Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
United Kingdom

UK To Launch Digital Wallet For Passports, Driving Licences, and More (www.gov.uk) 40

Britain will launch a digital wallet app later this year allowing citizens to store government documents on their smartphones, UK Science Secretary Peter Kyle announced on Tuesday. The GOV.UK Wallet, available on Android and iOS, will first support veteran cards followed by driver's licenses in late 2025, with plans to eventually include passports, marriage certificates and benefit documents.

The app will use facial recognition for security. "The overflowing drawer rammed with letters from the government and hours spent on hold to get a basic appointment will soon be consigned to history," Kyle said. The Labour government aims to have all UK agencies offering digital alternatives to physical documents by 2027. Officials said users can recover their digital credentials if phones are lost, adding the system complies with existing data protection laws.

UK To Launch Digital Wallet For Passports, Driving Licences, and More

Comments Filter:
  • How many weeks until it's compromised?

  • Short Sighted (Score:4, Interesting)

    by nehumanuscrede ( 624750 ) on Tuesday January 21, 2025 @01:55PM (#65106683)

    Not a day goes by that we don't hear a story about some large hack that has stolen a bazillion credentials
    from some company who treats information security as an expense to be cut at the first opportunity to increase
    shareholder profits.

    Not one.

    Before the decision is made to make everything a digital entity, you might want to shore up the laws and
    heavily increase the penalties ( IE: Prison time ) to ensure the people who store this information take the
    security of it far more seriously than they do today.

    • Trust is a concept that requires impunity, unless you can use force, then you don't need trust.

      You are absolutely right that the only incentive that could force the organizations in charge of protecting our data to prioritize security is if failing to do so is almost guaranteed to cripple them with fines, and that these fines can't be evaded by bankruptcy or other legal loophole.

      But then, what would be the incentive for lawmakers and those who finance their campaigns to adequately enforce consequences for p

    • by mspring ( 126862 )
      How about penalties for stupid decision makers?
    • ... store this information take the security of it ...

      Your plan is, government demands these corporations paint a target on their backs, then spend all their money not getting shot. That works in the physical world, where one can buy a safe for a few thousand dollars that that can't be defeated quickly by professional locksmiths. Buy and forget doesn't work in the digital world, which is the real problem. Governments around the world have made the decision that tracking you is more important stopping identity-theft. Otherwise the laws you demand, would alr

  • Are they explaining how it will be calculated?
    • It's pretty simple to calculate, really.


      if not FrostPiss:
              SocialScore = -1
      else
              SocialScore = 5

  • by Ksevio ( 865461 ) on Tuesday January 21, 2025 @02:04PM (#65106713) Homepage

    Hopefully they'll add support for Google/Apple Wallet instead of just their special app. Would be much better to use open standards and access in a central location for everything

    • by Zocalo ( 252965 )
      What, and lose all that juicy citizen tracking data to Google and Apple? They're already going to need access to the camera for facial ID; you betcha this is going to have a long, and entirely superfluous to core functionality, list of other permission requirements as well. Of course, they'll need those because reasons - illegal immigration, terrorism, "think of the childen", or whatever else is pushing the public's buttons at the time.
      • Think of the stream of different facial ID pictures that the app will provide Gov. The purpose is to get a very comprehensive facial ID database with all the day to day variants that standard ID cards and passports don't gather.

        This will be optional to start with, then mandatory for anyone receiving a government payout such as welfare or pension.

    • by MeNeXT ( 200840 )

      No thank you. The laws need to be changed and users need to get total control of the property they own.

    • Hopefully they'll add support for Google/Apple Wallet instead of just their special app. Would be much better to use open standards and access in a central location for everything

      Because we all know it takes a multi-bazillion dollar company to make an open standard, not a government mandate. Jesus, what choices. Where's my fainting couch?

      • by Ksevio ( 865461 )

        The government made their own app instead of using the standard ones. Good thing about multi-bazillion dollar companies is they have teams of people making these secure and private (partially to avoid giving away information for free I'd guess). The same can't be said about the government

        • The government made their own app instead of using the standard ones. Good thing about multi-bazillion dollar companies is they have teams of people making these secure and private (partially to avoid giving away information for free I'd guess). The same can't be said about the government

          I just don't care for the word "open" being used to describe locked down corporate entities. It may be a standard by numbers, but I won't be one of those numbers because no amount of clout behind it makes me trust the digital wallet. I'm a tech person, which means I know better than to think security is easy.

