Interviews
David Kelts – From Idemia to Decipher Identity and the Evolution of Mobile IDs

Riley Hughes
·
·
5 min read

In this episode of The Future of Identity Podcast, we are joined by David Kelts, a leader in digital identity and mobile ID initiatives, with a career that spans significant contributions across multiple companies and initiatives worldwide. David’s insights shed light on the journey of mobile driver’s licenses (mDLs), the evolution of identity verification, and his current role at Decipher Identity, where he’s tackling adoption challenges and working with businesses to expand use cases for digital identity.
We explore:
David’s early work at Idemia, including pioneering efforts in connecting driver’s licenses to online identity proofing.
The origin and adoption challenges of mobile driver’s licenses (mDLs) and why adoption has lagged behind expectations.
Privacy concerns surrounding digital IDs and the misconception of “phone home” tracking in mobile identity, along with how privacy regulations are influencing this space.
The role of standards organizations and government agencies, like AAMVA and TSA, in fostering privacy and security in digital credentials.
The future vision for digital identity, including the potential for digital-native identity credentials, cross-border use cases, and the value of user choice in secure digital wallets.
David also shares stories from working directly with states like Utah and California on mDL projects and reflects on what’s needed for broader adoption. This episode is a deep dive into the evolving landscape of digital identity and is perfect for anyone interested in the future of authentication, privacy, and user-centric identity solutions.
You can learn more about Decipher Identity at https://decipher.id.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.
Listen to the full episode on Apple podcasts, Spotify, or find all ways to listen at trinsic.id/podcast.
Video timestamps from David Kelts’ interview
You can watch the full video interview on our YouTube channel, or skip to the timestamps below to find the sections that are most interesting to you.
1:40 – David’s career journey, starting with his time at Idemia
3:18 – The origin of mobile driver’s licenses (mDLs) as a concept
5:15 – The early days of identity proofing and how it has evolved
9:02 – Adoption of mDLs and working with Utah and California
17:09 – Decipher Identity and working closely with relying parties
19:44 – David’s involvement in the privacy portion of the ISO specification for mDLs
22:46 – Nuances of the “phone home” objection held by some privacy experts
33:53 – “Ripping IDs should go the way of CDs” analogy
37:39 – David’s views on the future of identity
41:16 – How to get in touch with David
How to get in touch
Most people listen to the Future of Identity on Apple or Spotify. You can find all ways to listen at trinsic.id/podcast.
We write a weekly newsletter to highlight the biggest news and developments from the reusable ID industry. To sign up and join over one thousand readers from the identity industry, you can input your email directly into the form below.
As always, you can reach out to our host, Riley Hughes, on X (@rileyphughes) or LinkedIn. We love hearing from listeners! See you again in two weeks.
Related from Trinsic: see how Trinsic verifies identity in the United States, or explore digital identity verification by country.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to The Future of Identity, a show that highlights the world’s most innovative digital identity ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we are the first identity acceptance network, helping businesses verify their users 10x faster through the 75 million verified users in our partner ecosystem. I’m here with David Kelts, who started Decipher Identity, a professional services firm focused on mobile driver’s licenses and digital identity. And in this conversation, we covered the last decade-plus of David’s career making mobile IDs a reality, from his work at IDEMIA in the early days of the Arizona and Iowa mDL journey to GET Group and Spruce with the Utah and California mDLs, respectively. David has an inside look into early stories from several successful mobile driver’s license deployments. We also spend quite a bit of time talking about a subject that David is a foremost expert in: the privacy implications of mobile IDs.
Riley Hughes: I learned several things from our conversations, including David’s unique perspective about why the phone home objection that some privacy experts have is actually much more nuanced than it seems. I loved when David mentioned that he wishes all those hours he spent ripping music off of CDs could be recovered, just like all the hours that companies have spent ripping his attributes off of photographs or photocopies of his physical ID cards that he’s uploaded. That point of view on the future of digital-to-digital versus converting analog to digital really resonated with me, and I think you’ll enjoy this conversation too. And now to my conversation with David. David, so glad to have you here.
David Kelts: It’s an honor to be here, Riley. Appreciate it.
Riley Hughes: I’ve had you on my list of people who I’ve wanted to get on the podcast for quite a while, and so glad that we could finally make this happen. I’ve wanted to talk to you because you’ve been so deeply involved in the mobile ID initiatives around the world for so long. Through multiple companies, you’ve seen the approaches taken, multiple chapters of adoption, as well as different companies, like I say, and of course leading to where you are now with Decipher Identity. So I wanted to cover each of these chapters with you to sort of frame the discussion, and then based on what we think sounds interesting, we can Maybe dive into a few more of the specific examples.
David Kelts: That sounds great.
Riley Hughes: Great. So maybe starting with your time at IDEMIA, what were you tasked with there, and how does it relate to sort of what you’re doing now?
