4 ms·
So maybe it's time we push for real private keys held by people and a signature is a fucking cryptographically proven document.
by coding123 7y ago
So maybe it's time we push for real private keys held by people and a signature is a fucking cryptographically proven document.
- chrismeller 7y agoYeah, but who issues those? The government is the obvious answer, blah blah blah Estonia blah blah, but that causes so many other issues... we already have debates over states issuing drivers licenses to “illegals” and “big brother” etc., so I don’t see this idea going over well. At the end of the day it would require that the US government issue an ID to every citizen, green card holder, visa applicant, long term visa holder, etc., illegals be damned... Even if that somehow happened, we now have the single largest hacking target in the world... are you comfortable with that? I’m sure not.
- tomjen3 7y agoNo we don't. Have the government HSM sign a separate key for each state for each month. Have each state HSM sign a separate key for each county for each month. Have each county HSM sign a separate key for each DMV, housing association or whatever, also only valid for a month. No big hacking target because they keys can be locked up or reverted pretty easily and the HSM are on military bases or whatever.
- chrismeller 7y agoI think that is remarkably ignorant. Yes, it works the same way the Chain of Trust does in your browser, but it also means that, at least for <insert time period>, there is a single point of failure. Hardware keys being on military bases doesn’t really fix that, the weak link is still a crappy government server. You also skipped over all the hurdles of recognizing a “person” that we will issue to anyway. Sure, we could ignore that... but then Montana doesn’t recognize signatures from Oregon.
- dwild 7y agoI think you completely lost the context of the conversation, we are talking about improving signatures. Everything you said against using private keys, apply to physical signatures. Sure hacks will surely happens, but they already do happens with signature. At least now you'll get much more traceability and be able to invalidate what needs to be. > You also skipped over all the hurdles of recognizing a “person” that we will issue to anyway. Sure, we could ignore that... but then Montana doesn’t recognize signatures from Oregon. Recognizing what? You are the only one here talking about this being a proof of citizenship. Does your physical signature prove that you are a US citizen? Does it need to? I certainly hope not. For each subsequent argument, please just ask yourself whether this issue apply to physical signature too in a way first.