One of the books I read last week was my co-blogger Jim Harper’s new book, Identity Crisis: How Identification Is Overused and Misunderstood. It’s excellent and if you have any interest in privacy policy you should read it.
Harper’s book does three things. In parts 1 and 2 he presents a theory of identification that classifies identification into four categories (something you are, something you are assigned, something you know, and something you have) and then identifies the relationships among identification, risk, and accountability. He particularly makes the point that the need for identification is intimately connected with the type of transaction being considered: the ID you need to check out a library book is much different than the ID you need to get a mortgage or access to a nuclear reactor. He also stresses the diversity of identification: we use many different forms of identification in our daily lives (library cards, credit cards, passwords, drivers licenses) and that’s a feature, not a bug.
In part 3 he digs into the details of identification cards: how they’re created, how they’re used, and how they can be misused. Finally parts 4 and 5 lays out his vision for an enlightened identification policy of the future: one that protects civil liberties by expanding the diversity of identifiers we use in our day-to-day life.