John Jordan, Province of British Columbia | OSS North America 2023
Join Mike Vizard in an interview with John Jordan, Executive Director for the Digital Trust Service for the Province of British Columbia. In this engaging conversation, they explore the role and purpose of the Digital Trust Service in ensuring the safety and security of online activities in British Columbia. John highlights the deep concern for people’s safety and their ability to engage in personal and business endeavors in a secure digital environment. Drawing from a decade of work, the Digital Trust Service has improved legislation and established trustworthy digital services for residents. John further explains how the program is leveraging open technologies and open standards to extend these capabilities and provide secure digital services to citizens.
Transcript
This is techstrong tv. Welcome back to the Open Source Summit. We're here with John Jordan, who's the Executive Director for the Digital Trust Service for the Province of British Columbia.
John, how you doing? All Right. It's great to be here.
I've been doing really well. Thanks. Digital trust service kind of sounds like all encompassing.
It's maybe a license to play with anything you want to play with, but, um, what exactly does the Digital Trust service do? So what we are working on is, uh, continuing to improve the safety and security of British Columbia's activities online. So the problems cares deeply about people's safety and ability to do things in their personal lives and in their business lives.
And we're building on 10 years of work where we have improved legislation and created trustworthy digital services for our residents. And so the program I'm working on is extending that by using open technologies and open standards to deliver these capabilities to citizens. It sounds like a lot of cybersecurity work.
Is that part of the mission and how challenging is that these days? Certainly. Um, what we're most concerned with is improving or, um, the digital experience of citizens, but minimizing, um, the risks such as phish attacks, spam identity theft, and uh, surveillance.
So the technologies and the capabilities we're working with the global community allows us to provide services and a and an app for citizens that creates peer-to-peer secure connections confidential between those two parties, deliver authentic data across those connections and to provide some privacy tools as well. We can, we can talk more in detail about that. Why is the province driving this conversation or, um, cuz in a lot of places around the world, it's kind of, those are private services by different companies, but what is the province see is the mission, right?
Like, so I mean, you governments provide the foundation for a trustworthy economy. So in, in the physical world, we provide, um, the services needed to, you know, provide identification for individuals, register legal entities, and regulate a wide variety of, of, um, economic activity, of course, like the environment, economy, health and so forth, resources. So this is really just extending into the digital world.
Surely we have to move beyond taking pictures of driver's licenses and, you know, incorporation certificates and emailing them. That can't be the foundation of digital trust for the economy. So really we look at this as just an upgrade moving from paper to secure cards and now to digital credentials and the ability to move them around safely.
We're at an open source conference. So what does open source play in this conversation that you guys are driving? Is everything built on open source and what are you playing with?
Right. So, um, some five years ago, we, uh, seven years ago, the province recognized that delivering technology projects was not as successful as we'd like. And we recognized that there was tools and capabilities in industry that allowed them to deliver value in incremental steps and repeatedly over time.
And open source projects and tools were a big part of that capability. So, um, by putting in place some new policies, some new procedures, uh, going for a default by open, um, projects like mine have been able to create new technologies and collaborate with projects within the Linux Foundation. And all of the code that we've developed is in the open because frankly it's a public good.
So why should we, uh, not allow others to benefit from the work that we're doing paid for by our, our residents. Was that a hard sell to the province officials or did they get it right away? Luckily, um, there's colleagues of mine that are very smart and visionary and they did the hard work of working with the lawyers and the policy makers to convince them that this was a good plan.
Uh, it's a definitely a challenge, but, um, we think we are seeing the benefits now with over 1400 repositories in GitHub, 200 teams that are developing software with contractors and with government employees and, you know, delivering value for, for the, uh, for our residents. How do you approach privacy? Because using your metaphor earlier, if I walk down the street somewhere, well that's out in the public, so therefore I don't have much of an expectation of privacy.
Right? So wouldn't that be the same in a digital world or is there a certain different constructs at work? Yeah, I mean, I think when we talk about privacy, that's sort of, I think of it as three, three pieces.
