].

The system should also be decentralised, similar to the EU’s, giving users control over their digital identities. This reduces the risk of centralised data breaches. It also ensures users are not reliant on a single government agency to manage their credentials.

Australia’s digital ID system is a step in the right direction, offering greater convenience and security for everyday transactions. However, the government must address the gaps in its current framework to ensure this system also balances Australians’ privacy and security.

References

  1. ^ new digital ID system (theconversation.com)
  2. ^ expected to run (ministers.dss.gov.au)
  3. ^ Trusted Digital Identity Framework (www.digitalidsystem.gov.au)
  4. ^ in a speech (ministers.dss.gov.au)
  5. ^ privacy issues (ia.acs.org.au)
  6. ^ myGovID (www.mygovid.gov.au)
  7. ^ World Wide Web Consortium (www.w3.org)
  8. ^ European Union’s digital identity system (digital-strategy.ec.europa.eu)
  9. ^ preventing what’s known as “linkability” (www.iso.org)
  10. ^ Our award-winning research (dl.acm.org)
  11. ^ make the system easier to use (www.sciencedirect.com)

Read more https://theconversation.com/australias-new-digital-id-scheme-falls-short-of-global-privacy-standards-heres-how-it-can-be-fixed-241797

The Times Features

The Gift That Keeps Growing: Why Tinybeans+ Gift Cards are a game-changer for new parents

As new parents navigate the joys and challenges of raising a child in the digital age, one question looms large: how do you preserve and share your baby's milestones without co...

Group Adventures Made Easy: How to Coordinate Shuttle Services from DCA to IAD

Traveling as a large group can be both exciting and challenging, especially when navigating busy airports like DCA (Ronald Reagan Washington National Airport) and IAD (Washington...

From Anxiety to Assurance: Proven Strategies to Support Your Child's Emotional Health

Navigating the intricate landscape of childhood emotions can be a daunting task for any parent, especially when faced with common fears and anxieties. However, transforming anxie...

The Rise of Meal Replacement Shakes in Australia: Why The Lady Shake Is Leading the Pack

Source Meal replacement shakes are having a moment in Australia, and it’s not hard to see why. They’re quick, convenient, and packed with nutrition, making them the perfect solu...

HCF’s Healthy Hearts Roadshow Wraps Up 2024 with a Final Regional Sprint

Next week marks the final leg of the HCF Healthy Hearts Roadshow for 2024, bringing free heart health checks to some of NSW’s most vibrant regional communities. As Australia’s ...

The Budget-Friendly Traveler: How Off-Airport Car Hire Can Save You Money

When planning a trip, transportation is one of the most crucial considerations. For many, the go-to option is renting a car at the airport for convenience. But what if we told ...

Times Magazine

Australia Post - Christmas International sending dates fast approaching

Australia Post has today announced the need-to-know dates for more than 180 international destinations to help Australians sending Christmas cards and presents to loved ones overseas. For Economy Air, many destinations require cards and gifts to b...

3 Solar Panel Warranty Categories You Should Know

A solar power system is a multi-decade investment. If its components degrade quickly over time, you’re likely to drive less long-term value from it. That’s why there’s a need to check whether each component comes with a rock-solid warranty. All so...

Segway ZT3 Pro All-Terrain Electric Scooter

Segway-Ninebot, the global leader in the micromobility transportation solutions and robotic service industries is announcing its brand-new ZT series of electric scooters with the ZT3 Pro in Australia. The Segway ZT3 Pro combines cutting-edge smar...

The Reasons Why You Should Never Leave Your Car At An Outdoor Car Park

Surveys show that Australia is the most expensive country in the world to park in! The average daily parking charges were in the region of AUD 35 in 2022, and they showed no signs of coming down. Parking in the CBDs (central business districts) c...

Sustainable gift ideas to help you be a conscious consumer this Christmas

With all that has happened over the past twelve months, it’s understandable that many are excited for the holiday season. However, during such times, it’s easy to lose track and either overspend or over-purchase. While the festive season is, ...

The Endless Supply of Fun with Buckets and Spades

Buckets and spades are classic beach toys that have been around for generations. They bring joy to children of all ages, providing hours of entertainment at the beach or in the backyard sandpit. Buckets and spades can be used to create imaginative ...