Hacker News new | ask | show | jobs
by toomuchtodo 941 days ago
Identity and access management is a component of my work at a fintech. The argument isn’t lost on me. A death certificate is a powerful government signal, so while friction should be minimal so as to not be overly burdensome on the practitioner, it is not something you can be careless about from an identity perspective. It calls for strong provenance. If the technology is not transparent, that is a call to improve it to be so, not to ignore the requirements.

Doctors are also known for superiority complexes. Took forever just to get them to wash their hands to prevent contagion spread, historically speaking. They are not special snowflakes nor gods, but yet another stakeholder in a system. Their feedback should be used to improve systems as I mention above, to assist them but not block them. Change is inevitable.

https://www.cmu.edu/dietrich/sds/docs/loewenstein/physicianN...

https://www.nationalgeographic.com/history/article/handwashi...

(not a software engineer, head of security, including anti fraud measures)

1 comments

The legal system can generally deal with anything that falls through the cracks.

There's probably not a whole lot of massively society-impacting fraud in the death certificate system if a whole hospital can run off of technically fraudulent records when one guy is signing them all.

You could cut down on that by relaxing the technological attempts to "improve" it all and just let the legal system and humans address any actual abuse.

In this case it’s less fraud and more the fact that it can take months or even years to undo a death certificate during which time one would experience undue hardship. Making it hard to sign is by design.
> In this case it’s less fraud and more the fact that it can take months or even years to undo a death certificate during which time one would experience undue hardship. Making it hard to sign is by design.

It should be noted that absolutely none of those goals were achieved by the above-mentioned poorly implemented biometric requirement. The only thing that achieved was inconvenience that needed to be worked around to get the real job done.