David Kelts: Well, initially I was doing software architecture and systems engineering for the backend systems that implement and manufacture the driver’s licenses. But then we had an idea that we could address some of the problems with online identity in the sort of open ID and the login space by bringing that trust behind the proofing of the driver’s license and try to bring it behind the account. So somewhere around 2012, 13, we started doing, and I applied and did two grants that were funded by NIST on how you could do enrollment processes that would establish the same amount of trust as behind the proofing of the driver. How would you use a driver’s license in an enrollment process in order to bring trust into an online account, bring that proofing value into an online account? So that’s kind of where that started. And from that, this concept of like, well, okay, then we can also render the driver’s license on the phone too. So there was those two efforts plus some prototypes of how you would do a mobile driver’s license that were the starting point of what I was doing at IDEMIA.
Riley Hughes: That’s interesting. Just because, just to jump in, I’m realizing now I don’t really know the origin story of mDL as a concept. I mean, I’m sure people have been thinking, oh, we have this credential in a physical wallet. Why isn’t it digital for a long time? Was what you’re describing a part of the origin story of mDL? Did mDL sort of originate out of a desire for stronger authentication, or was it sort of initiated by AAMVA and the DMVs?
David Kelts: Yeah. I mean, I think there were several things at the same time really that happened, because you did have AAMVA that started to talk about like, well, okay, but like, can’t we put this thing on a mobile phone? What would happen if we put this on a mobile? And that was a part of like a kickoff here. I mean, from my point of view, I was looking at it, I was looking at the online space and the issues and problems in the online space because there was no proofing. Like you could just sign up and get an account and you could do all kinds of things. There was no like… You know, like proofing associated and no authentication of that user. And then I think similarly, as discussions happened within the AAMVA space, then there was an early prototype. There was an early I/O prototype that was just a rendering on the phone that IDEMIA did. There was an early sort of engagement model that CBN did with Virginia that they published. So, and I think those kind of came together when everybody started talking about the problems found in each of those.
David Kelts: Then that sort of started kicked off a transition. It brought a bunch of people into what was happening in Working Group 10 within the International Organization of Standards, because that was basically saying, like, how do we put the SMARC, same thing as the smart card on the phone. And then that changed it over into how do we do this right for a mobile application. And in large part, like, I came at that from how do we put it in a mobile application, but how do we use that mobile application as an authenticator for my online accounts? Because now, if you start doing that, then you have proofing value and anonymity and authentication value that you can get in online accounts, which, you know, really kind of didn’t exist. So that was really the starting point of those conversations back then.
Riley Hughes: Yeah, that’s really interesting because, you know, you’re talking about the 2012 time frame and how at the time there was no real good way to do proofing online. And I think about some of the big identity proofing companies of today, like specifically the document verification companies, right, which are related to the driver’s license like we’re talking about, right, like the Jumio, Mitek, Onfido of the world. And this 2012 to 20 sort of 16 period was really when those companies were, you know, started and starting to grow really quickly. And I guess it’s just an interesting note to think about how these two different worlds have played out, right? Like, I guess maybe I’ll ask, when you were starting working on this in 2012, if I were to ask you where mobile driver’s license adoption would be by 2024, what would be your, you know, what do you think you would have said at the time?
David Kelts: I would have thought that it would be much, much farther along than it is in terms of adoption. adoption, because here we are in 2024. So we’re, I mean, a dozen years later, and mobile application speeds, that’s in 12 years. I mean, every three years things should be completely different, right? And here we are with adoption just starting and just starting really, you know, hopefully starting to ramp up bigger. So I would have thought it would be much farther along. But then I also acknowledge that when you start to really look at what people do with identity documents and what they would do with their phones and how they travel with them and how they travel the world with them, now you’re in the scenario where you can’t just do one thing. You can’t have a company comes up with a solution and thinks that solution is going to be used everywhere.
David Kelts: You have to have something that is worldwide and standardized, because that’s the only way that this can happen in the way that consumers actually are going to use their identity, which is, yeah, I pick up my phone and I fly to Europe and I go places, or I’m interacting with people and companies from around the world. So, and I’m not just talking me. I’d say I, that in the, like all, you know, many of us do that. So I think then when you look at it, it’s sort of, okay, well, if you want this to happen around the globe, it needs a critical mass. It needs people from around the globe to try to do it. It needs to take into account the fact that everybody in the world is entitled to do this if that’s what they choose to do. So how do you include all, you know, include everybody?
