4 ms·
So large companies are now government agencies?
by aestetix 2y ago
So large companies are now government agencies?
- growse 2y agoWhat do you think passports and signed TLS certs have in common? (Hint, it's nothing to do with "the government").
- aestetix 2y agoPassport/ID document expiration dates are decided by law. Therefore it is in fact "the government." Do you think there should be a law limiting the lifetime duration of an SSL cert to 45 days?
- gruez 2y ago>Do you think there should be a law limiting the lifetime duration of an SSL cert to 45 days? No such law is being proposed. The cops aren't going to bust down your door for generating a 3650 day certificate using openssl.
- appendix-rock 2y ago[flagged]
- bawolff 2y ago> Passport/ID document expiration dates are decided by law Passport max validity length is set by the ICAO not the government.
- bigfatkitten 2y agoICAO makes recommendations about the validity length of passports (amongst many other things). Contracting states are free to do whatever they like but for the most part, they choose to follow the Recommended Practices. https://www.icao.int/WACAF/Documents/Meetings/2018/FAL-IMPLEMENTATION/an09_cons.pdf https://www.icao.int/WACAF/Documents/Meetings/2018/FAL-IMPLE...
- xxs 2y ago> it's nothing to do with "the government" The depends where you live, and what the government means. In some places the validity of a passport is written in a law, voted by the parliament; in other it's a operation decision by the government (e.g. the ministry of the internal affairs). Where I live it's a law voted by the parliament. Also TLS fingerprints and biometrical data are "hashed" data, if that's what you mean about having in common.
- growse 2y agoIt's got nothing to do with what committee decides what the expiry is and how they then enforce it. The thing that certs and passports have in common is unrelated to whether the issuer is a governmental body or not. They're both centrally revokable, attested assertions of identity, where the attestation can be validated with the attester offline. If you try and come up with a design for any system that includes this type of assertion, you'll end up in a place where you'll probably want it to expire and need re-validation at some point. That expiry is a property of the attestation, and is therefore controlled by the person/group doing the attestation. In the case of a passport, this happens to be the government. For a cert, it's the CA.
- xxs 2y ago>where the attestation can be validated with the attester offline. Oddly enough, virtually all passport/personal ID checks around here are... online. Airports, police, any shop... all of them are all online.
- bawolff 2y ago> So large companies are now government agencies? The CAB forum is not a company (although it is made up of some) and the government does not set passport max validity lengths (they can make it shorter than 10 years, just like CAs can make certs shorter, but there is a reason no country gives out passports longer than 10 years)