5 ms·
> n this paper, we describe several security flaws found in the ID card manufacturing process .. Like accidentally on purpose,secure up to a point, but weak en
by Stierlitz 6y ago
> n this paper, we describe several security flaws found in the ID card manufacturing process ..
Like accidentally on purpose,secure up to a point, but weak enough to allow the spooks to generate their own IDs. I mean if the cards were unhackable how would a spy do his job :]
- xyzzy123 6y agoI know your comment was tongue in cheek but this has come up in the digital Id space before. All these things get bootstrapped off government sources and spooks have no problems because governments control those databases. You don’t need technical hacks if you control the systems of record.
- dane-pgp 6y agoSo what's to stop the ruling party from issuing its loyal spooks thousands of ID cards in key districts, which they then use to cast fraudulent votes in the election?
- chrismeller 6y agoAs an American residing in Estonia, I’m not sure what the benefit of a state compromising the card crypto would be. There are four broad categories of uses for the ID cards: 1) Obviously, a government-issued photo ID 2) For an increasing number of shops, as your “frequent shopper” card, which admittedly is slightly related to... 3) Authentication, including: logging into your bank, government websites (the state portal, the tax authority, the the “digital story” - all your medical records, the online booking website for booking some combination of surgeons/specialists that operate under the public healthcare system), the (one) online pharmacy that exists, etc. 4) Signing things. I’ve signed my lease with it (though “paperless” Estonia still wanted me to sign a paper version as well) and more routinely you have to “digitally sign” any bank transfers... which are the standard way to pay bills in Estonia, so you do it a lot. Finally, voting online. I don’t see how broadly compromising the crypto would really benefit anyone for any of those things, it would have to be a more specific individual attack, like draining your bank accounts. Edit: formatting, added voting
- LatNax 6y agoA single leak can be bad, multiple leaks piled into a single actor can be life changing.
- pisipisipisi 6y agoGetting asked as an expert "can this id card thing be trusted?" my answer has been "for communicating with the government you inherently don't trust, the method or security of an authentication device does not really matter" (filing your taxes or logging to services being the scope). Some claiming encryption privacy issues ... Well, for any meaningful opsec you should not be using the id card for encrypting messages about overthrowing the same government issuing the encryption devices in the first place, if government reading your messages is a threat in your model.
- chrismeller 6y agoYeah, I think the biggest risk would be rigging an election, but we’re talking about a country of 1.2 million people. Not to dismiss the importance of their elections on Estonia, it doesn’t really have the same worldwide ramifications that compromising a US, UK, German, etc. election would have.
- Strom 6y agoRigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the "digital results in rigging, keep it physical for safety" kind isn't super convincing. -- [1] https://en.wikipedia.org/wiki/1940_Estonian_parliamentary_election https://en.wikipedia.org/wiki/1940_Estonian_parliamentary_el...
- dane-pgp 6y ago> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. How many more votes would the party in second place at the last election have needed in order to have won instead? > If some party suddenly receives a lot more votes than they polled for - it will be noticed. Is there a mechanism by which the election could be run again (before the winners of the election have a chance to prevent this)? > Also Estonia already has a history of (non-digital) election rigging Or it's an argument that a voting system should have both hand-counting and digital counting, because rigging both counts is at least twice as difficult as rigging one.
- roywiggins 6y agoThe spooks are the same government issuing the ID. They can just call up the department issuing the IDs and ask for a batch of new identities. No technical flaws necessary.