0:00 As 10 minutes is a short period of time to get quite a bit done. I am… looks like
0:06 this mic is live since I'm going to leave this here. I'll make this quick here. So,
0:12 I've been in working for companies like Google, Microsoft, Amazon, and others for
0:17 the last 30 something years focusing on technologies like authentication. And so,
0:24 today what I'm going to talk to you about is what is digital identity. And this was
0:27 a little bit of bias in this, But I'm going to try to get through about 30 years
0:32 of lessons in what I have left here. So identity is not new. This is a picture of
0:41 a clay tablet from 1900 BCE. Merchants used to put their thumbprint into these
0:46 clay tablets so that you could authenticate that this is legitimate. This
0:51 is a point
0:55 that authentication is of transaction actions is something that we've been
1:00 worried with since the dawn of time and this is the earliest example I could find.
1:04 But we've been trying over and over to solve this problem and each generation of
1:09 has to approach this problem slightly differently for the environment that they
1:13 exist in. I've got a few examples that exist in this timeline below here. We
1:17 won't go through them today, but at the end of this presentation, I have a QR code
1:21 that talks a little bit about successes that you can follow for a paper on
1:24 successes and failures in this space as I'm going to go fairly fast here. So what
1:30 identity is not is as important as what identity is. It is not a better document.
1:35 Digital identity is materially different than the one-time issuance of a document
1:42 that we would use to authenticate at a government office or when traveling. It is
1:48 more of a living type of credential that lives for a long period of time. And that
1:52 living nature means that this is a governance problem. This is not a
1:57 technology problem. So why is this important? Because seven out of ten of the
2:04 projects that I've looked at over the last several decades and then you'll see those
2:08 in that white paper have failed and they failed because they looked at this as a
2:12 government not as a governance problem but as a technology problem as IT or
2:15 procurement. And so that's why it's important that we're all here today and
2:20 I'm really excited to be involved in this conversation. So this is a model shift.
2:25 State issues document you carry it it, verifier inspects it. That's what we're
2:30 all used to. But as we look at what does it mean to have civic digital identity,
2:36 it's much larger than just my name is Ryan Hurst. There's many endorsements about
2:40 Ryan Hurst that might be material to the verification. I'm a motorcycle driver.
2:45 That is certainly a driver's license thing, but I also am a parent. I also have
2:51 other attributes about me that are important and the state is involved in
2:55 many elements of those and being able to prove that to third parties is becoming
2:59 increasingly important and I'll talk a little bit about some of those cases. This
3:03 expanded role of identity in the online world is something that means that we have
3:10 to change the way we look at this problem and we have to start with a set of guiding
3:14 principles which is why again I think SEDI is an important project. So one of the
3:20 biggest differences that we'll see as we look at digital identity versus our paper
3:24 history historical analog is that they actually codify the policy that you all
3:31 come up with. And this is important because now when you make a change, that
3:36 digital document and the systems that verify it may also need to be changing. So
3:41 we have to think a little bit more holistically than that issuance moment. We
3:44 have to think about how are we going to manage this over its entire life cycle. If
3:48 we think of this as we bought a solution to print these digital identities and
3:53 declare victory, we will fail. That's the number one pattern we see when we look
3:57 back at the failed systems.
4:02 So what is maintained over time? Well, there's a lot of status changes. Licenses
4:07 get suspended, whether it be medical or driver's license or credentials may get
4:12 compromised and may need to be replaced. Algorithms may need to be changed over
4:17 time. These are probabilistically secure methods to prove these things and so we
4:21 may have to change them. For example, post -quantum cryptography is coming in the
4:25 future. And policies change continuously faster than ever before. And this all
4:31 means that how we govern these systems is going to become increasingly important. So
4:37 if we look at these failure patterns, there's many that we can point at. One of
4:43 the ones that I like to point at is the German solution. Germany came up with a
4:48 national ID card that was technically pure and perfect. From their definition of
4:55 technically pure, and perfect and it was an abysmal failure. Nobody adopted it
5:00 because the governance model was not right. They put the burden on the
5:04 constituents. They made it very complicated to adopt. They didn't have a
5:11 core utility. So it was massive amounts of money spent with no return on investment.
