6 ms·
I am looking forward to the stressors this places upon identity in the online world so we can develop something better than showing a picture of an ID card. Som
by sackfield 3y ago
I am looking forward to the stressors this places upon identity in the online world so we can develop something better than showing a picture of an ID card. Some sort of public/private key repository kept by licensing authorities would be a more preferable solution to me at an initial glance.
- aidog 3y agoJapan has done this with the mynumbercard. It's an ID with a chip on it. The problem is they used to tell people that the Number was private. It hasn't caught on for verification outside of government yet.
- boeingUH60 3y agoUntil that licensing authority gets hacked, then RIP to online security..
- c22 3y agoSure, but this is like saying you shouldn't replace your cardboard box with a safe because it could get cracked.
- maxwell 3y agoCardboard boxes aren't subject to leaked electronic keypad codes. https://www.thetruthaboutguns.com/liberty-safe-changes-its-policies-after-firestorm-resulting-from-their-compliance-with-fbi-j6-investigation https://www.thetruthaboutguns.com/liberty-safe-changes-its-p...
- stefs 3y agostill, card board boxes have no security at all; doesn't matter whether the codes were leaked or not. there's a point to be made for expections of strong security where it's actually weak, but is no security at all really better than bad security?
- Muromec 3y agoIt can be. If my bicycle has no lock at all, I will not leave on a outdoor parking near the central railway station, because I know for sure it will be stolen. The value here comes not from imperfect security per se, but from my ability to predict the outcome. Now if my bicycle has a meh lock, the chance of it being snatched suddenly increases.
- fluoridation 3y agoSo what are you saying? That the solution is to never prove your identity to anyone in any way?
- Muromec 3y agoI'm saying that maybe people who chose to accept the id scan knowingly accept the risk, have a second line of checks somewhere, evaluate amount lost to fraud or fines against the cost of having full-fledged PKI and also knowingly make it your problem if their evaluation proves to be wrong.
- maxwell 3y agoCardboard boxes can be acquired without a record of their purchase and are easy to hide among other cardboard boxes, like a book in a library. Also can be used to hide from enemies while moving around under the box.
- Spivak 3y agoI think the argument against is that right now people know how terrible an authentication system this is and don't build actual security on top of it -- "we only have cardboard boxes so we installed cameras and encrypted the contents." Once it's good people will outsource the work to what is essentially a CA system where every BMV in America is an issuer and I expect it to hold up at best as well as SMS verification.
- c22 3y agoI think the problem is that people are relying on this for actual security. The article demonstrates how easy it is to get companies to accept this form of fraudulent authentication (and the demand for this service speaks to its efficacy as well). Why not let notaries or an authoritative agency issue cryptographically signed one time codes upon inspection of your physical ID? Frankly, it sounds like a superior system to me.
- Muromec 3y agoThat's a good reason to not use HTTP, because hey, the keys can be hacked! The CA can be hacked, let's just use plain text and pray.
- jerf 3y agoThe CAs have been hacked. Multiple times, in several different ways. And that's just the public ones we know about, which I have no reason to suppose are all of them or even necessarily a significant fraction of what we would consider compromises. At the scale of "everything done on the internet" or "all the money" you can't wave this issue away. It is difficult, if not impossible, to build a security system that is more expensive to break than "all the money and value in the world". A government identity to do business with the government might just about be possible. A government identity to cover everything done by everyone everywhere is not. The value of cracking that system is just too high.
- Muromec 3y ago> A government identity to cover everything done by everyone everywhere is not. The value of cracking that system is just too high. So the value of the system being broken is too high, yet we live in a world where it's broken, as anybody can make a photoshop of your driving license? I'm sorry I don't get the argument.
- jerf 3y agoBasic principle of security: A security system should be more expensive to break for the attacker than the value of the thing it is securing to the owner. This is generally a counter to people using binary thinking and believing that a security system is broken if there is any way in at all, thus thinking things are either in the categories "secure" or "insecure" without any further qualification. In fact those categories don't exist. It is intrinsically at a bare minimum a spectrum of security, and one can slice & dice more finely if one likes based on what sort of attacks various different types of attackers can mount, e.g., defending against whole-internet scans is one thing, nation-state attackers specifically targeting you quite another. I'm using it in a different way: When what you want to lock behind your security system is essentially "all economic value in the world", such as "we'll solve all identity problems on the internet by just having the government provide identities", that means you need to create a security system that is more expensive to break than "all economic value in the world". However, you can't. Any conceivable security system is easier to break than that. There is a sense in which it is simply necessary that there be a wide variety of independent identification systems, each individually covering sufficiently small amounts of value that they are possible to exist at all, and with a diversity of costs and strengths to cover the various cases.
- yellow_lead 3y agoAs far as I know Estonia has had something like this for years
- mormegil 3y agoEU is working on an "EU Digital Identity Wallet". Which might be a good step in that direction. Even though it remains to be seen whether it won't be piggy-backed on some current weak authentication/identification methods in practical implementations.
