8 ms·
I've been mulling over an idea that is essentially a combination of personal ID, secure digital authentication and online communications all baked into one. Th
by httpsterio 6y ago
I've been mulling over an idea that is essentially a combination of personal ID, secure digital authentication and online communications all baked into one.
There's a EU directive instructing on how citizens should be able to identify online with eIDAS. In my country, you can use eIDAS to authenticate in basically any governmental agency portal, but you can't get any eIDAS enabled auth method as a citizen. The current way of authenticating is done via bank accounts or a paid extra mobile service that requires a non-prepaid mobile contract.
This is a relatively huge issue. First off, the Finnish government pays the banks for each auth any user does when they for example want to log into their medical records etc. It's a few million euros a year just for verifying the users.
There's also obviously issues with whom the banks serve, there has been some cases with them not taking foreigners or people with bad credit as customers, making it impossible for them to authenticate themselves.
The current EU directives also indirectly require that the banks should provide a bank customer the possibility to authenticate without needing to have a banking account (which costs money), but to my knowledge this still isn't possible. I pay around 20 euros a month just for the luxury of having an account, not everyone can afford that on top of other bills.
Auth services are not accessible for impaired users.
It's also basically impossible to manage who has essentially the power of attorney and over which matters, for how long etc. Either you have to give them your login info (good luck resetting your SSN) or try to use the services over the phone and somehow convince the other side that you have permission to manage things for another person.
There's no ways of authenticating who is using your accounts online and actually verify the users.
Basically, my idea is combining biometrics, PGP and having the government running the identity management themselves. This would have added benefits of basically enabling hashed throwaway addresses and info for use online while providing a free and accessible way of authenticating strongly online.
- magahacka 6y agoIn my european country we can use the Personal identity card with the use of a USB to ID card converter?, to log in to governmental resources. although people mostly use the SmartID because its on the phone and free, unlike the SIM card authentication which is a bit more cumbersome.
- fabianlindfors 6y agoHi! I’m working on a similar thing aiming at bringing a digital identity to everyone. I’d love to hear more about what you’re working on. You can reach me at fabian (at) flapplabs.se
- amelius 6y ago> throwaway addresses Unrelated but speaking of throwaway addresses, it would be cool to be able to create a throwaway postal address (which is then translated by the postal service), so online shops don't get your personal address information.
- VWWHFSfQ 6y agoisn't that a po box
- amelius 6y agoNo because for example if you order from the same shop multiple times using the same PO Box, then they can link the information from each order.
- VWWHFSfQ 6y agoSo you're thinking like a virtual mailing address as a service. You receive and forward people's mail. Seems interesting. Also kind of high risk for the service provider. People will use something like this to buy guns and drugs and other stuff on the black markets. But I guess they do that anyway. You would have to be prepared to deal with a lot of subpoenas to unmask the real mailing addresses. Could be a useful service though. Be sure to charge a lot for it.
- amelius 6y agoWell, I would be ok with it if the regular postal service does the translation, and I wouldn't want to support any criminal activity.
- httpsterio 6y agoMy idea would have to be implemented on a national level. I take issue with the socio-economic injustities in the current identity and personal management solutions as they're not technically accessible nor free while still being simply a must have in order to do anything in Finland.
- toomuchtodo 6y agoI’m very interested in doing this as well, and have been trying to get the Login.gov folks (US centric) onboard (with Estonia’s electronic ID system as the model). We should chat!
- fabianlindfors 6y agoHi! I'm also working on something similar to this. If you want to chat, please reach out! fabian (at) flapplabs.se
- rawgabbit 6y ago> authenticating is done via bank accounts It occurred to me the USA might do something similar in the future and let the banks authenticate and verify identities. (The $1200 CARES Act stimulus payments were automatically wired to those who previously authorized the IRS to post their tax refunds to their banks.) > actually verify the users Maybe you can harness existing Public Notaries instead of using online banking? The USA has over four million Public Notaries who can "witness" and verify identities. For example, a user can pay for a Public Notary to come to his house. The Public Notary reviews the user's government provided identification and issue them an official E-ID and a encryption USB key like Google Titan Security key. The Public Notary can record this transaction in a government database so that there is a trail of who received the Titan key and who provided it.
- httpsterio 6y agoWe don't have public notaries as such and it would still 1. be a system that places trust in humans (which is easily exploitable) and 2. not free for the end users. I mean, I think it's some ten cents per auth through a bank, if you'd have to invite a notary or visit them every time you want to auth, it'd definitely cost more than that. I was thinking of a combination of biometric ID, physical card with NFC or USB and a pin or a password. Biometric info is hard to spoof, but not entirely impossible which is why ust stealing the ID card or biometric info shouldn't be enough, you'd need some type of password. Once the user provides all three, you'll know that physically that person carries the aforementioned identifications and is like whom they claim. These would be used to encrypt and unencrypt hashes, meaning that other individuals can also use the hashes to make sure they're contacted by or contacting themselves the correct person they meant to. We'd also need to implement a way to manage permissions for other users to manage our own data. If you're for example physically incapacitated and want your caretaker to be able to access some services, you could add their hashed identity as an allowed entity and decide over which services and features they can see and/or edit.
- culturestate 6y agoYou should take a look at SingPass[1], which is the Singapore government’s version of this. Most people[2] with a valid Singaporean ID card can register for it, and we use it for all kinds of stuff - signing in to government websites, opening bank accounts, checking in for covid contact tracing, etc. 1. https://www.singpass.gov.sg/ https://www.singpass.gov.sg/ 2. As far as I know, people on migrant worker visas aren’t allowed to use SingPass.
- jugg1es 6y agoI work in healthcare in the US, and using banks to perform auth is a fascinating concept. I also don't see the US ever adopting it due to nuances in American concepts of privacy. We don't mind sharing literally everything with a single entity, but once you get more than 1 entity involved, everyone freaks out. Using banks for auth would also eliminate the wide array of third party auth services, like Auth0. Eliminating the middle-man is very un-American.
- icebraining 6y agoIt's interesting that Finland took that approach. In Portugal the government just created its own ID provider (https://www.autenticacao.gov.pt/ https://www.autenticacao.gov.pt/), which lets you login with your ID card (which is a PGP smartcard) or a two-factor PIN + mobile phone token. The relationship is actually opposite: banks will let you login on their sites using the government's ID provider. It's not mandatory, though.
- diroussel 6y agoNot the same, but this reminds me of https://keybase.io/ https://keybase.io/