Riley Hughes: I mean, I guess my takeaway is, you know, in 2012, with these document verification companies coming into the scene and growing really quickly, right, I think some of these companies see, you know, millions of unique users per day in terms of their verifying documents for very big volumes of people. And, you know, that grew really quickly over that period. And mDL is just starting to get adoption in the last few years. However, the approach of asking a user to photograph a plastic card and take a selfie and upload that to the servers and be processed and everything like that has really, in large part, met a ceiling. Right, in terms of, like, the market has been penetrated, and all the use cases that can afford to put a user through that journey of uploading a physical ID document have really been tapped out. And so it’s interesting how much more quickly that market took off, but how much bigger the market could be if it were more interoperable or digitally native, where the user experience was much faster. So I think both of these things are good, right?
Riley Hughes: The sort of commercial push on the one hand to get things moving quickly, but then also embracing the standards as they are being adopted, I think is probably a recipe for success in a lot of these areas that just take a lot more time.
David Kelts: As you described it, like uploading a copy of my driver’s license, this is something that really shouldn’t happen very often. I even just checked into a hotel earlier this week, and they scanned—they took a picture of the front of my license. This is in the U.S. too, and then scanned the back. And it’s like, where does that go? Where’s that, you know, what’s the residue that I’m just left with that? In a digital form, you can have a little more control over the residue that you leave.
Riley Hughes: Well, speaking of adoption of mobile driver’s licenses, you’ve been, you know, obviously really deeply involved in several initiatives there, both, I know, with the Utah mobile driver’s license, which was a very early pioneer in the space, as well as you worked on the California mobile driver’s license as well for a time. Could you speak to those experiences? What did you learn about adoption of mDLs through working directly with states and that you think would be an interesting jumping-off point for that chapter of your career?
David Kelts: Yeah, so a couple of things. Actually, even going back into my IDEMIA days, so there’s a story that a friend of mine and I tell over and over because we went into Arizona to sell a mobile driver’s license as you would think of it now, like a credential on the phone. But we also had this ability to run that proofing and create an online account with the value behind it. Arizona wanted to buy the online account side. They bought what was called eID at the time because that’s all their problems. Because that trust, like how do you take something that is—how do you take a transaction that’s a high-value transaction? You’re going to have a car title transfer. You don’t want to get that wrong. Two people, you know, are selling a car to each other or something, right? So being able to move those online, that was the value behind, to the DMV, was that the online transactions. Then looking at, and I was involved also at the origins of Iowa’s RFP response. Utah, like, I’m glad just what I learned there. There was so much learned through doing Utah.
David Kelts: So with Get Group, North America, the Get Mobile ID line, we won the Utah mobile driver’s license contract, and they were looking for a certain thing. They were looking for a consumer pays model, essentially. They didn’t want, from the government point of view, they didn’t want to pay to put this in people’s hands. And so we did a different model, a consumer model that I think was the reason sort of that that won, which is this consumer subscription model. Again, the state didn’t pay anything to deploy that. And then on the other side, there’s a $9.90 a year subscription model. So that was the payment mechanism that they wanted. This is in context of several other states doing different payment mechanisms. So this is a trial of, like, how this is going to work. I mean, I think the learning from that is there’s more pushback, really, from the consumers because you’re asking them to pay upfront for a value they don’t realize until they’re actually doing transactions. So that’s a key thing.
David Kelts: Another really important thing in Utah was how much people struggled with that onboarding process. When you look at who, not just tech-savvy people, hold IDs and driver’s license. Everybody, if they want to, right, holds this. So they have all kinds of skill levels and all kinds of abilities and all kinds of levels of vision and color detection. And so when you look at how people do that onboarding, it was enlightening to sit there and watch. Thousands, because we did events, thousands of people tried to register themselves with the selfie matching and liveness and take a picture of their card, and the struggles people have with that. It was, that was really enlightening, looking at how could we possibly do a better job with that onboarding. And I think, as you were alluding to earlier, right, that onboarding that we’re doing transactionally right now through the identity verification companies is something that we could probably make more reusable, and how mobile driver’s license could make that more reusable, because now you’ve got digital native.
David Kelts: You’re not going analog to digital on these things. You’re lessening the skill level required of a user. Some of the first Utah applicants were, like, over 80 years old. And so, you know, they were actually some of the very first people that got it, right? And so you watch them trying to, with their hands not as steady and vision where they’ve got the screen, you know, and this is how people use their phones. It’s great that they do, but watching them try to do this scenario, this analog to digital scenario, was interesting. And I don’t want to say that it was limited to any one age group. It was not. The struggles are completely across the board.
Riley Hughes: Yeah, totally. I mean, I was just at an event earlier this week, and I was talking to somebody about what we do at Trinsic, and she said, Oh, I live in California. How do I get my, you know, my mobile driver’s license? And I sort of told her, Okay, go to the wallet, you know, click the plus button, find your state. And she started just doing it right there, and similar kind of thing, right, where, like, you know, I’m sure that there’s hundreds of these scenarios where one little step of the process in enrollment will trip somebody up who is otherwise really, you know, tech savvy.
