3 ms·
Provable identity: you get an email, hi i'm a hiring manager from company X, can we get in touch about job Y, could you please send me your (secret) phone numbe
by ng55QPSK 5y ago
Provable identity: you get an email, hi i'm a hiring manager from company X, can we get in touch about job Y, could you please send me your (secret) phone number?
It should be possible for you, the receiver of the email, to check if the email originated at company X.
Digital Notary: this came up in several data privacy discussions. You (A) are in contact with B, but you don't want to send B something like a scan of your passport (e.g. for age restricted services). So you disclose the passport scan to Notary and he sends B the message, the passport was disclosed to me and the person is >21.
- teddyh 5y ago> It should be possible for you, the receiver of the email, to check if the email originated at company X. You could check the DKIM signature of the email.
- na85 5y agoExactly. "Did this email originate at $server" is what DKIM and SPF are meant to solve and IME they work well. Setting them up is not particularly difficult and there is a wealth of open documentation about it.
- 0xCMP 5y agoThe point is "proving" something without showing them the proof. E.g. someone Company X trusts looks at the documents or etc and sends a signed confirmation that they confirm X, Y, and Z about Person A. The point being that Company X does not have a copy of the sensitive information (and neither the liability of losing it) and the Digital Notary would (in theory) have better procedures for properly deleting or storing the data as needed.
- namibj 5y agoRe: passport scan issue: check out what the German ID card[0] does. It's better than the passport scan sending "state of the art" on both security and privacy. [0]: https://www.personalausweisportal.de/Webs/PA/EN/home/home-node.html https://www.personalausweisportal.de/Webs/PA/EN/home/home-no...