5 ms·
> You have it all wrong. > Apple Reference Image is not an id system GP does not have it all wrong. A company desiring you to prove your identity often asks f
by cvoss 16d ago
> You have it all wrong.
> Apple Reference Image is not an id system
GP does not have it all wrong. A company desiring you to prove your identity often asks for a photograph of your government ID. Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID.
That the Apple Reference Image itself is not traceable to the device/user is beside the point in this use case.
- slester 16d agoWhy would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.
- JumpCrisscross 16d ago> If they can verify an Apple Reference Image they can verify an NFC document Interfacing with images is easy. Interfacing with NFC takes work. I have experienced precisely zero identity-verification workflows which NFC'd anything, and that includes my banks, which could easily ask for my debit card's NFC but don't.
- inquirerGeneral 16d ago[dead]
- lxgr 16d agoICAO doc 9303 validation is about 10 lines in Python (on top of importing the right packages) last time I did it around 2012. I doubt it has become harder since then.
- fweimer 16d agoWas the public key directory even operational in 2012? What about revocation checking? I think processing that information is mandatory now, but probably was optional/largely unimplemented in 2012. But maybe I'm off by five years or so?
- lxgr 15d agoRevocation checking seems like a big gap, yeah. I’m not aware of any public revocation lists (but I’m also not super familiar with the industry), so I can only assume (hope?) that there are some shadowy but highly accurate databases that KYC providers are tapping into. The CA public key I just got off my country’s website, they were kind enough to just publish it :)
- crote 15d agoCounterpoint: all of the identity-verification flows I have experienced in the last few years used NFC to read the chip in my identity documents - from car rental apps to my bank doing KYC. If anything, verifying NFC is easier than images. Asking the chip in my identity card to provide a cryptographically-signed "This document belongs to Jane Doe" request is a handful of lines of code. Doing the same with images? Good luck coming up with an approach which isn't fooled by a photocopy!
- JumpCrisscross 15d agoCool! Where are you geographically? I’m mostly in North America, Europe and South Asia.
- microtonal 15d agoMy credit card company’s app (in Europe) reads my ID through NFC when logging in for the first time (besides requiring ID photos). Our national app for logging into government sites and confirming things also requires a step where the ID’s NFC is read to reach the highest trust level. So it’s definitely becoming more and more common here.
- tmp10423288442 16d agoThere are tons of online services that require you to take pictures of your face, driver’s licenses, passports, etc.
- happyopossum 16d agoHow exactly am I expected to upload my nfc chip to my insurance company’s website?
- lxgr 16d agoThey just have you tap your identity document against your phone. Works pretty well in my experience. The phone is just a relay to a remote server here, as newer ICAO machine readable travel documents intentionally don't support signatures/non-repudiation anymore, so you have to run the entire exchange against a component you trust (i.e. your server, not so much your app on a rooted/manipulated phone).
- rickdeckard 16d agoI agree, but for this to matter, a critical amount of fraud should be based on people uploading modified photos of ID's. If someone took a picture of a fake ID in the past, this method will bring no benefit, it will just add Apple as a paid service-provider. It also doesn't change the trust-relationship between the two parties: If I need to prove my identity by uploading a government ID, _I_ am doing the photo attestation that this is the ID matching the data I provided, with or without an Apple Reference image.
- alwillis 15d ago> Now that this is easily faked, it is reasonable to expect that the company will ask for a verifiably authentic photograph of your government ID. The image will be authentic, but an authentic image of a fake id isn't useful to them. Also--only two iPhone models support this technology. It'll be years before the DMV or whoever could count on enough adoption before they could support it.
- vablings 15d agoI think this is a good thing. Proof that an image is actually real is a valuable underpinning of society and being able to provide that is incredibly important.