Tag: identity security risks

  • Risks We Took Seriously — And How We’re Addressing Them

    Version 5 of the white paper incorporates the findings of an external red-team review conducted against the prior draft. Each identified risk is paired with who is likely to raise it and the specific mitigation now built into the architecture.

    • Identifier reassignment could misdirect sensitive communication to the wrong person — mitigated by retiring, never reissuing, identity anchors and parent aliases.
    • A centralized breach target would concentrate an entire population’s identity data — mitigated by a federated model where the national layer holds only short-lived attestations, and personal data stays with local systems of record.
    • Directory enumeration would turn a browsable list of verified educators into a target list — mitigated by query-response verification only, rate-limited to prevent scraping.
    • Guardianship and custody changes are common and were unaddressed in earlier drafts — mitigated by a separate, mutable relationship/authorization layer.
    • MI agent overreach would create a new insider-threat class — mitigated by scoped, short-lived, human-revocable credentials.
    • Perception as a national tracking database — mitigated by explicit statutory scope limits, sunset and oversight clauses, and consistent public framing as an interoperability standard, not a database.
    • Vendor lock-in via domain ownership — mitigated by a public-trust or licensing structure for domains, overseen by a multi-stakeholder body.
    • Unfunded mandate resistance — mitigated by strictly opt-in participation, a phased pilot, and an explicit funding-model proposal.

    Publishing the risks alongside the mitigations, rather than only the finished architecture, is intentional — it’s the same standard the framework asks legal reviewers and pilot districts to hold it to.