David Kelts: Where people register, it’s kind of funny. It’s they’re either at home or a large number of people are in their car when they register. So the seatbelt’s on, right? And now, okay, now why do I know this? Okay, because as part of the pilot, when people struggled, we, like, asked them and then we opted in to help them, and you could see, they’re like, so how are they lit? They’re lit on this half of their face, and this half is dark. So the biometric match. So there’s a lot of those things that are there that were struggles that people saw. But, you know, another thing I think out of Utah was there’s a really good model that GET Group used for spurring adoption, and that was the driver’s license division worked with a local business. Typically local business or maybe a small chain and do an event there, because if you give people—because people need that reason to use it. They need a place to use it. So if you were going to roll out acceptance of it, you could have an event. It was sort of marketing for that business.
David Kelts: They could be seen as working to make privacy better for their customers, working with the state government, and so they would. Now, and that the key thing there is how important it is to have places to use it for it to be, you know, for people to want to adopt it or keep it. It’s really—that’s the whole pull in the marketplace, is, like, places to use it. And there’s only a little pull right now in the marketplace.
Riley Hughes: Yeah, and even the places that ostensibly accept it sometimes don’t in practice or something, right? Like I’ve heard of a hundred stories of people going to the TSA where they say it’s accepted, and then they get there and then the specific attendant in that line has no idea how to work it, and then they go try to find someone else, and then the line is held up, and it’s just a, you know, it ends up being a whole process. I’ve wondered how adoption initially takes place like that, right? Like you mentioned the events with specific businesses that want to accept the mobile driver’s license. That’s an interesting approach because I listened to this podcast recently with somebody who described this experience they had where they forgot their key to their apartment in San Francisco, and they thought, Oh man, it’s in my house. I locked my key in my house. What do I do? And then they sort of looked up, and on the external door there was a sticker right above the lock that they’d never noticed the sticker before because of course they were never looking for it.
Riley Hughes: But the sticker said, Need a locksmith? Call this number. And it was just like, you know, the sticker was right in the right place when they needed it. You know, the solution was right there when they needed it. And so, and I think about that a lot with mobile driver’s license, because I have tried to get into a happy hour or something and forgotten my wallet in my car. And of course, you can’t onboard into, you know, an mDL in a moment like that because you need your physical driver’s license. And so it’s almost like I wonder how to kick off that adoption if those locksmith-like scenarios aren’t really possible. Because again, if you have a physical ID on you already, then you can do most of the things. It’s mostly useful when you don’t have it on you. Do you see what I’m saying?
David Kelts: And it’s, you know, actually the physical card is needed really just as in order to create another authentication factor in that first enrollment, right? It’s like, okay, if you have the card and you have the face that matches the record, the original record, and perhaps if you have some pieces of data that also match to what is on file when your proofing happened, right? Because the DMV has the record of what they produced for you for a card. Now those things add up, add up to what is really important. What is really important is that the right person gets their driver’s license on their phone and not someone else. I mean, you don’t want to give it to the wrong person, and you don’t want to give somebody else’s. So.
Riley Hughes: Yeah, and I know right now at Decipher Identity, you are spending a lot of time working with relying parties on a lot of these challenges that we’re talking about. And, you know, looking at your background, initially I would have thought that you would be doing more work with the issuers, just given that you have so much experience there working with, you know, what is it, five states or something, and—or probably even more. And what made you want to dig deeper into the relying party side and work more closely with that side of the equation? What is the gap in the market that you see, and how are you kind of helping to address that?
David Kelts: If people need a place to use these in order for them to have the value, it is sufficient, once people find out, I can put this on my phone, great, I can get rid of that little sticker thing I have on the back where I put cards into it. Right now I can actually have everything. So that’s enough to get people in. But to give them real value out of it, it’s places to use it. And when you look at the places to use it, there’s all kinds of reasons that a business might adopt as well, whether it is that the fraud reduction matters to them. Depending on the use case that they have, if it’s a speed of processing, if it’s electronic records, you know, there’s lots of reasons to do that. The gap was there in the poll. but also because issuers, typically our government agencies, don’t necessarily have the relationship with the businesses who are the consumers of a driver’s license.
David Kelts: In the physical card model, it’s produce something, tell people what the security features are that they can look for so that, you know, and then it becomes pretty easy because it’s, you know, and there’s a standard for reading the back. So they don’t have a relationship with the businesses on the other side of that. And nor could you really expect them to, nor would we want our governments to be spending money and time to go and build out the other side of this, to build out the ecosystem that we all want as consumers of being able to put this on a phone. So my goal was to move to that, move over to this other side so that there was more of a pull in the marketplace. And that pull would help not just consumer adoption, but then all of a sudden it’s like, oh, okay, the states that are waiting to see what happens would also then jump in, and there’s all kinds of really interesting use cases over there too, including cross-border use cases, where we think of our driver’s licenses as an identity within the U.S.
