Written evidence submitted by David Moss (HAR0005)

1.      This document is submitted by David Moss to the Home Affairs Committee’s inquiry[1] into harnessing the potential of new forms of digital ID. It concentrates on item 4 in the terms of reference: “What potential risks does the adoption of new forms of digital identification have for individuals, including risks to privacy and security of personal data?”.

2.      22 years ago in 2003 David Moss proposed an identity management system[2] to the UK Home Office which he called “Dematerialised ID”. Since then Mr Moss has kept up to date with the subject and knows enough to recognise an obvious problem with a digital ID project.

3.      The principle objective of this submission in summary is to bring MPs’ attention to the litany of danger signals emitted by the Government’s digital ID service GOV.UK One Login and to ask MPs to scrutinise before legislating:


4.      On 3 April 2025 42 MPs wrote an open letter[3] in favour of digital ID being used in the UK. Three of those MPs are on the Committee – Jake Richards, Shaun Davies and Connor Rand.

5.      A longer case for digital ID is made by the think tank Labour Together in their 4 June 2025 report, BritCard: A progressive digital identity for Britain[4]. Nothing progressive about it, that report has a foreword written by two MPs, Jake Richards again and Adam Jogee.

6.      The MPs’ open letter doesn’t identify any particular digital ID scheme. The BritCard report, by contrast, recommends GOV.UK One Login for identity verification and GOV.UK Wallet for attribute exchange.

7.      Both of these services, GOV.UK Wallet and GOV.UK One Login, are due to be provided by the Government Digital Service (GDS).

8.      Natalie Jones OBE, the Director of Digital Identity at GDS, made her optimistic case most recently in a 14 May 2025 blog post, GOV.UK Wallet: Building momentum, working in partnership[5]. Emily Middleton, Director General, Digital Centre Design, at the Department for Science, Innovation and Technology added her weight to the case for the two services in an interview at the Public Technology Live conference[6].

9.      GOV.UK One Login is the successor to the failed GOV.UK Verify service, which GDS started work on in 2012 under the name IDA (identity assurance). GOV.UK Wallet, on the other hand, doesn’t exist yet.

10.  MPs obviously cannot unconditionally recommend a service to the public when the service doesn’t even exist. That would be imprudent, irresponsible, unbusinesslike and unprofessional. It is important to wait until the service can be properly evaluated, warts and all. Let’s put GOV.UK Wallet to one side for the moment.

11.  GOV.UK One Login does exist. And the warts/cyber security problems it suffers from are well known.

12.  Computer Weekly magazine published Government faces claims of serious security and data protection problems in One Login digital ID[7] on 14 April 2025 followed by:

13.  And the Telegraph newspapers have published Government digital ID system ‘put citizens’ data at risk’[11] on 16 April 2025, followed by:

14.  Officials will have known about these cyber security problems with GOV.UK One Login for years. Why did they lure early adopters like the Department for Education into using the system? Please see Department for Education: Our experience of joining GOV.UK One Login[15], 20 December 2023.

15.  Not just officials but the IT consultancies also knew and in some cases caused the GOV.UK One Login security problems. The consultancies, that is, who have been paid tens of millions to develop GOV.UK One Login and who continue to be paid, e.g. PA Consulting Services, Accenture (UK), Deloitte, BAe Systems Digital Intelligence, Experian, Hinduja, …, please see the GOV.UK ContractsFinder service[16] for details of which firms are getting how many tens of millions.

16.  Think tanks such as Labour Together and the Tony Blair Institute for Global Change should also have known that there are GOV.UK One Login security problems. Otherwise, what is the point of them? (One of the authors of Labour Together’s BritCard report, Kirsty Innes[17], was previously Director, Public Services Policy at the Blair Institute.)

17.  MPs are not expected to be experts on cyber security. But they must beware of recommending a service to the public which resembles nothing so much as a national security crisis waiting to happen.

18.  In the articles listed above GDS themselves confirm that there are high and very high risks with GOV.UK One Login and that that has been known for years. They confirm that GOV.UK One Login scores only 21 out of 39 on its National Cyber Security Centre cyber assurance framework tests, up from a mere 5 out of 39 a year before. And they do not deny that it has been found to be possible to break in to GOV.UK One Login and take control of it without being detected.

19.  It follows that it is unsafe for us to record our personal information with GOV.UK One Login. Doing so opens us to the risk of fraud. MPs who recommend that we should use GOV.UK One Login are unwittingly recommending that we should risk being defrauded. They are unwittingly helping the fraudsters.

20.  GDS’s idea is for all government departments and agencies, both central government and local[18], to use GOV.UK One Login to allow access to public services. And Companies House, for example, are planning to make registration with GOV.UK One Login by company directors and by people with significant control of companies mandatory, starting this autumn 2025, please see Verifying your identity for Companies House[19], 8 April 2025.

21.  When it transpires that, far from reducing fraud, GOV.UK One Login actually automates fraud and multiplies it Companies House will have to stop operating. The same will happen if GOV.UK One Login becomes the unsurprising victim of a ransomware attack.

