3 ms·
eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You alrea
by lima 1mo ago
eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs.
Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem.
Doesn't even need ZKP, the CA can just issue an attestation.
- maratc 1mo agoI've experienced this "solved problem" when visiting Germany during COVID. On every entrance to a mall there was somebody with a scanner device, and they only let you in if the scanner showed a green mark. I've been fully vaccinated (not EU) but my code didn't show a green mark on their scanner and I was promptly denied entry. The solution was to show them my German friend's code on my phone, this registered just fine, so I could enter anywhere. So the whole "eID/CAs/ZKP/PKI" mumbo jumbo can be easily fooled by a gif file.
- pas 1mo agoyes, just as age verification can be fooled by an older friend who gets the check mark.
- maratc 1mo agoReminds me of If you think cryptography can solve your problem, you don’t understand your problem and you don’t understand cryptography. (Bruce Schneier dug into origins of this here: https://www.schneier.com/blog/archives/2026/05/laurie-anderson-is-quoting-me.html https://www.schneier.com/blog/archives/2026/05/laurie-anders...)
- benregenspan 1mo agoThat part seems to qualify as an unsolved problem. But could anyone have taken the scanned data (or the GIF file) and used it to open a bank account in your friend's name? That seems like the main issue that is genuinely solved by correct implementation of this type of system.
- maratc 1mo agoAlready today nobody can open a bank account in my name with just a picture of my passport, as the original would be required. My passport doesn't have any of the "eID/CAs/ZKP/PKI", so the question of "what exactly the addition of it solves" remains open. My national ID card supposedly has some of it, the 17-year olds who want to pass as 18-year olds usually show a doctored gif file of their ID card, with a year of birth one or two years before the actual one; this works in ~98% of the cases.
- lbschenkel 29d agoActually it does. Biometric passports (and IDs) have a chip which is read via NFC and the information the NFC provides is signed by a CA which is the government that issued the passport. ICAO compiles a database of public keys corresponding to each government (plus countries exchange their public keys via bilateral agreements). Unless somebody is doing purely visual inspection, any time a passport is scanned there's PKI involved to validate if the information is genuine.
- maratc 28d agoNone of that applies to my (non-biometric) passport, and we were talking about banks that don't have the passport-reading equipment to begin with.
- Nursie 1mo agoThat’s not what the new schemes are about, and they aren’t going to be based on a qr code you can just copy, no. If you’re genuinely interested, look into things like OpenID credentials systems, and similar standards like w3c verifiable credentials.
- grebc 1mo agoYou’re conflating the real life need of ID, with trust in the organisation. Sorry. Wrong.
- thayne 1mo agoIf the scan also included a picture, that was signed with your private key, then it would be harder to spoof.
- fc417fc802 29d agoNot really, the attacker would just need a picture of you which he could then sign (since we're assuming here that he gained access to your key IIUC). That's a pretty low bar compared to the first step of gaining the key.
- deleted 29d ago[deleted]