5 ms·
You don't have to fear it. It's already here. I can't store my electronic government id on my Yubikey since it's not an approved device. So unless I buy a certa
by MyFedora 2y ago
You don't have to fear it. It's already here. I can't store my electronic government id on my Yubikey since it's not an approved device. So unless I buy a certain hardware token, my only option is to entrust my private key to a privately-owned certificate authority named A-Trust that forgot to renew their own root certificate once, taking out all government websites and services, and blamed an influx of users on a DDoS attack, in a regulatory environment where companies and even the government itself sue security researchers for disclosing security vulnerabilities responsibly, combined with tech illiterate journalists that buy whatever press statement they publish without verifying anything. Yeah uh, how about no? I trust my Yubikey more than you. I in fact lack so much trust in A-Trust that I assume my electronic government id is compromised, and that I among a few others call them A minus Trust, not A Trust.
- 4ad 2y agoAre you from Austria by any chance? So this is why I can't provision my yubikey for government authentication?
- 1oooqooq 2y agoAustralia, India, China, Brazil, EU. That I know of. US have id.me which is even worse than everything under the sun, and passkey bound by device would be a welcome alternative. Pray you never get poor enough to have benefits gate kept by digital goverments logins.
- 4ad 2y agoHere in Austria authentication revolves around this A-Trust entity (which is anything but) that the GP mentioned. The way it works is by SMS, which is very bad. They also have two absolutely appalling and confusing apps for authentication (and signing documents, but that never works), but they are useless from a security point of view as you can always revert back to SMS. And sometimes you need both the SMS and the app. Ugh. Also, if you are a non-Austrian citizen you need to register your phone with the police to be able to fully use most services. I want to get rid of this SMS loophole, and my understanding is that they used to support smartcards[1], and now support FIDO2 keys. Smartcards are annoying so I am trying to use my Yubikey, but when I try to provision it, it fails with some generic error. [1] Our health insurance cards used to be these smartcards, but I believe this system has been discontinued, although it's definitely still in use for medical services.
- 1oooqooq 2y agomy point is that Australia, like the others i mentioned, are phasing out sms. and more importantly, already phased out TOTP. Because they want you to use a dumb app which collect data.
- MyFedora 2y agoYes, exactly. Here is a list of approved hardware tokens: https://www.a-trust.at/de/fido/ https://www.a-trust.at/de/fido/
- klabb3 2y agoI don’t know anything about this. But let me guess: they also require you to use edge or chromium or some closed source and shitty sidecar application on your desktop?