4 ms·
We should stop treating digital pictures of physical documents as some sort of crdentials. There is a reason why numerous security features are embedded in phy
by w3ll_w3ll_w3ll 3mo ago
We should stop treating digital pictures of physical documents as some sort of crdentials.
There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.
- mrweasel 3mo agoDifferent countries handle these things differently, but it's honestly surprising to me that a photo of a passport or drivers license have any value. It provides no security, so why would anyone ever accept it a proof of identity?
- notpushkin 3mo ago> It provides no security, so why would anyone ever accept it a proof of identity? Because there is no other universal method that works online, and because companies don’t really care about identity verification – they just need something “good enough” so that they can say “hey, we’ve followed industry standard protocols, how could we have known this passport scan was photoshopped?” And to be honest I think it’s for the best. I really don’t want to be scrutinized even more online (and give even more personal data so it gets leaked a couple years later).
- mrweasel 3mo agoThere's certainly a point to reducing scrutiny online. However when companies are forced to do this verification, I just question why a photo of a password is considered "good enough", when it clearly isn't. I don't think you should be able to do anything with your passport online. That's a document that should only have value if you're actively holding it in your hand.
- Tangurena2 3mo ago> We should stop treating digital pictures of physical documents as some sort of credentials. This is how biometric "authentication" works - you slide a picture (of a face, or maybe a fingerprint or hand geometry) under a door, and the guard on the other side of the door looks at the picture, maybe compares it to some database somewhere and then says PASS/FAIL. Maybe the device taking the picture has some sort of cryptography to prevent yourself from shoving a picture of some authorized person. Usually not. People keep trying to find the correct magic spell to make biometrics "foolproof". That's a waste of time. Blackhat/DEFCON type conferences were showing people how to make fingerprints out of (the gelatin that makes) gummy bears back in the late 90s. Make them thin enough and you can fool pulse detection (carjackers in some Asian countries were chopping fingers off to bypass theft deterrent systems that used fingerprints).