4 ms·
> Because private keys are a far greater tool of proving identity than a SSN, I would argue one should have much greater culpability in an "unauthorized" action
by random023987 9y ago
> Because private keys are a far greater tool of proving identity than a SSN, I would argue one should have much greater culpability in an "unauthorized" action.
If you have the technical know-how to protect your private key, and you're immune from rubber hose attacks, and there's no mechanism for key recovery outside your control, I'd agree.
However, people.
- sliverstorm 9y agoYou wouldn't depend on technical know-how, you'd roll it into a card or something like that. Chip & pin cards already do all of this. And I'm not aware of any system suitable to replace SSN that can withstand rubber hose attacks. That's where law enforcement & the justice department will have to step in, as always.
- random023987 9y ago> You wouldn't depend on technical know-how, you'd roll it into a card or something like that. Chip & pin cards already do all of this. https://arstechnica.com/tech-policy/2015/10/how-a-criminal-ring-defeated-the-secure-chip-and-pin-credit-cards/ https://arstechnica.com/tech-policy/2015/10/how-a-criminal-r...
- snuxoll 9y agoThis attack doesn’t work with smart cards that basically do nothing but act as a HSM. The MITM attack works with a loophole in some EMV cards because the card isn’t signing a transaction request but just saying “PIN is good!” If your card holds a private key and won’t sign anything without also being fed a correct PIN you’d need a proper exploit of the application on the card to defeat it.
- nwellinghoff 9y agoWhy does the initial attempt of a solution have to work for everyone overnight? Stop the bleeding with those with tech know how first. The the others will come as the solution matures. What is with people wanting to flip the bit all time jezzz. Run two bits!
- vpalanc1 9y agoI think what many Americans fail to appreciate is that all the safety guarantees that come with deniability + lax security have a (pretty big) cost, one that YOU are paying in the end. Like - US for a very long while didn't use chip & PIN - but it was simple to deny the transactions and as a consumer you were somewhat well protected, despite lax security. But this generates large costs, and perversely, the cost/uncertainty affects the small businesses the most. Yes, when I use 3DSecure for an online transaction, the bank shifts the burden of proof to me (a correctly-authorized 2-factor transaction cannot be simply challenged with a complaint at the bank, I have to prove that it wasn't me). Still, it's hard to argue that 2-factor for online transactions is consumer-unfriendly, even if the consumer loses the deniability