David Kelts: However, why would it not be valid to those who would accept it outside the U.S. too? So there’s a lot of really interesting things that triggers by moving to that side: trust frameworks and mechanisms for acceptance.
Riley Hughes: So yeah, so I happened to know that you were deeply involved in the sort of privacy portion of the ISO specification for mobile driver’s licenses, the annex. And so I guess because of your kind of deep understanding of that spec specifically, and particularly as it relates to the privacy implications, I wonder what have you, you know, what perspective do you have about that that you think most people don’t understand, or is there something that the way people talk about privacy and mobile driver’s licenses that you think should be spoken about differently in the sort of Public eye.
David Kelts: Yeah, sure. So, well, there are a couple of questions there. Like from an historical perspective, I started doing privacy risk assessments, PRAM, with NIST’s PRAM model on the online identity things I was working on. And then through Working Group 10, which was the ISO working group that was putting together ISO/IEC 18013-5, which is for mDLs and mobile IDs or national IDs, I was the lead author of a pretty large group within there that was looking at privacy and what are the privacy impacts of what we were doing, and to make recommendations. And we actually created a really, really comprehensive list through a privacy assessment. What are the potential pitfalls in this, if you look at 18013-5? It’s merely a mechanism to interchange data between two devices or between two, you know, an intermediary of a server and two devices. That’s what is specified there. Take that to a bigger context, and now there’s a whole lot of privacy implications of that.
David Kelts: So how could you inform others on ways that you could assist or help or improve the privacy, not only just of that data exchange, but around the whole ecosystem? So that Privacy Annex, we actually wrote a pretty long document which included a bunch of ecosystem things, and then we really cut it back in order to be what was specifically applicable to that data exchange that’s part of that standard. Some of that was written, and some of that will end up informing some of the other standards that are coming out, 18013-7, ISO 23220 for provisioning, but it also became part of AAMVA’s mDL guidelines because they had that for the issuers. So the issuers have a set of requirements that they have to fulfill in order to have their public keys listed in. AAMVA’s digital credential. And similarly, there’s a whole set of requirements for being accepted at TSA, privacy requirements.
David Kelts: So a lot of the things in that annex, like of not releasing correlation handles to relying parties so that they could go back and collude and assemble a profile of you, a lot of those recommendations ended up in forming multiple different places. And it’s a good thing because then that makes it so that people have the information pre-thought, and they can think from their own mechanisms about how to improve privacy across the ecosystem that we’re all building.
Riley Hughes: Yeah, that’s interesting. I didn’t realize that. I mean, I had known that obviously we don’t have comprehensive regulation around this stuff at the federal level, and certain states have things, but it’s obviously piecemeal and not universal. But it’s interesting that TSA and AAMVA both—so maybe think of it almost like AAMVA on the issuance and provisioning side, right? And then TSA on the acceptance side as being the major relying party right now that accepts these—has, you know, both of which are organizations with leverage and an important role to play in the ecosystem have requirements around privacy that need to be present to be accepted, which kind of runs a little counter to a narrative I think that I hear occasionally in the market, which is that the ISO 18013-5 or 7, just sort of the mDoc family of specifications is inferior from a privacy perspective relative to other digital credential formats, particularly because of this notion of phone home, right? Like that the mobile driver’s license somehow would allow the government to know everywhere you use it.
Riley Hughes: And my understanding is that this is a little bit much more nuanced than this, and even in some cases flat out just wrong. But I wonder if you could expand on that. Why does this—I mean, I’m sure this conception does not exist for no reason. There’s probably some reason it exists, but also in practice, things pan out a little differently than that narrative. So yeah, I wonder if you could speak to that.
David Kelts: Start with a beginning statement because, so I want to—I am in 100% agreement with the reason that this exists. We don’t want people—we don’t… want anybody, those companies, government, other people, relying parties, we don’t want them to be surveilling our transactions, and there’s no reason. Like, that is the protection that you want to have in place. 100 percent that, like, if that’s achievable, like, we should as an ecosystem work to achieve it. And I say it that way, as an ecosystem working to achievement, because it is, it has to be a large group effort. Everybody does have to be involved in this. You started this talking about lack of comprehensive privacy legislation at the federal level and it being piecemeal with the states. There’s some really good state privacy legislations. But yeah, it does need something across the ecosystem, especially as we cross state borders, that’s going to work and be enforceable.
David Kelts: So now let’s look at phone home because, and there was a comment about, because I think phone home is one of these labels that got thrown on ISO 18013-5, and I think it’s unfair to that standard that it’s thrown there. And I’ll state again, 100% agree. We don’t want surveillance of our transactions, and so if you can architect that in, let’s do that. But my contention is you can’t architect it. Every architecture that exists eventually has a home. There is some place where transactions are going to be pulled together. And in my opinion, the only real solution to this is choice, user choice. Let’s look at all the different component pieces. Say you do server retrieval in a ISO 18013-5 server retrieval. And yes, that creates a home. That creates a place where transactions could theoretically be aggregated, right? You could have a log of them.
