Ryan Hurst

Morning Session · 10:10

0:00 As 10 minutes is a short period of time to get quite a bit done. I am… looks like

0:06 this mic is live since I'm going to leave this here. I'll make this quick here. So,

0:12 I've been in working for companies like Google, Microsoft, Amazon, and others for

0:17 the last 30 something years focusing on technologies like authentication. And so,

0:24 today what I'm going to talk to you about is what is digital identity. And this was

0:27 a little bit of bias in this, But I'm going to try to get through about 30 years

0:32 of lessons in what I have left here. So identity is not new. This is a picture of

0:41 a clay tablet from 1900 BCE. Merchants used to put their thumbprint into these

0:46 clay tablets so that you could authenticate that this is legitimate. This

0:51 is a point

0:55 that authentication is of transaction actions is something that we've been

1:00 worried with since the dawn of time and this is the earliest example I could find.

1:04 But we've been trying over and over to solve this problem and each generation of

1:09 has to approach this problem slightly differently for the environment that they

1:13 exist in. I've got a few examples that exist in this timeline below here. We

1:17 won't go through them today, but at the end of this presentation, I have a QR code

1:21 that talks a little bit about successes that you can follow for a paper on

1:24 successes and failures in this space as I'm going to go fairly fast here. So what

1:30 identity is not is as important as what identity is. It is not a better document.

1:35 Digital identity is materially different than the one-time issuance of a document

1:42 that we would use to authenticate at a government office or when traveling. It is

1:48 more of a living type of credential that lives for a long period of time. And that

1:52 living nature means that this is a governance problem. This is not a

1:57 technology problem. So why is this important? Because seven out of ten of the

2:04 projects that I've looked at over the last several decades and then you'll see those

2:08 in that white paper have failed and they failed because they looked at this as a

2:12 government not as a governance problem but as a technology problem as IT or

2:15 procurement. And so that's why it's important that we're all here today and

2:20 I'm really excited to be involved in this conversation. So this is a model shift.

2:25 State issues document you carry it it, verifier inspects it. That's what we're

2:30 all used to. But as we look at what does it mean to have civic digital identity,

2:36 it's much larger than just my name is Ryan Hurst. There's many endorsements about

2:40 Ryan Hurst that might be material to the verification. I'm a motorcycle driver.

2:45 That is certainly a driver's license thing, but I also am a parent. I also have

2:51 other attributes about me that are important and the state is involved in

2:55 many elements of those and being able to prove that to third parties is becoming

2:59 increasingly important and I'll talk a little bit about some of those cases. This

3:03 expanded role of identity in the online world is something that means that we have

3:10 to change the way we look at this problem and we have to start with a set of guiding

3:14 principles which is why again I think SEDI is an important project. So one of the

3:20 biggest differences that we'll see as we look at digital identity versus our paper

3:24 history historical analog is that they actually codify the policy that you all

3:31 come up with. And this is important because now when you make a change, that

3:36 digital document and the systems that verify it may also need to be changing. So

3:41 we have to think a little bit more holistically than that issuance moment. We

3:44 have to think about how are we going to manage this over its entire life cycle. If

3:48 we think of this as we bought a solution to print these digital identities and

3:53 declare victory, we will fail. That's the number one pattern we see when we look

3:57 back at the failed systems.

4:02 So what is maintained over time? Well, there's a lot of status changes. Licenses

4:07 get suspended, whether it be medical or driver's license or credentials may get

4:12 compromised and may need to be replaced. Algorithms may need to be changed over

4:17 time. These are probabilistically secure methods to prove these things and so we

4:21 may have to change them. For example, post -quantum cryptography is coming in the

4:25 future. And policies change continuously faster than ever before. And this all

4:31 means that how we govern these systems is going to become increasingly important. So

4:37 if we look at these failure patterns, there's many that we can point at. One of

4:43 the ones that I like to point at is the German solution. Germany came up with a

4:48 national ID card that was technically pure and perfect. From their definition of

4:55 technically pure, and perfect and it was an abysmal failure. Nobody adopted it

5:00 because the governance model was not right. They put the burden on the

5:04 constituents. They made it very complicated to adopt. They didn't have a

5:11 core utility. So it was massive amounts of money spent with no return on investment.

