As governments learn how new systems are defrauded
they need to bolt on security to existing processes and
digital systems to cause them to be immune to hackers
and fraud and access to public funds.
Technologists invented TLS to protect web traffic from
malicious observers and OAuth 2 provides
authentication
to computers. Why can't we invent some thing that allows
new services to be rapidly created while preventing bad
people's abuse of them?
Surely society has collective wisdom of what bad people
shall do when given the opportunity. We invented locks to
prevent people from accessing our things or property.
Why not a society wide government protective lock?
In the UK the government was defrauded by people
applying for covid loans. Welfare benefit fraud and
attitudes towards the poor has caused the general public's
perspective to be punitive and adding barriers to poor
people in receipt of benefits to get them back to work.
I am proposing a framework partially digital that allows the
onboarding of new and old governance structures to be
handled by a single architecture that is secure against
badness of people.
How does it work?
We describe a process or procedure using a set of
primitives that are secure independently and compose
them into a combination that is secure against the badness
of people when combined together.
Typical services that any government service needs is -
Address verification, identity verification, case verification,
data sharing between departments, public funds received.
UK government is trying to modernise all its services and
use technology to solve the hassle of administration. This
is the Government Digital Service (GDS)
But each system is separately built! There's a common
checklist that each service must satisfy. Each service has
to independently implement scaling, web security and all
the protections against fraud and bad people.
Let's use our collective wisdom of how to prevent not
genuine fraudulent requests from bad people from being
fulfilled. There is a number of protections that must be
generatable.
High end Security should be a service.