5:17 So not something that we can afford. UK is another great example. I can't go into the
5:22 details today, but they wasted $233 million in a decade of time roughly
5:26 because they didn't look at this problem holistically and they didn't measure it in
5:30 the right way. Some of the successes we can point at Estonia. They started with a
5:36 list of three or four utility scenarios that they were going to enable and as a
5:39 result, their system continues to exist. We can look at Sweden. They looked at what
5:45 was practical to deploy and achieve results with and their existing exists and
5:50 is loved. Very rarely do you find a government service that is loved, but I
5:54 think that it's fair to say that that particular program is. U.S. government has
5:59 its own as well and there's others that have elements of success but we'll go into
6:04 those later in that paper I mentioned. So why is this important? I'm from the state
6:10 of Washington. We have the honor of I believe being the largest COVID fraud for
6:14 distribution of COVID funds. I think Africa got more than we did. So this is a
6:22 big problem and it's a problem because we didn't invest ahead of time. We didn't
6:26 build the infrastructure to enable the government to be able to identify its
6:29 citizens online and we can't let this pattern repeat again. So why does this
6:37 matter now? I mentioned COVID, but it's much larger than COVID. We can look at AI,
6:41 for example. Today, I can generate a fake utility bill, birth certificate, and
6:46 whatever easily with just a few types of on my keyboard that you're going to
6:50 believe is legitimate. I can do real-time deepfakes that are nearly impossible to
6:55 distinguish. The voice will be the same. You cannot rely on a video call to
7:00 authenticate who you're talking to anymore. And so this means that we have to
7:03 invest in infrastructure to be able to strongly authenticate who we're dealing
7:07 with so that we're able to prevent mistakes like that one from happening
7:12 again. I also think it's important to note that in the context of security breaches,
7:16 88% of security breaches tracked by two companies, roughly that figure, I think
7:21 they have two slightly different numbers but very similar, were just using stolen
7:26 credentials. They didn't hack anything. They logged in. And so it's important that
7:31 we pick strong technologies that solve for the problems and don't have externalities
7:36 that make things worse. This is you are the foundation of how the federal
7:41 government interacts with Americans. You are the foundation of how the rest of the
7:45 world interacts with Americans online. And we have to solve this problem. This is not
7:49 something that we can ignore. So why does this matter for you? you don't manage
7:58 digital identity in abstract. There's a lot of different examples of this that
8:01 exist inside of your organizations. You may not think of them as digital identity.
8:05 Different people have different definitions of this term, but I view all
8:08 of these things as part of the life cycle of identity. A birth certificate is my
8:13 child's ID until they're old enough to get a driver's license. Many of these other
8:19 elements, my wife carries our marriage license because she's from another
8:23 country. When we travel because it's part of her digital identity. All of these
8:26 things are part of that package that we have to use, that the state produces, that
8:30 the rest of the world relies on to verify who we are. So before you commit to any
8:35 approach, I think it's important to understand what digital identity tells you
8:42 or what questions to ask. I didn't word that particularly well. So since this is a
8:48 codified thing, the question becomes when policy changes, how does the digital
8:52 identity get affected? it. Because it's policy-based, how are you actually going
8:58 to create demand for this thing? If you have no utility function for your
9:01 deployment, some scenarios that are enabled that are actually meaningful to
9:05 your constituents, they're not going to go through the hassle of doing it no matter
9:08 how beautiful the solution you build is. Because it's how are you going to maintain
9:13 the entire life cycle of this system? This is like any IT investment in that respect.
9:18 And because it's civic identity, you have to pay attention to who's excluded. My
9:22 parents are not particularly good at using things online anymore. And so we don't
9:26 want to exclude an entire segment of our society and there's of course other
9:29 examples as well. So what does success look like? You've identified anchor
9:34 tenants, you've budgeted some amount for continual governance, you've addressed how
9:40 are you going to deal with interoperability with existing systems,
9:43 you understand how your platform is related to the various dependencies that
9:48 you have, and you understand the equity implications for this system and how are
9:54 you going to manage them? And you've defined success metrics and how you're
9:57 going to continually revise those metrics so that you can make sure that your system
10:01 is delivering on the promises that you should have set out to do. So that is my
10:06 presentations. Ladies and gentlemen, I appreciate your time today.!