Published: September 27, 2025
116
1.5k
2.8k

There’s something Starmer isn’t telling us about his digital ID plans… And it all centres around a little-known system called One Login. Thread 🧵

Image in tweet by The Stark Naked Brief.

From the level of outcry yesterday, it’s safe to say that many are aware of Starmer’s scheme to impose mandatory digital ID, dubbed BritCard, on every working person in the UK—citizen and foreigner alike.

Image in tweet by The Stark Naked Brief.

For context, BritCard was initially advanced by Labour Together, the think tank Morgan McSweeney ran before becoming Starmer’s chief of staff.

Image in tweet by The Stark Naked Brief.

Now, Starmer claims BritCard will help tackle illegal migration, and to be fair, it might—a little. But this is coming from a man who promised to stop illegal immigration, and since then, we’ve only seen record highs.

Image in tweet by The Stark Naked Brief.

What seems to have been entirely forgotten, however, is that the government already has a digital ID scheme in place. And let’s just say… there have been a few issues.

Image in tweet by The Stark Naked Brief.

In May, journalist Andrew Orlowski was contacted by a government whistleblower who revealed some of these issues involving something called One Login.

Image in tweet by The Stark Naked Brief.

One Login is the digital identity service system created by the Government Digital Service (GDS) in 2021 that will help deliver BritCard.

Image in tweet by The Stark Naked Brief.

It was designed to give citizens streamlined access to hundreds of government services and, through the GovUK Wallet, store key digital documents such as driving licences.

Image in tweet by The Stark Naked Brief.

It currently processes the personal and biometric data of some three million citizens and has already chewed through over £300 million in public funds.

Image in tweet by The Stark Naked Brief.

(In fact, the total cost of our digital ID escapade so far totals upwards of £700 million when you include the Conservative's digital ID programme, Verify, which was abandoned in 2023... That's a lot of houses.)

Image in tweet by The Stark Naked Brief.

When the whistleblower, who worked as a senior civil servant, arrived on the One Login project to set up an information-assurance team in 2022, he encountered complete chaos.

Image in tweet by The Stark Naked Brief.

The system was being accessed thousands of times a month by users holding unrestricted “do anything” system-administrator privileges. (And yes, many did not have the security-clearance required to work with such sensitive data.)

Image in tweet by The Stark Naked Brief.

So we're talking about hundreds of government employees having access to an unprecedented amount of very private information.

Image in tweet by The Stark Naked Brief.

Tie this in with past incidences of data misuse and institutional political prejudice and we have a troubling picture.

Image in tweet by The Stark Naked Brief.

Worse still, GDS did not require locked-down workstations for either its remote-working staff or the hundreds of external contractors involved in developing the system. In other words, this made it ripe for cyber attack.

Image in tweet by The Stark Naked Brief.

But it got worse yet... The civil servant discovered that part of the One Login system was being developed in Romania—a country that researchers at Oxford University have identified as one of the world’s "cybercrime hotspots".

Image in tweet by The Stark Naked Brief.

Next come the conflicts. Turns out, the same contractor responsible for developing One Login is the same one responsible for managing its risks. Can a company objectively assess the risks of a system they themselves helped build?

Image in tweet by The Stark Naked Brief.

In fact, according to the civil servant, no external provider has conducted a security and risk assessment at all. This would immediately disqualify it for use in other sectors.

Image in tweet by The Stark Naked Brief.

To put the danger into perspective: It would take only one user with certain privileges to create havoc—to install a back door into One Login that nobody would spot until it was too late.

Image in tweet by The Stark Naked Brief.

Want to guess what happened when all of this was raised with the GDS hierarchy?

Image in tweet by The Stark Naked Brief.

Rather than investigate, senior figures quietly reassigned staff from the civil servant assurance team to menial duties. A formal HR complaint was then lodged against the whistleblower, and new officials were swiftly brought in to replace them.

Image in tweet by The Stark Naked Brief.

As one digital-identity expert remarked to Orlowski on the scheme's potential dangers: "Imagine if [what happened to M&S] happened to Companies House or the Land Registry"

Image in tweet by The Stark Naked Brief.

Put simply: the UK’s digital ID scheme has already been marred by alarming security lapses, not just technical failures, but institutional ones, fuelled by a civil service committed to concealment over correction. Starmer's plan will likely amplifies this—on steroids.

Image in tweet by The Stark Naked Brief.

@StarkNakedBrief Given how the civil service in many departments are invested with those whose allegiance is to open borders and those that may have unrestricted access with no controls. The problems wont be the threat of being hacked but by the wholesale selling of created legit IDs and rights

@StarkNakedBrief One Login is everything. Rather: One lockout!

Image in tweet by The Stark Naked Brief.

@StarkNakedBrief The SDP also believes this is one of the many reasons for rejecting the government’s digital ID plans. @SDPhq https://sdp.org.uk/2025/09/26/...

@StarkNakedBrief Is this the same as Government Gateway ?

@StarkNakedBrief Great post briefing if you needed it on why you cannot trust the government on Digital ID Most people these days do not trust the government to run a bath, never mind a multi million pound IT system Please find out your MP’s stance on this, and if they are in favour show this!

@StarkNakedBrief I do not consent to my data being centralised. I do not consent to them knowing how I shop and what food I buy. It’s none of their business.

@StarkNakedBrief When has a Government IT project come in on time, on budget and without problems? 🤷‍♂️

@StarkNakedBrief Like in France !

Image in tweet by The Stark Naked Brief.

@StarkNakedBrief I predict that Britcards will be forged and issued to migrants before they fly in or cross the Channel. The migration number will probably double, not decrease. 😡😡🤬

@StarkNakedBrief But look how successful System One for the whole NHS has been. One unified system now takes care of all patients interactions with one simple source of truth and no delays. All for just a few million & paid for itself ten times over. Or did I dream that? Hang on, is that my alarm

@StarkNakedBrief It’ll be seamlessly linked to pornhub, social media and all online activity. It’s obvious. Then we are completely fucked. The worst regimes of the last century could only dream of this.

@StarkNakedBrief What's not clear to me is how this will effect tourists and business visitors. At any one time, we have tens of thousands of foreigners in the country, renting hire cars, booking AB&B, buying food and pharmaceutical items etc and occasionally needing medical treatment.

Share this thread

Read on Twitter

View original thread

Navigate thread

1/37