          No, I don't trust the government to do it any better. I think the idea of digital wallets is a really, REALLY dumb path to go down to begin with, and government created ones are doubling the dumb. But h

    • Would be much better to use open standards

      I don't think you know what those words mean.

  • Soon you will have to use this app to pay for anything, or get paid, as cash will go away. At that point the government will control all aspects of life.

    Have fun my British friends.

  • If you hand over your phone to police or border agents, you are an idiot.

    • by vanyel ( 28049 )

      Exactly my thought...

    • You talk a big talk but I guarantee you presented at the border your phone is being given to the border agent. Outside of the safety blanket of the internet everyone becomes "yes sir, of course sir, I'm sorry sir."

  • Unless the plan is to just toss out existing issuance standards under the cover of a new-hotness flavor of ID I'm highly skeptical of the magnitude of the claimed improvements in wait time and inconvenience.

    Strong identifiers are relatively trivial(or, more accurately, they absolutely aren't; but reusing the work of a modest number of cryptographers and other specialists is easy and scales readily); but ensuring that you are issuing them to the right person is...less trivial; and normally where the hassl
  • Putting all those important documents in one place makes exfiltrating them SO much easier! Just like a password manager; make it easier for the real hackers to get the important stuff while appearing to be good security against casual intrusions. Fools make easier targets I guess. (Yes, password managers are great, until someone copies your manager's database. Then they can take their time and break in to get ALL of them, and you may not even know the copy occurred. I know people are gonna flame me for this
  • I'd never install a government app of any kind on my phone, regardless of declared permissions. Too much room for abuse and concealed access to my data.

    • As opposed to commercial apps that have an actual incentive to turn you and your data into a commodity?
    • uh, gee. Well, extending trust en masse to government entities may indeed be foolish, but, it appears that governments all over the world already have the access they need/want to all of your data via laws they have passed to ensure that the businesses (in this case, cell phone companies) are already required to hand it over, if asked, and in other cases, they simply hand it over without even being asked.
    • I'd never install a government app of any kind on my phone, regardless of declared permissions. Too much room for abuse and concealed access to my data.

      You will when you need proof of identity, only available via the government installed app on your phone, in order to work, to purchase things, to own or rent a place to live, and all that other nonsense a modern citizen needs to do to survive the day to day. Isn't modern life grand? Haven't we done marvelous things with our tech toys?

  • I've had a digital driver's licence for over a year now. Having a passport like this is only a matter of time (and foreign countries implementing the standard).
  • The UK introduced the ETA process this year similar to the USA ESTA, and the digital part is a shitshow.

    1. They suggest you use an app
    2. The website option to do it online instead suggests you use the app.
    3. When you click "the app doesn't work on my phone" it says to borrow a family member's phone.
    4. Finally click the option to apply online because you can't use the app and you end up back at step 1.

    When you're in the app there's no going back. Anytime you make any mistake you have to start the process fro

  • In my country digital IDs have been used for more than 5 years now. It's very convenient and nowadays I only carry my "paper" documents with me in travels, as a security measure in case my smartphone gets inaccessible.

    There's no information you give to the government to use it beyond what they already have. Also, you don't handle your smartphone to the police or anyone else. I was stopped by police in a traffic stop once, showed them the QR code on my screen and they scanned it with their device and checked

  • Two things:

    1. The smartphone screen displays an image, and today's apps display a static screen, meaning a previously taken screenshot or even a modified image file will work. I'm not familiar with the UK system but here in the US there is no "revocation system" like there is for certs, keys, signing authorities, etc. So if you image your driver's license and one day it's taken away (see point 2 below) that image is still good. For practical ITSEC purposes this is infinite-authentication without revocati

  • The key reason for UK government to push digital ID is to better track and prosecute online dissent. It will be mandatory to identify yourself when you connect. They are already arresting people for Facebook posts, but now that Trump is in the white house, Meta will no longer be as cooperative with outing people to various authoritarian governments.
    • Meta will no longer be as cooperative with outing people to various authoritarian governments.

      Meta demands people publish under their real name, hence their collaboration is not much needed for the police to track and arrest users based on their posts.

Every cloud has a silver lining; you should have sold it, and bought titanium.

Working...