3 ms·
Here is the gist (directly taken from the website): > Governikus provides the online service for authenticating your OpenPGP key on behalf of the German Federa
by Dunedan 3y ago
Here is the gist (directly taken from the website):
> Governikus provides the online service for authenticating your OpenPGP key on behalf of the German Federal Office for Information Security (BSI). This online service compares the name read from your ID card, your electronic residence permit or eID card for citizens of the European Union with the name specified in your OpenPGP key. If the names match, your public key is electronically signed by Governikus, confirming the match. The Governikus public key can be used to verify the Governikus electronic signature.
So this is apparently useful if somebody wants to send an encrypted email to somebody else and want to ensure that only the desired person can read the email. For that the sender would have to check that the OpenPGP key got signed with the Governikus public key before encrypting and sending the message.
What that doesn't seem to address are multiple people with the same name. So the sender know he's sending an email only John Doe can read, but he still don't know which John Doe it is.
To me that sounds like something which makes only sense for a few limited use cases.
- kkfx 3y agoI might be wrong but IMO the point is sign a key/subkey with something all trust, instead of having key-signing parties or unsigned keys. This allow John Doe to publish a public key other already trust it's belong to him.
- haukem 3y agoThis is not indented as a bullet prove government authentication system, if you need this use the eID card directly. The goal is to have a CA for (existing) OpenPGP keys which checks if the name in it is matching the one from the identity card. When you sign a PGP key to tell that you trust it you should compare the name in the identity card or passport with the one from the key, this system does it automatically. One tricky part is that many people like me leave out some names in the PGP key. In the first implementation of the PGP signing service it only ensured that at least one first name and one last name is also in the PGP key. I do not know if this is still the case. The German Federal Office for Information Security (BSI) is supporting GPG4Win since many years, see for example here: https://www.golem.de/news/bsi-deutsche-behoerden-bekommen-gpg-zur-verschluesselung-2201-162167.html https://www.golem.de/news/bsi-deutsche-behoerden-bekommen-gp... Disclaimer: I worked for Governikus some years ago and worked on the initial version of this service.
- codethief 3y ago> I worked for Governikus some years ago and worked on the initial version of this service. Do you happen to still know some people at Governikus? I've been wondering for years why their AusweisApp2 is so ridiculously bad. (For everyone else: It's the official government app to scan the NFC chip in your ID to use it for authentication online.) I have not been able to authenticate successfully even once in all these years. Every single time the app keeps telling me I should scan my ID again, and again, and again. Contacting Governikus support has been completely useless as well, and the reviews on the Google Play Store speak for themselves I think. Why is it so hard to fix this and why does Governikus support keep pretending I'm simply not scanning my ID "correctly" (i.e. holding my ID against my phone in the right way) when clearly the app is not working properly?
- kuschku 3y agoI've been using the ausweisapp on several phones, it's always worked reliably. But you have to hold the ID in the spot for NFC scanning for a solid minute, including while you type the PIN.
- codethief 3y ago> But you have to hold the ID in the spot for NFC scanning for a solid minute, including while you type the PIN. And I did. I have tried all kinds of ID <> phone positions (I also looked up where exactly the NFC chip is in my phone) and always made sure not to move ID at all while scanning it. I have even tried it on other phones, and I also asked several friends. No one has been able to use the app successfully.
- kuschku 3y agoI've had it working on several Google Pixels, Nokias, and Sony Xperias. With the eID of myself and several friends. Try if you can reliably read and write simpler NFC cards (e.g. a Mifare card as common for eTicket or university cafeteria cards). I'd like to see if it's something NFC-related or related to the eID specifically. I'll make sure to continue to check this thread for a reply from you, as I'm now genuinely interested in what's going wrong here.
- jolmg 3y ago> What that doesn't seem to address are multiple people with the same name. So the sender know he's sending an email only John Doe can read, but he still don't know which John Doe it is. That's not the way I read this. Governikus validates the names match, but they're linking the PGP key with the government ID, which should have some sort of unique identifier. What Governikus ought to be signing is a link between the PGP key and the government card's unique identifier. The name ought to be purely informational, and I wouldn't be surprised if the government has a public service showing the name of a person after supplying the unique ID as a parameter.
- germanier 3y agoIt does not have such a service. In fact, it is prohibited to use the document number for any other purpose than identifying the document itself, even for government entities.