• Skip to primary navigation
  • Skip to main content
Identity Woman

Identity Woman

Independent Advocate for the Rights and Dignity of our Digital Selves

  • About
  • IETF Research
  • She’s Geeky: AI Edition
  • Weekly SSI Newsletter
  • Blog
  • Media Coverage
  • Contact
  • Show Search
Hide Search

Archives for June 2025

No Phone Home: What it means and why it is important 

Kaliya Young · June 2, 2025 · Leave a Comment

I am a signatory to the No Phone Home Statement being released today, June 2, 2025.

This statement concerns a specific design choice that many in the industry consider potentially hazardous and unsuitable for many digital identity systems. The “phone home” capability is where the issuer of the identity is notified every time the identity is used in any way. For example, imagine if the government was notified every time a person took out their driver’s license to prove they are old enough to buy alcohol. This actually is the case in several eID implementations worldwide.

Some digital identity systems “phone home”. In some instances, this design choice is appropriate. One example where this is the case is for enterprise systems where a company issues a digital identity to an employee. When the employee uses this digital identity within the enterprise or at a partner site it is appropriate to phone home to the issuer of the employee identity—the employer.  This makes sense because they are acting on behalf of their employer in the role of being an employee. 

Until about 10 years ago the only architecture design for digital identity systems had a phone home design because it was the simplest to implement, and because the issuers, by and large, were organizations which felt they should have authority over people’s use of their identity. Older National and state issued identity systems use phone-home design, examples include Aadhaar, India’s national ID system, SingPass in Singapore, and the Estonian eID. The Nordic’s BankID, where the banks are the primary issuer of digital identities for all citizens, also has this design.  

Over the last 10 years many people have worked on designs and implementations for effective digital identity systems that do not phone home. The purpose of this work is because we believe in a reciprocal relationship between citizen and state rather than a power-over relationship that is appropriate in an employee-employer relationship.  It is not appropriate for a state to know or “see” everywhere a person uses an identity document, which is what happens in a phone home system. 

We innovated the three party model where the issuer issues a digital signed credential to a subject and the subject of that credential can share a digital signed proof of the credential with any other party of their choosing, that we call the verifier. With this design the issuer and the verifier do not have any direct interaction. The issuer does not know which verifiers the subject shares information with. 

This model was worked on in primarily in two different standards development organizations:  

  • The W3C first within the Credentials Community Group and in a formal Working Group (which has just completed V2 of the specification).
  • The International Standards Organization where they standardize Drivers Licence’s, the digital drivers license standard is 18013-5

I co-authored Standards Based Digital Credential Flavors Explained in 2023 which explains key differences between several credential types. However, this paper doesn’t touch on the fact that one of the flavors, ISO mDL/mDOC 18013-5, has a server retrieval option. Server retrieval means “phone home”. When an individual shares their identity information with a party can ask for permission to return to the issuer (in this case a state level government that issued the drivers license) and access the issuer server to retrieve the current information about the individual they are interacting with. This means that states who turn this functionality on can see where you choose to share/use your identity documents. The ACLU publication Identity Crisis: What Digital Driver’s Licenses Could Mean for Privacy, Equity, and Freedom, explains that there is the server retrieval/phone home issue within the mDL spec on page 13.  

The ISO mDL/mDOC standard is being widely adopted in North America and in the European Digital Identity Wallet project and mandated in their Architecture Reference Framework.

I hope the No Phone Home statement raises the awareness of  policy makers and those considering digital identity designs that this option for phone home functionality could potentially enable inappropriate surveillance. 

Additional Links:

  • IIW 40 Sessions Notes that covered the issue:
    • mDL: Privacy Concerns – How can it track you? (Day 1) Page 69 in the IIW Book of Proceedings
    • No Phone Home (Day 2) Page 164 in the IIW Book of Proceedings
  • Kim Hamilton Duffy’s Post – Even the Experts Didn’t Know: How a Simple Presentation Revealed mDL’s Latent Surveillance Problem
  • IIW 40 mDL Privacy Concerns Presentation
  • ACLU Digital ID State Legislative Recommendations
  • State Scoop article: Privacy advocates are worried about mobile driver’s licenses

     Copyright © 2026 Identity Woman  evelurie.com/web design/develop     

  • Terms of Use
  • Privacy Policy
  • Accessibility
  • Sitemap
  • Contact