22.  If GDS have their way, HMRC and DWP will be out of action for the same reasons. No tax will be collected and no benefits or pensions will be paid.

23.  This submission recommends therefore that Parliament should examine the digital ID services on offer from Whitehall or wherever very carefully before legislating for the public to use them. As usual, the watchword is “scrutiny”, Parliament’s job.

24.  GDS’s current pretence in answers to questions posed in the House of Lords that there’s nothing to see here is untenable. Please see for example Baroness Jones of Whitchurch’s claim that “GOV.UK One Login follows the highest security standards for government and private sector services” in answer to a question[20] from Lord Clement-Jones.

25.  Accountants, lawyers and other professionals are currently trying to work out procedures for their clients to register with GOV.UK One Login in order to comply with the new Companies House requirements[21] on pain of committing an offence if they don’t.

26.  These practitioners can read the newspapers like the rest of us and see the security problems. What are they supposed to do? Pretend like the officials briefing Baroness Jones that there isn’t a problem? Given that the practitioners were warned, will their professional indemnity insurers pay up when the predictable crisis hits?

27.  It is hard for any organisation to disclose information about its security. But trust in GOV.UK One Login’s security has taken such a battering that GDS must either somehow restore that trust or abandon the service.

28.  One major reason that GDS’s GOV.UK Verify service failed was that it had a verification success rate of less than 50%[22]. Half or even more of the public’s attempts to register failed. That is not acceptable in what is meant to be a universal service for the whole UK population.

29.  Has the problem been solved in the case of GOV.UK One Login? We don’t know. GDS haven’t told us. They may not know. With GDS’s current track record MPs could find themselves promoting a service which excludes half the population.

30.  Other identity verification services are available. The Government Gateway[23], for example, has served us well for several decades and allowed HMRC to raise trillions of pounds in taxes that paid for trillions of pounds of public services. GOV.UK Verify and GOV.UK One Login have never done anything so useful.

31.  The NHS app might be a good choice to replace GOV.UK One Login. It doesn’t currently cover the whole of the UK but maybe it could. The Government is by no means exclusively bound to use GOV.UK One Login.

32.  Each component of the non-existent GOV.UK Wallet service will have to be certified trustworthy[24] under the Digital Identity and Attributes Trust Framework (DIATF). The certification authority is the Kantara Initiative[25].

33.  GOV.UK One Login has lost its DIATF certification, as noted above. Will it be able to regain its certification? That is unlikely given the recent revelations about its rickety security. Could Kantara certify a service which can be infiltrated without detection? Why should other DIATF services bother in that case to be secure?

34.  Natalie Jones OBE and Emily Middleton can deliver any number of panegyrics on the two services but in reality it looks like no GOV.UK One Login, so no GOV.UK Wallet.

35.  GDS have no experience of operating a digital wallet. They are trying to corral the businesses certified trustworthy under DIATF into a new market. Their lack of experience in markets was painfully clear years ago both to the Identity Providers signed up to GOV.UK Verify and to us accountholders. It is becoming clear again, this time to the DIATF service providers[26],[27],[28].

36.  It is possible or even probable that GOV.UK Wallet will turn out to be no more than the object of a Whitehall fantasy and that the attribute exchange job will be inherited in the end by Apple[29] and Google/­Alphabet[30], the people who actually do know how to operate a wallet[31].

37.  If it somehow sees the light of day in one form or another GOV.UK Wallet or its US-based successor could turn out to be an instance of David Moss’s Dematerialised ID[32].

38.  Over the years the Dematerialised ID proposal[33] was sent to Tony Blair, David Blunkett, Gordon Brown, Charles Clarke and John Reid among others with no response from either those politicians or their officials.

39.  The Committee may note that Pakistan[34] has introduced a digital ID scheme actually called “Dematerialized ID”. And the French[35], too, have their programme of dématérialisation.

40.  Everyone seems to be able to do Dematerialised ID except the UK (even with its 22-year head start). There’s Singpass in Singapore and iAM in Hong Kong and Smart ID in China. There’s MitID in Denmark/Greenland/The Faroe Islands and BankID in Sweden and Norway and MobileID in Finland. That is not an exhaustive list.

41.  But let’s get this in proportion. Do none of these countries suffer from illegal immigration? Or illegal working? Or tenants with no right to rent? Or crimes that rely on identity fraud? Or tax evasion?

42.  The assumption is so often that identity cards, whether material or not, will “obviously” always prevent or significantly reduce crime. But is that true?

43.  Says who? Former Prime Ministers? Officials? Think tanks? Consultants? Journalists? Salesmen? Are MPs sure that crime reduction follows ID cards like night follows day? Scrutiny required.

44.  And do these countries with ID card schemes all have better government as a result? Or more progressive public administration? That’s often the promise. But is it true? Scrutiny required.

45.  The BritCard report includes an indent for £400 million for GOV.UK Wallet and faithfully promises £2 billion of savings. MPs should satisfy themselves before any UK digital ID project proceeds that these benefits really can be garnered. They won’t want to find out after the GDS GOV.UK One Login team has worked its way through another £400 million that there is, as usual in these false prospectus cases, no £2 billion benefit to the public.