One is I want the ability to, you know, talk to another party like my friend, my family, my doctor, uh, a business, the government. I want to do that confidentially and digitally. Right now we have very little confidentiality because we always have a login service in between myself and the, and the, and the service that I'm using and that login service knows that I connected to it, right?
So the famous ones are, you know, login with Facebook or login with Google. They then know all the services that you're using with that login. So confidential connections is one of the things that we have in the technology we're working with.
Second is, is that data authentic? Do I know where it came from? Was it given to me?
Can the other party verify it without contacting the source? So that's breaking the phone home, uh, connection like, so that, that, um, is another privacy aspect. And finally, um, tech like privacy is really two parts.
One is, can I minimize the data that I share? So we have technologies like selective disclosure and even fancier stuff called zero Knowledge Proofs. So I can prove I'm over 19 or over 21 for Americans without revealing my date of birth.
Um, but the other aspect of privacy is really a contractual agreement that the, that the party that I'm sharing with agrees that they're not gonna disclose what it is we talked about and the fact that we even talked. And so that's not a technology question, that's a policy question. So over time I hope that the regulatory regimes will be the such that that's recognized as important, you know, and the data sharing that happens today will be minimized.
Are there certain technologies that play a bigger role in helping you kind of map that out? Or is there projects that you're s squarely focused on in that space that you wish more folks would help out with? Yes, absolutely.
It's a good question. Um, the work that we've been doing from the software point of view has been primarily in the Hyperledger project in a project called Hyperledger Aries. Um, Hyperledger known for blockchain, but Aries is actually blockchain agnostic, protocol agnostic, credential format agnostic.
So it's a generalized, uh, software frameworks that allow you to create wallets for your phone and the issuing and verifying services for enterprise and cloud. Um, there's a newly formed organization called the Open Wallet Foundation and we think there's gonna be some really interesting opportunities coming, uh, to, you know, share and, and um, perhaps um, add code to that project, the things that we've been working on. And then recently, uh, the Linux Foundation announced the digital trust initiative, which is really right now identifying that there are a number of projects that re that deal with the broad idea of, you know, confidential, authentic privacy respecting conversations.
And I think there's gonna be a lot of interesting work going on there in the future as well. There seems to be a lot of people playing around with digital wallets these days. Mm-hmm.
And I scratch my head cuz I go, am I supposed to have one from Apple, one from Google? Mm-hmm. And maybe one from Citibank and everybody else?
Or is there gonna be more like, I have one wallet in my pocket right now and that's all I need? That's also a great question. Um, I'm not sure we know the answer to that.
I think we use the term wallet, um, and it brings into mind, you know, what you usually have in your pocket or your bag. Um, but I think that term may become redefined kind of like phone is redefined. So you know what we carry around with us, this super computer in our pocket.
We call it a phone, but it's clearly not a phone. Um, I think wallets and wallet capabilities might be built into a variety of the apps we have in our phone. I sort of controversially say that phone equals wallet.
I don't think we're gonna have one app that contains it all. That's John's opinion, but we'll see what the future brings. Um, and I think that, um, businesses will want to have apps that are their brand because it provides them the opportunity to have a good customer experience.
Um, but I do think there will be important government issued things that need to go into a wallet that governments can be confident that the privacy and safety and security of their citizens is in good hands and is not being, you know, commercially exploited. You know, We saw the Lennox Foundation kind of wrap a bunch of projects today together and call it the digital service. Sounds like they've cried a little bit from you.
Uhhuh, um, is the way we think about all those technologies needs to evolve and cuz it seems like we're not really thinking about them in conjunction with each other and we're kind of walking through this in isolation and do we need to rethink our whole approach? I think we're in the, um, what, you know, we would call the period of ferment. So there's a lot of different protocols and potential standards and document formats that are attempting to tackle some of the problems we discussed around confidentiality, authenticity, and so forth.
Um, I think that's a great reason to get involved in open source projects because the work we're doing, for example, we don't require people to choose and forever stick with a certain protocol or standard. If things evolve, we can add new modules and take out modules. So, um, I think we will need to think a lot differently about how we use computing and provide services to people back much more to the way things were in the physical world where you actually, generally speaking, didn't enjoy a certain sense of privacy as you moved around and did things because it wasn't all correlated by computers behind the scenes.