Riley Hughes: And when you’re saying server retrieval, you’re speaking to the sort of portion of the spec that people point to as the part that enables this phone home, or that theoretically could enable the source of the document to know that you are requesting it or using it or something.
David Kelts: That is a place in an interaction that could be correlation—or, sorry, an aggregation point for transactions, right? And that place is typically associated with the government, whether or not it’s actually run by the government, because in every implementation that exists right now, it’s not actually the government that is operating that service that is implementing server retrieval, right? But let’s look at the device-to-device transactions. So now in the device transaction, who is it that knows about the transaction? Obviously the relying party and the wallet application. So now the wallet is actually a home in these scenarios. If you take the credential, you put it on the wallet, and you go, like, the wallet has all the transactions, and you can see this in your wallet. So we’re using them today. You see that you have a list of all your financial transactions for each of the cards that you have. So that’s a home.
David Kelts: Now, in my view—and okay, this is why I think choice is so important—in my view, I’m more worried that the big tech companies from whom I might get a wallet would be aggregating my transactions and running intelligence on my transactions and offering me things, or handing that information out the back door. I’m more worried about that than I necessarily am about the government. But I want to respect that everybody has their view, and for a lot of people it is like, I do not want my government, and I don’t mind if my wallet is. So let’s take another potential, because this will also happen with credentials if you look at a sort of blockchain document data on the device and the validation in a blockchain. So as I turn that to the relying party, and the relying party goes back and uses an API through a steward, say a blockchain steward, to get that. Like, that’s home. Now all of a sudden, right, the reading, writing that blockchain. So could somebody at the node level, the steward level in a blockchain, could they then pull that together and do it? And yet they can.
David Kelts: I would contend every architecture that we have for these has a home. And we don’t want phone home as a concept of surveillance and tracking transactions. We don’t want it, and it doesn’t matter where the home is. Yeah, we want to prevent it. And I think this is why I say, I think user choice. If I’m comfortable with Apple Wallet, I’ll use it. If I don’t and I want to get a wallet from my government, as it’s going to happen in the EU, I can do that. And I can change them. I can swap them. I can get the DuckDuckGo of wallets, right, and put that there, right? So I think that it is choice and interoperability, which is going to enable the privacy in the whole system. And then having overarching privacy, whether it’s legislation or just enforcement, if there’s a place people can go for redress and problems and to remove, you know, to have better control of their data and report issues with it, then I think that’s another part of the picture, a non-technical part of the picture that’s needed to avoid what is phone home.
Riley Hughes: Yeah, so what I’m hearing you say is, you know, phone home is a term that is used to describe essentially surveillance, right? And a specific type of surveillance where all of your transactions are viewable by some party, right, who can correlate and see everywhere you use something. And what I’m hearing you say is one thing we should be worried about is at the issuance side, whoever issued that, right? So in this case, with a mobile driver’s license, the government, we should also be maybe worried about it at the wallet level. I would argue we should also be worried about it at the relying party level, given that there are data brokers and data aggregators and services that relying parties use all throughout the stack that, you know, tend to even today aggregate users’ data and financial transactions. And so it sounds like the concept of phone home in the mDL spec is a little bit of a red herring when we consider that there are a lot of places where transactions could be aggregated and surveilled, and we should take a more holistic approach to addressing that.
Riley Hughes: And it sounds like legislation is your suggestion for maybe how we do that.
David Kelts: Well, legislation is a start. That’s the enforcement part of it, and collaborate— like working together to build an ecosystem and making sure that the privacy requirements up front are spoken, which is part of why the privacy annex is good, and all of these different views and the ACLU papers on this is like, this is why all of these are good things, because we can all be aware of it and we can try to work towards that as a whole in an ecosystem.
Riley Hughes: Why does the spec even have server retrieval? Why not just present the data from the user’s device every time and then avoid this whole topic becoming a potential issue that the ACLU wants to write about anyway?
David Kelts: So the question was, why not just do the device-to-device that seems to be taking hold right now for the transactions?
Riley Hughes: Yeah, like why—what does the server retrieval feature in the specification give you? Like why even have it in there if it is somewhat controversial?