46.  Don’t let’s forget that the UK does have a thriving on-line economy, the fourth biggest in the world[36], and has had for decades thanks to private sector digital ID services underpinned by the identity verification work done by the banks and the credit referencing agencies.

47.  It may be just the government that has a problem.


June 2025


[1] https://committees.parliament.uk/committee/83/home-affairs-committee/news/207446/new-inquiry-harnessing-the-potential-of-new-forms-of-digital-id/

[2] http://www.dematerialisedid.com/BCSL/29%20May%202003.pdf

[3] https://www.computerweekly.com/news/366622277/Labour-MPs-launch-digital-ID-campaign

[4] https://www.labourtogether.uk/s/Final_BritCard_Labour-Together.pdf It must be infuriating for GDS, who make the unlikely claim that the GOV.UK Wallet/GOV.UK One Login combination does not amount to an ID card, to have Labour Together contradicting them.

[5] https://gds.blog.gov.uk/2025/05/14/gov-uk-wallet-building-momentum-working-in-partnership/

[6] https://www.publictechnology.net/2025/05/20/government-and-politics/interview-new-gds-architect-on-service-and-system-reform/

[7] https://www.computerweekly.com/news/366622533/Government-faces-claims-of-serious-cyber-security-and-data-protection-problems-in-One-Login-digital-ID

[8] https://www.computerweekly.com/news/366623357/Govuk-One-Login-yet-to-meet-government-cyber-security-standards-for-critical-public-services

[9] https://www.computerweekly.com/news/366623835/Govuk-One-Login-loses-certification-for-digital-identity-trust-framework

[10] https://www.computerweekly.com/news/366623991/Security-tests-reveal-serious-vulnerability-in-governments-One-Login-digital-ID-system

[11] https://www.telegraph.co.uk/business/2025/04/16/government-digital-id-system-put-citizens-data-at-risk/

[12] https://www.telegraph.co.uk/business/2025/04/19/ministers-are-pushing-digital-ids-can-you-trust-them/

[13] https://www.telegraph.co.uk/news/2025/05/21/the-single-government-login-has-just-failed-a-red-team-test/

[14] https://www.telegraph.co.uk/business/2025/06/08/digital-id-cards-could-be-starmers-poll-tax/

[15] https://gds.blog.gov.uk/2023/12/20/department-for-education-our-experience-of-joining-gov-uk-one-login/

[16] https://www.contractsfinder.service.gov.uk/Search

[17] https://www.linkedin.com/in/kirsty-innes-89834a49/?originalSubdomain=uk

[18] https://mhclgdigital.blog.gov.uk/author/local-digital-collaboration-unit/

[19] https://www.gov.uk/guidance/verifying-your-identity-for-companies-house

[20] https://questions-statements.parliament.uk/written-questions/detail/2025-04-23/hl6778

[21] https://www.accountingweb.co.uk/any-answers/identity-verification-and-govuk-one-login

[22] https://webarchive.nationalarchives.gov.uk/ukgwa/20201228155154/https://www.gov.uk/per­form­ance/govuk-verify

[23] https://www.publictechnology.net/2025/06/16/economics-and-finance/government-gateway-to-be-ready-for-retirement-during-this-parliament-minister-claims/ Another politician, this time Feryal Clark, repeating an official brief without knowing the same thing had been said nine years ago and still isn’t true, https://www.publictechnology.net/2016/05/13/uncategorised/dell-appointed-decommission-government-gateway/

[24] https://www.gov.uk/guidance/using-govuk-wallet-in-the-digital-identity-sector

[25] https://kantarainitiative.org/uk-certification/diatf/

[26] https://www.digital-identity-services-register.service.gov.uk/

[27] https://www.computerweekly.com/blog/Computer-Weekly-Editors-Blog/UK-government-set-to-finally-meet-with-digital-identity-providers-but-will-anything-change

[28] https://www.computerweekly.com/news/366623927/Government-starts-private-sector-engagement-on-digital-ID-and-Govuk-Wallet

[29] https://www.apple.com/uk/wallet/

[30] https://wallet.google.com/wallet/home?utm_source=walletweb

[31] https://www.computerweekly.com/blog/Computer-Weekly-Editors-Blog/Calm-settles-over-digital-identity-market-for-now-Hark-is-that-Big-Tech-on-the-horizon

[32] https://www.dematerialisedid.com/

[33] http://www.dematerialisedid.com/BCSL/29%20May%202003.pdf

[34] https://www.app.com.pk/photos-section/founding-chairman-nadra-maj-general-r-zahid-ihsan-addresses-during-the-pakistans-first-dematerialized-id-card-at-a-historic-ceremony-in-the-federal-capital/

[35] https://www.interieur.gouv.fr/actualites/actualites-du-ministere/avec-france-identite-vos-titres-didentite-deviennent-numeriques

[36] https://www.business.com/articles/10-of-the-largest-ecommerce-markets-in-the-world-b/