{"id":1804,"date":"2020-08-06T13:29:24","date_gmt":"2020-08-06T21:29:24","guid":{"rendered":"https:\/\/blog.mozilla.org\/netpolicy\/?p=1804"},"modified":"2020-08-06T13:29:24","modified_gmt":"2020-08-06T21:29:24","slug":"by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/","title":{"rendered":"By embracing blockchain, a California bill takes the wrong step forward."},"content":{"rendered":"<p>The California legislature is currently considering a bill directing a public board to pilot the use of blockchain-type tools to communicate Covid-19 test results and other medical records. We believe the bill unduly dictates one particular technical approach, and does so without considering the privacy, security, and equity risks it poses. We urge the California Senate to reconsider.<\/p>\n<p>The bill in question is A.B. 2004, which would direct the Medical Board of California to create a pilot program using <a href=\"https:\/\/www.w3.org\/TR\/vc-data-model\/\">verifiable digital credentials<\/a> as electronic patient records to communicate COVID-19 test results and other medical information. The bill seems like a well-intentioned attempt to use modern technology to address an important societal problem, the ongoing pandemic. However, by assuming the suitability of cryptography-based verifiable credential models for this purpose, rather than setting out technology-neutral principles and guidelines for the proposed pilot program, the bill would set a dangerous precedent by effectively legislating particular technology outcomes. Furthermore, the chosen direction risks exacerbating the potential for discrimination and exclusion, a lesson Mozilla has learned in our work on digital identity models being proposed around the world. While we appreciate the safeguards that have been introduced into the legislation in its current form, such as its limitations on law enforcement use, they are insufficient. A new approach, one that maximizes public good while minimizing harms of privacy and exclusion, is needed.<\/p>\n<p>A.B. 2004 is grounded in large part on legislative findings that the verifiable credential models being explored by the World Wide Web Consortium (W3C) \u201cshow great promise\u201d (in the bill\u2019s words) as a technology for communicating sensitive health information. However, W3C\u2019s standards should not be misconstrued as endorsement of any particular use-case. Mozilla is an active member of and participant in W3C, but does not support the W3C\u2019s verifiable credentials work. From our perspective, this bill over-relies on the potential of verifiable credentials without unpacking the tradeoffs involved in applying them to the sensitive public health problems at hand. The bill also fails to appreciate the many limitations of blockchain technology in this context, as <a href=\"https:\/\/www.eff.org\/document\/842020-ab-2004-effaclu-letter-oppose\">others have articulated<\/a>.<\/p>\n<p>Fortunately, this bill is designed as the start of a process, establishing a pilot program rather than committing to a long term direction. However, a start in the wrong direction should nevertheless be avoided, rather than spending time and resources we can\u2019t spare. Tying digital real world identities (almost certainly implicated in electronic patient records) to contact tracing solutions and, in time, vaccination and \u201cother medical test results\u201d is categorically concerning. Such a move risks creating new avenues for the discrimination and exclusion of vulnerable communities, who are already being disproportionately <a href=\"https:\/\/news.un.org\/en\/story\/2020\/06\/1067502\">impacted<\/a> by COVID-19. It sets a poor example for the rest of the United States and for the world.<\/p>\n<p>At Mozilla, our view is that digital identity systems \u2014 for which verifiable credentials for medical status, the subject at issue here, are a stepping stone and test case \u2014 are a key real-world implementation challenge for central policy values of privacy, security, competition, and social inclusion. As lessons from <a href=\"https:\/\/economictimes.indiatimes.com\/blogs\/et-commentary\/you-cant-make-citizens-safer-by-making-them-more-vulnerable-aadhaar-does-exactly-that\/\">India<\/a> and <a href=\"https:\/\/www.nytimes.com\/2020\/01\/28\/world\/africa\/kenya-biometric-id.html\">Kenya<\/a> have shown us, attempting to fix digital ID systems retroactively is a convoluted process that often lets real harms continue unabated for years. It\u2019s therefore critical to embrace openness as a core methodology in system design. We <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/01\/22\/what-could-an-open-id-system-look-like-recommendations-and-guardrails-for-national-biometric-id-projects\/\">published a white paper<\/a> earlier this year to identify recommendations and guardrails to make an \u201copen\u201d ID system work in reality.<\/p>\n<p>A better approach to developing the pilot program envisioned in this bill would establish design principles, guardrails, and outcome goals up front. It would not embrace any specific technical models in advance, but would treat feasible technology solutions equally, and set up a diverse working group to evaluate a broad range of approaches and paradigms. Importantly, the process should build in the possibility that no technical solution is suitable, even if this outcome forces policymakers back to the drawing board.<\/p>\n<p>We stand with the Electronic Frontier Foundation and the ACLU of California in asking the California Senate to send A.B. 2004 back to the drawing board.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The California legislature is currently considering a bill directing a public board to pilot the use of blockchain-type tools to communicate Covid-19 test results and other medical records. We believe &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/\">Read more<\/a><\/p>\n","protected":false},"author":665,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"coauthors":[311512],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>By embracing blockchain, a California bill takes the wrong step forward. - Open Policy &amp; Advocacy<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Chris Riley\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/\",\"name\":\"By embracing blockchain, a California bill takes the wrong step forward. - Open Policy &amp; Advocacy\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\"},\"datePublished\":\"2020-08-06T21:29:24+00:00\",\"dateModified\":\"2020-08-06T21:29:24+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/netpolicy\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"By embracing blockchain, a California bill takes the wrong step forward.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/\",\"name\":\"Open Policy &amp; Advocacy\",\"description\":\"Mozilla&#039;s official blog on open Internet policy initiatives and developments\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263\",\"name\":\"Chris Riley\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/559fa836e2ec3814f8e5ac20d5b8cae6\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g\",\"caption\":\"Chris Riley\"},\"description\":\"Head of Public Policy, Mozilla\",\"sameAs\":[\"https:\/\/blog.mozilla.org\/netpolicy\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"By embracing blockchain, a California bill takes the wrong step forward. - Open Policy &amp; Advocacy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/","twitter_misc":{"Written by":"Chris Riley","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/","url":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/","name":"By embracing blockchain, a California bill takes the wrong step forward. - Open Policy &amp; Advocacy","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website"},"datePublished":"2020-08-06T21:29:24+00:00","dateModified":"2020-08-06T21:29:24+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/08\/06\/by-embracing-blockchain-a-california-bill-takes-the-wrong-step-forward\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/netpolicy\/"},{"@type":"ListItem","position":2,"name":"By embracing blockchain, a California bill takes the wrong step forward."}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website","url":"https:\/\/blog.mozilla.org\/netpolicy\/","name":"Open Policy &amp; Advocacy","description":"Mozilla&#039;s official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/92c467284d1b178dea38bea5386a5263","name":"Chris Riley","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/559fa836e2ec3814f8e5ac20d5b8cae6","url":"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4778f215cde88b189620cafd0476b440?s=96&d=mm&r=g","caption":"Chris Riley"},"description":"Head of Public Policy, Mozilla","sameAs":["https:\/\/blog.mozilla.org\/netpolicy\/"]}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1804"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/users\/665"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/comments?post=1804"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1804\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media?parent=1804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/categories?post=1804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/tags?post=1804"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/coauthors?post=1804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}