David Kelts: Well, okay, so there’s a lot of advantages that can be accomplished when server retrieval is used, because you can have sort of lighter-weight applications that where the relying party—and if you look at 18013-7 or OpenID—the mechanisms of moving data from your IDP that you chose to the relying party that you chose to do business with, the mechanism moving that data isn’t necessarily device direct. There are those mechanisms, so you could have a lighter-weight app that does server retrieval. It actually turns out in practice to be much faster, especially when you get into scenarios where there’s a lot of Bluetooth traffic concurrent and it slows down the traffic that you’ve got, or distance—you go past 25 feet. In the Bluetooth spec, and yes, it will reach a little further, but it slows down. So there’s advantages to the transactions in that. And again, I think if you take away the choice of implementing different ways, and you force everybody through one thing, especially as technologists kind of forcing through that one thing, you take away the ability to mix up this ecosystem.
David Kelts: In the scenario where it is just device to device, like I mentioned before, the wallet applications really become the nexus of transaction tracking and surveillance, and we’ve handed it to them. If you look at how this, you’re going to do a lot of this in a browser, and your browser applications now are from the same companies that are giving you your wallet applications. So, you know, is there potential collusion between these different things in order to, like, see how these transactions work together? And therefore, again, the people that feel that concern, which is a lot of people, can mix up what they do. They can mix up what they choose, and they can change what they, you know, choose to do, and it gives more choice. So I’m a proponent of it going lots of different directions. I think, as you tying way back to an earlier thing in the conversation, that concept that the benefit to the government was the online identity because they can move more transactions onto the web. That shows this OpenID, right, which is one of the predominant standards there, which has value.
David Kelts: And so being able to support OpenID as a mechanism in 18013-5, that you can force an OpenID flow, means that it’s now tied to the identity provided that person chose to use. So the authentication is put there. So you’ve got these other things that open up when you tie The on-device credential would be in-cloud authentication that you have, and you start to mix those two things together, I think people are going to be able to build a much more robust ecosystem when all of those pieces are implemented.
Riley Hughes: We could probably talk about this for forever, but for time’s sake, I do want to mention that a few months ago you wrote a series of blog posts where you used an analogy that I really like. You talked about how we used to rip songs off of CDs to get the sort of music from a physical thing onto a digital, you know, storage or whatever, and how the current process for identity verification, you know, mirrors that a little bit, right? We sort of photograph an ID to rip the attributes off of the ID and get them into a digital format. And I wonder, would you mind just breaking down or summarizing the point of the post about basically, I forget the name, ripping IDs should go the way of CDs or something like that?
David Kelts: Yeah, I know. I want back all those hours that I spent. I had—I was the guy with the CD collection that, like, filled the wall, right? And I’m feeding them every night into my computer. I want those hours of my life back, just like I want back all the photocopies of people have made of my passports and my driver’s licenses and all the uploads. Like, I want these back. And so what is it about this is the analogy is analog to digital. This is what we’re doing every time we run one of these identity verifications, was taking an analog real-world thing and we’re forcing it through a sensor, which is an only white light camera, in order to turn it into something that we can use digitally in the digital world. And so removing those steps—they’re painful steps—to do this analog to digital, and they’re fraught with a lot of problems. The problems I wrote about in the article is, one, that white light, like the security features that are on our documents, and then you see this when they shine a blue light or UV light onto the document, right?
David Kelts: The security features that are there are not detectable in white light. Or they’re so small because they’re meant to be looked at with a magnifying glass, and you don’t have the resolution to get to them. It’s really, really hard. And what I mentioned before with people and even myself, like, it’s hard to get that steady, to get that decent enough picture. And then we probably can’t get around the analog, the face analog to digital, the liveness and so on. But maybe we can, you know, come up with additional—you’re looking to authenticate that person in that process. But anyway, so from the analog to digital, I think that’s the area that’s got so many problems. Yeah, so, and this is also in these identity verification flows. This is also… where users are dropping off. I mean, we don’t get statistics on failure rates in identity verification, and you can get them from not matching, you know, as well. But, like, its quality of the photo taken is so low.
David Kelts: If you crop the— try to crop the photo of a bad, shaky capture of a card and you’re trying to match to the photo on the card with security lines through it and a hologram over the top, and it’s small and you’ve cropped it at that resolution and you’re trying to match the face to it, you have to set the matching value. You have to set the face matching value lower. If you’re matching that to the digital credential where you pulled a reasonable— I mean, you could, whatever the resolution is, mostly they’re going to be between 20, 40, maybe 60K, right? Good for matching. When you go direct digital, it’s going to take a whole bunch of the friction out of it, the drop-offs, the inaccuracies. You’re going to be able to tune the security higher. So this is why I think, you know, reusable credentials and using mDLs or any other identity credential, passports, and so on in these processes when they’re natively digital is going to be so much better. Not to mention, you could then start to do trusted phone authentication where you don’t have to release the images.
David Kelts: You don’t have to release the image of your card. You don’t have to release the image, like if you had a trusted process on the phone to match to what’s on the phone, and you can release that, and then it’s known to the service provider that you can trust that. I think that’s— this digital switch has to happen in order to get where we want to go.
