About The Blog

Debate at the intersection of business, technology and culture in the world of digital identity, both commercial and government, a blog born from the Digital Identity Forum in London and sponsored by Consult Hyperion



  • Add to
Technorati Favorites


  • Creative Commons

    Attribution Non-Commercial Share Alike

    This work is licensed under a Creative Commons Attribution - Noncommercial - Share Alike 2.0 UK: England & Wales License.

    Please note that by replying in this Forum you agree to license your comments in the same way. Your comments may be edited and used but will always be attributed.

« Cheering on ID cards | Main | Gambling on ID security »

It was great until the users showed up

By Dave Birch posted Dec 1 2008 at 10:24 PM

[Dave Birch] An example that I've used before to explore what can go wrong with identity management system is the smart card-based "strong" authentication system that has been delivered as part of the National Health Service (NHS) £20 billion Connecting for Health (CfH) scheme.

The poll of more than 300 GPs found that one in six family doctors said they were aware of NHS staff sharing smartcards in their area, and one in 20 GPs admitted they sharing their own smartcard. Reasons given included the time taken to log-on to systems or to access data at multiple terminals, and losing cards or leaving them at home.

[From E-Health Insider Primary Care :: CfH condemns smartcard sharing]

Now, obviously the $20 billion and-still-rising Connecting for Health scheme is hardly representative of the average project with identity management requirements, but it does illustrate what happens when the management consultant-driven top-down politically-architected grand project meets the real world: in the end, something always gives.

A spokesperson for NHS Conecting for Health said the sharing of smarcards was unacecceptable and a serious discplinary offence.

[From E-Health Insider Primary Care :: CfH condemns smartcard sharing]


What's puzzling about all of this, to a technologist, is that the entirely predictable consequences of the implementation chosen would have been obvious to anyone with more than a passing acquaintance with security, smart cards, identity management or people.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]


TrackBack URL for this entry:

Listed below are links to weblogs that reference It was great until the users showed up:


The comments to this entry are closed.