Showing posts with label id. Show all posts
Showing posts with label id. Show all posts

Thursday, February 18, 2010

The Maksu- ja Tolliamet perils of internationalization

In these tax declaration times, as a foreigner in Estonia I have a particularly treacherous time to get with the usability of Estonian e-services.

This year the Estonian tax authority (Maksu- ja Tolliamet - emta.ee, twitter) proudly declared that they will accept tax declarations in English:


However, trying to take them up on that promise, disregarding the numerous times I'm thrown into an Estonian-only environment, the English environment doesn't have the 2009 tax declaration I see if I switch to the Estonian one:


Estonian version:



Furthermore, once successfully in the declaration environment, the English version seems completely broken as I for example can't save my changed postal address (which of course works in the Estonian one). I can only deem this complete usability fail.

For the fairness of things and to provoke a debate, I'll share the opinion of a Swedish friend of mine:

"Yeah.. they really should not do it [attempt translation] at all..  no need to, really. Either you learn the language or you get help with it. Your choice (not theirs).

Just as in Sweden where they translate everything into 27 different languages and the tax payers pay for it. Not the tax payers fault that people do not know Swedish.

I do not mind any kind of miniority population but if they are unable to learn Swedish then they should pay for their own translation. Just as I seem to be unable to learn Estonian hence it is my problem to translate what I need, not the Estonian tax payers problem"

On another note, I've finally got a functioning mobile-id, as I was tired of the ridiculous software issues I had with my ID card. There english translation is even more absent, the support because of the jungle of organizations involved is terrible - but I recently was lucky enough to get both competent and helpful feedback when my ID card wasn't working.

Wednesday, September 24, 2008

The farse of BankID

The Swedish Administrative Development Agency (Verva) released has released a report suggesting to expand the concepts of electronic identification in Sweden. IDG writes how your cellphone will be used for e-identification, how e-identification will look in the future, everyone will have eID within two years and how the BankID company is optimistic about the future. What bull.

"BankID is an incompatible ugly hack the Swedish banks threw together to give Persson something to brag about during the EU-chairmanship"
... I quote from a renowned bank security specialist who must remain unnamed. The Swedish BankID really is terrible technology which attempts to fill the void the national ID-card should have, and could have filled long ago. Polisen writes (my emphasis): "På id-kortet finns ett kontaktchipp som i framtiden kan bli bärare av elektronisk information, så kallade eID-tjänster, som till exempel elektronisk legitimation". ("On the ID-card there is a contact-chip which in the future may be the carrier of electronic information, so called eID-services, for example electronic identification") Not only have they got backward what eID-services are and there is no such thing as a "contact-chip" if we are to be picky about device terms (which I think we should), they seem to not have any infrastructure, technical plan or even room to create a functioning hardware electronic identification.

The BankID-service is bad primarily because it is software carried ("BankID på fil") and because it requires service providers to chip in to the business model in a way which is just unfeasible. I have been told service providers avoid providing more services through BankID because the licensing is so expensive, whereas actually everyone could benefit and save money from using it more. Great success... I just realized that clunky BankID client which never works properly probably does embed standard PKCS#12 certificates (X.509) and keys (RSA) but I have not yet to peek into exactly what they are. The fact remains BankID chose to step beside existing infrastructure for hardware, software and protocols existing in browsers and other clients. Also, unless you're communicating with a BankID licensed organization, the BankID you have been issued is worthless. It may not matter much to most people, but principally it is strange not to be able to verify identity without going through a government.

Oh, and this story about Swedish bureucracy is just hilarious, according to
epractice.eu: March 2008 - "Due to the fact that the Swedish Administrative Development Agency (Verva) has no longer been assigned to manage the national eGovernment portal and that no other Government agency was handed this task over, the portal ‘sverige.se’ closes down." Yippie kay-yay...

In contrast, the Estonian ID card implements a regular PKI smart card much like the US DoD CAC. It ties into the OpenID project and anyone can implement services based on it using standard software and the government-provided LDAP directories. Oh and we already have Mobiil-ID using cellphone SIMs (using cellphone to pay for parking is a different but also very elementary thing done in all cities by most car owners for years).

To be fair though, the Estonian ID-card drivers are sometimes also messy to install, non-Estonian language support is failing in some points, the cards are pretty expensive to issue and since two cards have failed for me (I used to sit on my wallet) I've had to experience the failing support organization behind it. Probably Estonia can be said to have benefited from being a small country, not because there are few end-users (above a million is never a small number) but a limited number of market players which are able to cooperate and without too much involvement of Statskontoret framework agreements to stand in the way of pushing sensible technology.

My eToken PRO All this is of course pretty complex things and it cannot be expected of the layman to distinguish what is good or bad technology. Myself I've gotten a proper eToken PRO through Danish it2trust on which my keys are stored, to be able to encrypt, sign and authenticate while knowing that the key can practically (as far as I know) never be stolen unless the physical token is stolen. That feels really good, and even if I don't have that sensitive information myself, at least I know how to do it, and what software is capable or not to do these things properly.

Actually I recently found myself in a war-of-blogs regarding inferior banking security where the pretty large Swedish blogger "TKJ" spreads some confusion on what is the real problem and the cause for credit card frauds persisting. I'd like to say that I don't mind TKJ contributing to the discussion, on the contrary, and he's generously complimented the expert critique he's received. In my opinion also security experts should dare to step up and discuss these things openly, or media and consumers surely won't know where to push the market. So my $0.02 are that the reason swedes are still getting skimmed is the emberassing fact that Swedish banks and payment systems still use primarily copiable magnetic strips instead of the more secure "for electronic use only" smartcards. In the competition between nations for using the greatest technology, this is one area where Sweden is definitely suffering from having to carry it's legacy and being stuck with old solutions.

Tuesday, September 23, 2008

Buy bye privacy - I have joined facebook

So finally I have given in, I have joined facebook. One friend too many mentioned collaborating through a facebook app, and considering my revised view of integrity I have finally decided to give in and join this borg. Because, on today's internet, everyone know's you're a dog and you might as well be somewhat in control of it:

My name is Carl-Johan Sveningsson, I was born in Gnosjö, Sweden on the 25th of January 1981, my email address currently is cj.sveningsson(a)gmail.com, my S/MIME fingerprint is D1:50:3A:C3:76:FD:37:95:58:4D:A4:F1:A9:1E:D4:F9:49:0C:8C:95 and my OpenID is http://cjsveningsson.myopenid.com . This is me

On the other hand, I have a fascination with sousveillance and neoism pseudonyms, have just tried out FiSH IRC encryption (bulky and works so-so), I discuss encryption with #basvrak @ EFnet and have just signed up to FRApedia.se. So I think I'll be fine anyway... I hope.