Um, and we came back to sort of trustworthy peer-to-peer interactions. Um, but I think it's not yet certain how that's all gonna pan out. I mean, all those creepy algorithms that seem to know exactly where I am at any given moment mm-hmm.
Showing me whatever, yeah, it gets a Little weird. Yeah, we want to kind of undermine that, uh, from, from our point of view. I'm sure that's not comforting to commercial interests that are, that are benefiting from that.
Are you hearing from other governments around the world that are looking at your projects and things you're doing and you know, are they kind of saying, Hey, can we, uh, look over your shoulder? Well, we are certainly collaborating with, uh, peer provinces here in Canada. A number of the provinces we're collaborating at a code level and, you know, sharing user experience and policy, um, changes and so forth.
Um, we also through the Hyperledger projects have had a bunch of different interactions with countries around the world. Switzerland, Finland, Bhutan, Israel, and of course the European Union is heavily, uh, working on digital wallets and digital identity. Um, and again, that's where it's not yet certain where things will land from protocols and document formats, but we feel we're well positioned to adapt to change and, and would encourage others to look at the work that's happening in areas and in the Open Wallet foundation to make it better for their citizens and reduce costs, improve security.
I think you touched on this a little bit, but it almost sounds like we have a lot of projects that need that are related and need some cross pollination and maybe we also need to prevent ourselves from reinventing the same wheel over in these different projects. Is that kind of part of where this is headed? I think that's, I think that's part of the discussions that are starting to happen.
And like I said, it's very normal in technology to have this period of ferment over time. And then at some point, based on some set of circumstances, whether it's regulations, whether it's the availability of technology, a variety of factors, um, things will settle. And we experienced something called the dominant design.
It's kind of what goes forward. So yeah, at some point there was three, 400 car manufacturers in the early 19 hundreds all competing for this new thing called an automobile. But eventually it became the four wheeled hard bodied internal combustion engine that, that became the dominant design.
And after that we moved to the big three. There was a big shakeout. So at some point I think we'll experience this kind of, um, phenomenon because ultimately we have to talk the same protocols and languages like not human languages, but you know, the same, the machines need to interact in a predictable way and that that has to be protocols.
Just like we have IP on the internet, we're gonna need a trust over ip. I call it way to do things, um, that respects our privacy and empowers us As we go along here. Do you think that one of the challenges seems to be is not enough people are involved?
So how did you start out getting involved with the Lennox Foundation in these projects and are there things that you know, people can do? I feel like some of these folks, they're kind of, well that's kind of cool, but they're a little intimidated by the whole, how do I get going? Um, well first we're motivated by the problems we discussed earlier.
Um, and we had this open by default kind of notion. And my personal background back in the late nineties, I did my master's and I studied open source software versus proprietary software and looked at that as a, like I said, sort of the dominant design for software development. And it's come to be, that's open source is really a, a very powerful and popular way.
Um, if you wanna get involved, I think it's like any open source project, it's a super welcoming community. Um, you don't have to be a software developer. You can contribute to code, you can, um, help others in your organization understand the importance of this.
We have user experience people and different kinds of folks that are involved. Um, yeah. And, and we're always happy to talk to people as well as best we can to help them understand what we're doing and why.
All right. Last question. You're a kingdom for the day of open source everywhere.
What's that one thing you'd kind of want to fix tomorrow? Uhhuh? Oh my goodness.
I don't know how to answer that question. Um, I guess from a government perspective, I can take that sort of point of view is I'd really encourage governments to make the policy and legal changes they need to be able to use, not just use open source, but contribute to open source and work in the open. We've been having great success in British Columbia and nothing special here.
We're a government, like any other government in sort of, you know, uh, north America, western Europe and so forth. So yeah, make the changes and get, get, get contributing. All right folks, you're hearding here, those Wiley Canadians.
I up to something interesting again, maybe we should be looking a little harder at what they're doing and copy and paste. Yeah. John, thanks for being on the show.
Thank you for having me. All right. And we'll be back in a minute.





