Encyclopedia of Opinion
Question
Should electronic identities be managed by the state?
Position1 of 2
Yes, electronic identities should be managed by the state
Argument1 of 2

Only the state can guarantee security of data

Private firms cannot guarantee protection of data, especially against state actors. Only government security has the resources to appropriately protect citizen data.

The argument

Electronic identities should be managed by the government because only they can ensure the security of data. The largest caveat of electronic identities is that there are issues of cybersecurity. If private companies manage these electronic identities, the security of such data may come under attack. This type of issue has been seen increasingly over the years. In 2017, there was a catastrophic breach at the credit reporting agency Equifax, Yahoo admitted billions of email accounts were compromised, and Deep Root Analytics accidentally leaked the personal details of approximately 200 million U.S voters. Record-shattering data breaches and inadequate data-protection have been on the rise from private companies. The state should manage electronic identities because they have the means and resources to do so. There is no certainty that the state will be completely protected from security attacks, but the U.S government spends a large sum on data security. In 2020, the budget for cybersecurity-related activities was 17.4 billion dollars. The US also has federal institutions like the National Security Agency (NSA) that have the means to ensure the security of data. No other institutions can dedicate the number of resources into the security of electronic identities. The state should manage electronic identities because they will be able to ensure and guarantee the security of data.

Context

All activities related to official "papers" even if they are in fact in an electronic form should be governed by the state.

Premises

[P1]The chief risk with electronic identities is cybersecurity, and private companies have repeatedly failed to protect data—the 2017 Equifax breach, Yahoo's billions of compromised accounts, and Deep Root Analytics leaking some 200 million US voters' details. [P2] Only the state has the means and resources to secure such data, spending heavily on cybersecurity ($17.4 billion budgeted in 2020) and operating institutions like the NSA that no private body can match. [C] Because only the state can guarantee the security of the data, electronic identities should be managed by the state.

Counter-arguments

The government cannot guarantee the security of data. From federal government agencies to state agencies, cyber attackers have been able to get to US citizens' private information through every level of government. Significant government data breaches, while uncommon, still happen. In June 2015, 21.5 million people were affected by a breach at the US Office of Personnel Management, and in October 2009, 76 million people were impacted by the government security breach at the National Archives and Record Administration. The government cannot guarantee the security of data. Having the government manage electronic identities is not smart because this info can get streamlined in one system. This will make it easier for cyber attackers to get access to the information of millions at any given time. If electronic identities are managed by several private companies, it would mean that not all the data would be stored under one system, thus making any potential security breaches less potent. The state should not manage electronic identities because there is no guarantee that the data will be legitimately secure.

Rejecting the premises

[Rejecting P1] A list of corporate breaches establishes that private handling has failed, not that public handling would not — and the comparison is unbalanced, since the argument names no state failures while the breach of the US Office of Personnel Management exposed the background-investigation records of over twenty million people, which is precisely the identity data at issue. [Rejecting P2] Spending and agency capability do not deliver the guarantee the conclusion claims: a budget figure measures inputs, the agency named is a signals-intelligence body rather than a custodian of civil identity records, and consolidating identities in a single state system creates one target whose compromise is total — a structural risk that distributed private holdings do not carry.