- Muromec 3y agoEven US had it solved two decades ago on a peak of post 9/11 paranoia. Federal agencies use smartcards internally, there is federal root and the copy-cat of that was successfully rolled out in different flavors in several countries in Europe as well. On the other side of the spectrum, there is Dutch digi Id, which is the only way to use any government service online and works either with pure and simple username+password or a second factor through the app. There is no rocket since involved -- government agency sends you an activation code to your registered address and you activate the app. Then there is Ukrainian Diia, which is kinda both and also bundles government services themsevles and a digital id generator into the same app. But it's all built on top of existing PKI infrastructure that is used for decades before to tackle the problem of district tax office doing shenanigans with your tax reports. Add: And of course the most no brainer way to roll it out in a fragmented landscape of US is to let banks be Oauth2 providers, as they are already tasked with KYC stuff and have a license to lose. See https://www.bankid.com/en/ https://www.bankid.com/en/ refs: https://www.concretecms.com/about/blog/devops/how-make-us-government-pivcac-authentication-work https://www.concretecms.com/about/blog/devops/how-make-us-go... https://diia.gov.ua/ https://diia.gov.ua/ https://www.digid.nl/en/security https://www.digid.nl/en/security
- mschuster91 3y ago> And of course the most no brainer way to roll it out in a fragmented landscape of US is to let banks be Oauth2 providers, as they are already tasked with KYC stuff and have a license to lose. That doesn't stop banks from pulling all kinds of shit with their customers' identity or what they believe to be that. The amount of credit scams possible in the US is mind-boggling for me as an European.
- 3y ago
- nickrubin 3y agoWorld ID? https://worldcoin.org/world-id https://worldcoin.org/world-id
- smeej 3y agoPeople are already selling their Worldcoin identities. It has already failed.
- intotheabyss 3y agoThe actual blockchain usecase here is far less sexy than a dystopian eyeball scanning device: https://attest.sh/ https://attest.sh/
- jamiek88 3y agoThose immutable world ID’s are great! I have twelve different ones I like them so much.
- mschuster91 3y ago> Some sort of public/private key repository kept by licensing authorities would be a more preferable solution to me at an initial glance. Everyone in possession of an ICAO 9303-compliant ID card / password (so, at least everyone in Europe) already has such a thing. These cards can be read by any NFC enabled smartphone that can act as a reader, and the chips themselves can act as a a secure element capable of a range of cryptography functions. The problem is that while ICAO 9303 is a standard to retrieve and verify the data, it's fundamentally based on the assumption that it is just used to retrieve the data written in cleartext on the card as well as the biometric data so that you can build a staff-less boarding solution for air and sea ports. It's just a read-only dump of the data, signed with a certificate from the card issuer. We'd additionally need a standard similar to what Germany and Croatia have done that allows a person to use their computer or phone as an NFC reader "proxy" to create a digital signature against a service-provided challenge that can then be traced back to the government's PKI. Or, to put it in SSL terms, each government has a root CA, that issues a sub-CA certificate to the card producers ("can issue certificates for #.de"), who in turn have the card provision its own public/private keypair, and then sign the card's public key to use as a sub-CA ("can issue certificates for #.person-identifier.de").
- Muromec 3y ago>We'd additionally need a standard similar to what Germany and Croatia have done that allows a person to use their computer or phone as an NFC reader "proxy" to create a digital signature against a service-provided challenge that can then be traced back to the government's PKI. Why bother with NFC if the phone itself has secure enclave and a biometry check to lock it down too? And the best part of course, the federal government of US doesn't just have a standard, but actively uses all that for quite some time, just explicitly without NFC.
- mschuster91 3y ago> Why bother with NFC if the phone itself has secure enclave and a biometry check to lock it down too? There have been a lot secure-enclave exploits against both Apple [1] and everyone else [2], and fingerprint readers can also be bypassed. The Secure Enclave itself has a giant attack surface and is highly complex. (That however does not stop dreams of "digital driver's licenses" and whatnot, though, but that's another question) In contrast to that, ISO 7816 smartcard stuff has been in use for decades, and (unless it's Javacard...) a very limited complexity. It's rare to see something else other than sidechannel attacks. [1] https://news.ycombinator.com/item?id=24025502 https://news.ycombinator.com/item?id=24025502 [2] https://www.zdnet.com/article/manual-code-review-finds-35-vulnerabilities-in-8-enclave-sdks/ https://www.zdnet.com/article/manual-code-review-finds-35-vu...
- amarant 3y agoHere in Sweden we have a solution called BankID that is pretty much that. To get the key the first time you need to go physically to a location to identify yourself, after that you can use your BankID to get a new one when your first is about to expire(this is basically rolling your private cert) Never heard of any successful identity thefts in this system, except where someone has been tricked into signing something with their BankID that they shouldn't have. That's pretty hard to defend against on a systematic level though, at least in a way that's fool-proof. https://www.bankid.com/ https://www.bankid.com/
- sackfield 3y agoI've used BankID, I think its a fantastic system.
- lxgr 3y agoSimple public/private keys are neither private nor usable enough, but a federated, interoperable ID system is indeed desperately needed.