5:17 So not something that we can afford. UK is another great example. I can't go into the

5:22 details today, but they wasted $233 million in a decade of time roughly

5:26 because they didn't look at this problem holistically and they didn't measure it in

5:30 the right way. Some of the successes we can point at Estonia. They started with a

5:36 list of three or four utility scenarios that they were going to enable and as a

5:39 result, their system continues to exist. We can look at Sweden. They looked at what

5:45 was practical to deploy and achieve results with and their existing exists and

5:50 is loved. Very rarely do you find a government service that is loved, but I

5:54 think that it's fair to say that that particular program is. U.S. government has

5:59 its own as well and there's others that have elements of success but we'll go into

6:04 those later in that paper I mentioned. So why is this important? I'm from the state

6:10 of Washington. We have the honor of I believe being the largest COVID fraud for

6:14 distribution of COVID funds. I think Africa got more than we did. So this is a

6:22 big problem and it's a problem because we didn't invest ahead of time. We didn't

6:26 build the infrastructure to enable the government to be able to identify its

6:29 citizens online and we can't let this pattern repeat again. So why does this

6:37 matter now? I mentioned COVID, but it's much larger than COVID. We can look at AI,

6:41 for example. Today, I can generate a fake utility bill, birth certificate, and

6:46 whatever easily with just a few types of on my keyboard that you're going to

6:50 believe is legitimate. I can do real-time deepfakes that are nearly impossible to

6:55 distinguish. The voice will be the same. You cannot rely on a video call to

7:00 authenticate who you're talking to anymore. And so this means that we have to

7:03 invest in infrastructure to be able to strongly authenticate who we're dealing

7:07 with so that we're able to prevent mistakes like that one from happening

7:12 again. I also think it's important to note that in the context of security breaches,

7:16 88% of security breaches tracked by two companies, roughly that figure, I think

7:21 they have two slightly different numbers but very similar, were just using stolen

7:26 credentials. They didn't hack anything. They logged in. And so it's important that

7:31 we pick strong technologies that solve for the problems and don't have externalities

7:36 that make things worse. This is you are the foundation of how the federal

7:41 government interacts with Americans. You are the foundation of how the rest of the

7:45 world interacts with Americans online. And we have to solve this problem. This is not

7:49 something that we can ignore. So why does this matter for you? you don't manage

7:58 digital identity in abstract. There's a lot of different examples of this that

8:01 exist inside of your organizations. You may not think of them as digital identity.

8:05 Different people have different definitions of this term, but I view all

8:08 of these things as part of the life cycle of identity. A birth certificate is my

8:13 child's ID until they're old enough to get a driver's license. Many of these other

8:19 elements, my wife carries our marriage license because she's from another

8:23 country. When we travel because it's part of her digital identity. All of these

8:26 things are part of that package that we have to use, that the state produces, that

8:30 the rest of the world relies on to verify who we are. So before you commit to any

8:35 approach, I think it's important to understand what digital identity tells you

8:42 or what questions to ask. I didn't word that particularly well. So since this is a

8:48 codified thing, the question becomes when policy changes, how does the digital

8:52 identity get affected? it. Because it's policy-based, how are you actually going

8:58 to create demand for this thing? If you have no utility function for your

9:01 deployment, some scenarios that are enabled that are actually meaningful to

9:05 your constituents, they're not going to go through the hassle of doing it no matter

9:08 how beautiful the solution you build is. Because it's how are you going to maintain

9:13 the entire life cycle of this system? This is like any IT investment in that respect.

9:18 And because it's civic identity, you have to pay attention to who's excluded. My

9:22 parents are not particularly good at using things online anymore. And so we don't

9:26 want to exclude an entire segment of our society and there's of course other

9:29 examples as well. So what does success look like? You've identified anchor

9:34 tenants, you've budgeted some amount for continual governance, you've addressed how

9:40 are you going to deal with interoperability with existing systems,

9:43 you understand how your platform is related to the various dependencies that

9:48 you have, and you understand the equity implications for this system and how are

9:54 you going to manage them? And you've defined success metrics and how you're

9:57 going to continually revise those metrics so that you can make sure that your system

10:01 is delivering on the promises that you should have set out to do. So that is my

10:06 presentations. Ladies and gentlemen, I appreciate your time today.!