3 ms·
> Is it practical to do this cryptographically on the web, with something technically similar to today's client certificates? That one is easy to imagine (and
by matheusd 5y ago
> Is it practical to do this cryptographically on the web, with something technically similar to today's client certificates?
That one is easy to imagine (and is already deployed for some other use-cases in Brazil). People will be required by the government to have a client certificate, in order to interact with government services.
You just slowly increase the scope of both which people are required and for what. If you increasing it slowly enough, most people won't even notice or status-quo-bias it into being "business as usual".
- Freak_NL 5y agoClient certificates? Oh no, those are on the way out. You'll get some form of third party signed attributes. You go to a site that needs age verification, and get redirected to one of the applicable trusted providers of attributes (attributes like 'I am 18+'). In practice, this means you get forwarded to a government portal to login with your government issued ID, and then you'll be asked if you're OK with providing site X with the 'I am 18+' attribute (which you only have when you are over 18). Site X then gets a time-limited token from your browser that allows it to verify those claims with the provider of it. This is being worked on by various governments to my knowledge, and it will all be backed by ID-apps on your Google or Apple smartphone which won't be mandatory, but neither is there a clear answer to how people without (those) smartphones or no wish to install government apps are supposed to do certain things. The Dutch government is experimenting with one at the moment. Link in Dutch, including cheerful dystopic animated video: https://www.rvig.nl/digitale-identiteit/digitaal-identiteitsbewijs https://www.rvig.nl/digitale-identiteit/digitaal-identiteits...
- disqard 5y agoThanks for sharing that video!