Riley Hughes: Great. Well, I always ask people at the tail end of our podcast, you know, what does the future of identity look like to you? And maybe in this case, if you have any prognostications or forecasts about specifically how mDLs fit into that future, maybe over the next, you know, handful of years. I would love to get your perspective on that.
David Kelts: Well, yeah, I mean, I do think that, well, prognostications, I actually get my prognostications from others. I get them from Trinsic. And so, and it’s nice to have that because I kind of look at what I do in a vision way, I guess, as much as, you know, more than prognostication. And so when you’re looking at this, like being able to actually, whether this will happen in five years, I doubt it, ten years maybe, but can I just go and get my digital native version of these things? Wouldn’t it be awesome if I, when someone’s born, the parents say, Yeah, you know what? Great. We’re going to take a DID, and we’re going to have a blockchain birth certificate. And now I get to use that to then go build my identity. When I get a phone, I can, like, start to put things in that wallet application natively. I can go and get my driver’s license, and I can put it natively in Passport. Now I’ve got these things here. I’ve got, I can back them up in the way that I want. I can do cloud backups of these.
David Kelts: And my interactions in the physical world and in the digital world, you know, we get that additional trust that you get from that bridge. So I would say, you know, to me it’s—then also I look at the places where you get to use it. The other thing I can see happening here is it’s going to change what people do, what relying parties do, what businesses do, what federal agencies do. It’s going to change the way that they interact and do the business. I’ll use an example of when I last visited a federal agency for a meeting, and I had to send my social security number in an email to the person who I was visiting, along with my full name and information, so that they could enter it into the system and then they could do the background checks and so on. I’m like, Ah, this is just—it’s painful. Could you do it much— And then you show up and you show the physical card to the person, and you walk through the metal detector and everything, right? And then the person has to come down to meet you and visit that you’re visiting. There’s so much pain in that process. It’s so streamlinable.
David Kelts: Here, I’m going to send you a link. Register here, right? So then now I go to the link on the web, I present my identity document over the web, and I’m going to need to add my social security number for it because they’re going to do that background check, and I consent to do that. And now that doesn’t even go, that doesn’t go to the employee. It goes into this, right? It goes into the processing system, and into the backend, they can determine. Now I show up at the door and I’m presenting something. I don’t even have to share data with the security officer. I’m like, yep, I am the same person who’s registered. And now I go through the security. Like reduction in data collection and data processing that can happen in these digital formats when we start to trust not just data, because our, I mean, our whole computing system is built on text now, but not just data, but the processing that is happening at the edges. So I think that’s going to change a lot of flows, and it’s going to open up new areas of business that people didn’t really anticipate.
David Kelts: So I’m really looking forward to seeing what happens on the relying party side as these go, because people are going to dream up better, faster ways to do things. The pandemic forced that you can do all your groceries online and go and, like, get it put in the back of your car and come home when you’re busy. That’s a great convenience, and that doesn’t exist in the scenarios where we’re in these analog worlds. So I’m kind of really looking forward to seeing those things.
Riley Hughes: Great. Yeah, I totally agree. Well, last thing before we wrap, David, do you have anything to plug? Anything that you, anywhere if somebody wants to get in touch with you, you know, where should we send them?
David Kelts: Well, I can be found at Decipher ID. That’s the sort of nexus or starting point for the consulting work that I do. I actually do a lot of work with Secure Technology Alliance as well, which is another public forum where we have an mDL committee that’s working on rollout of mDL, building the ecosystem, a lot of the things that we talked about together in the podcast where we’re trying to solve the non-technical sides of this, the ecosystem sides, the privacy sides. So that’s another place where I can be found. I don’t really have something that’s particular that I’m going to plug, other than I think we should really start to collaborate, all of us together, on seeing the vision that we want. In this and working together for it.
Riley Hughes: Great. Awesome. Thanks so much, David, and thanks to all of our listeners for listening. Thanks so much for listening. If you enjoyed this content, please share it with others who will benefit from it. I’ve been getting some great feedback on the podcast recently, and since we don’t do a lot of self-promotion or ads or whatever, sharing the word really is the best way to signal to us that the content is valuable and that we should keep doing it. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out to me directly on LinkedIn or X at Riley P. Hughes, and visit Trinsic if you’re interested in building the future of identity. You can also visit trinsic.id/podcast to subscribe to new shows and subscribe to the Future of Identity newsletter, where we’ll share the essential reusable identity news we rely on straight to your inbox.

Riley Hughes
Co-founder & CEO @ Trinsic
Riley is the founding CEO of Trinsic, which he started in 2019 after making an impact on the digital identity industry as the first employee of Sovrin Foundation. He regularly writes and speaks on digital ID, including by hosting Trinsic’s podcast, “The Future of Identity.”
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
