4 ms·
My first inclinations are that Apple and Google should be in these committee meetings. 77% of Americans own smartphones [1]. 99.6% of new smartphones run Androi
by nthj 9y ago
My first inclinations are that Apple and Google should be in these committee meetings. 77% of Americans own smartphones [1]. 99.6% of new smartphones run Android or iOS [2]. I would love for my iPhone to generate a private/public key pair, with the private key stored on the Secure Enclave.
To register my public key, I fill out, on my phone, a bit of basic public information: full legal name, place & date of birth, and my current address and submit it. My phone suggests a nearby SSA office and proposes several appointment times, reminding me the day of.
At the appointed time, I take my phone, passport, birth certificate, SSN card, driver's license and recent electric bill with my address on it to the local SSA office. [3] There, the administration manually inspects and verifies my documentation. Their systems then sign the authentication along with the current location, the time, the official's ID number, and a sha256 hash of a photo of me and the official holding up today's paper.
My phone chirps, I use my passcode/Touch ID/Face ID/Dance ID to digitally counter-sign their authentication. This assures me that when the SSA's private keys are rotated because of inevitable compromise or on a routine schedule, my public key was not overwritten by the attackers.
The SSA administration publishes my public key in their online directory. Private companies can download the public key directories and cache them, or pay Stripe-like vendors for just-in-time lookups. When I want to apply for a credit card, my phone chirps and I sign the credit request, just like Apple Pay. When I lose my phone, I run by the SSA office again before I apply for another credit card.
Empowered by this new security layer, Congress passes a law establishing that no one can be held liable for—and credit decisions may not be made against—accounts that have not been digitally signed for any citizen who has a verified public key.
And then I remember healthcare.gov and I wonder if I should even press submit.
[1] http://www.pewinternet.org/fact-sheet/mobile/ http://www.pewinternet.org/fact-sheet/mobile/
[2] https://www.theverge.com/2017/2/16/14634656/android-ios-market-share-blackberry-2016 https://www.theverge.com/2017/2/16/14634656/android-ios-mark...
[3] I wouldn't necessarily need to have all of these kinds of documentation, but the public directory system would be able to indicate which forms of identification I did have at time of authentication, for third parties to weigh the risk of identity theft.
- andrewflnr 9y agoSo my legal identity is tied to proprietary hardware? Hardware that I arguably don't even meaningfully own? Running software with, especially in the case of Android, an atrocious security record? A secure enclave won't help if hackers just get the OS to call it to sign something malicious. It also kind of sucks for people who can't afford a smart phone.
- kelnos 9y ago> At the appointed time, I take my phone, passport, birth certificate, SSN card, driver's license and recent electric bill with my address on it to the local SSA office. Say I'm homeless and I literally do not have any of those things. How do I prove my identity? (To be fair, I'm not sure how I'd prove my identity under the current system.) Regardless of this... I can't have a credit card or any kind of loan without owning a smartphone? What if I can only afford a feature phone? What if I simply don't want to own a phone? What if own a Windows Phone, and the software only runs on Android and iOS? What if I'm a developer who wants to start a new phone OS (new huge barrier to entry)? I suppose I wouldn't be opposed to the option of having this stored on my phone, but what's wrong with just having a smart card with this information on it? If I lose it, it can still be easily revoked and replaced.
- nthj 9y agoIn retrospect, I'm not sure I was clear enough that my proposal was mostly a usability / familiarity hack for the general public. I agree this would only be an option. Specifically, if I'm not in a financial position to own and maintain a smartphone, OR I'm not inclined to trust Apple or Google with my identity, I could acquire a (heavily subsidized?) smart card from the SSA office. If I don't trust a national office with my identity (see the National ID debacle), I can choose not to use the system entirely. Banks can continue to offer to extend me credit by verifying my identity manually. Specifically, I wrote: > no one can be held liable for—and credit decisions may not be made against—accounts that have not been digitally signed for any citizen //who has a verified public key.// My idea being that if Bank of America sends me to collections or pursues a judgement against me, I can take them to small claims for the statutory limit by easily showing the judge that (1) I had a verified public key at the date of the debt and (2) Bank of America cannot provide my digital signature showing I accepted the debt. I'm in and out in a few hours and clear $5K. If the proposal above had even 20% rollout/adoption, that's 65 million people who can sleep a bit more soundly at night knowing their identity is–not perfectly secure—but FAR more secure than our current system.