3 ms·
Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they
by slester 18d ago
Why would anyone be using images of government IDs when modern documents have NFC chips with the data, signed and with anti-cloning mechanisms on them? If they can verify an Apple Reference Image they can verify an NFC document.
- JumpCrisscross 18d ago> If they can verify an Apple Reference Image they can verify an NFC document Interfacing with images is easy. Interfacing with NFC takes work. I have experienced precisely zero identity-verification workflows which NFC'd anything, and that includes my banks, which could easily ask for my debit card's NFC but don't.
- inquirerGeneral 18d ago[dead]
- lxgr 18d agoICAO doc 9303 validation is about 10 lines in Python (on top of importing the right packages) last time I did it around 2012. I doubt it has become harder since then.
- fweimer 18d agoWas the public key directory even operational in 2012? What about revocation checking? I think processing that information is mandatory now, but probably was optional/largely unimplemented in 2012. But maybe I'm off by five years or so?
- lxgr 17d agoRevocation checking seems like a big gap, yeah. I’m not aware of any public revocation lists (but I’m also not super familiar with the industry), so I can only assume (hope?) that there are some shadowy but highly accurate databases that KYC providers are tapping into. The CA public key I just got off my country’s website, they were kind enough to just publish it :)
- crote 18d agoCounterpoint: all of the identity-verification flows I have experienced in the last few years used NFC to read the chip in my identity documents - from car rental apps to my bank doing KYC. If anything, verifying NFC is easier than images. Asking the chip in my identity card to provide a cryptographically-signed "This document belongs to Jane Doe" request is a handful of lines of code. Doing the same with images? Good luck coming up with an approach which isn't fooled by a photocopy!
- JumpCrisscross 18d agoCool! Where are you geographically? I’m mostly in North America, Europe and South Asia.
- microtonal 17d agoMy credit card company’s app (in Europe) reads my ID through NFC when logging in for the first time (besides requiring ID photos). Our national app for logging into government sites and confirming things also requires a step where the ID’s NFC is read to reach the highest trust level. So it’s definitely becoming more and more common here.
- tmp10423288442 18d agoThere are tons of online services that require you to take pictures of your face, driver’s licenses, passports, etc.
- happyopossum 18d agoHow exactly am I expected to upload my nfc chip to my insurance company’s website?
- lxgr 18d agoThey just have you tap your identity document against your phone. Works pretty well in my experience. The phone is just a relay to a remote server here, as newer ICAO machine readable travel documents intentionally don't support signatures/non-repudiation anymore, so you have to run the entire exchange against a component you trust (i.e. your server, not so much your app on a rooted/manipulated phone).