5 ms·
Keys Not Included: recovering the signing keys for US driver's license barcodes
- jmathai 15d agoI come to HN to learn things I never realized I wanted to know.
- simoncion 15d agoAt the time of this writing, the subtitle of the submission here on HN is recovering the signing keys for US driver's license barcodes Notably, this subtitle doesn't appear on the blog post. Anyway. I only see claims that the public key can be determined from license barcodes, not that a signing key can be determined. What am I missing or misunderstanding? To head off one potential retort: While it's true that one can use a public key to encrypt data for the recipient that has the private half of that key or verify that data has been signed by the possessor of the private half of that key, I'm almost 100% certain that it's not possible to use that public key to sign data would validate to other folks as being signed by the private half of that key. It has been more than a decade since I've thought about any of this, but isn't the entire point of public-key cryptography that the public part can be distributed to your worst enemy without causing you any trouble at all?
- trollbridge 15d agoYes. The subtitle is wrong. He recovers the public key, due to the way EDCSA signing works.
- kccqzy 15d agoYup. The person who submitted this to HN is probably way less knowledgeable on this topic than the writer of the article. The article clearly labels the recovered keys as “recovered public keys” at the top.
- otterley 15d agoGiven the poster's nickname, the person who posted it and the author may be one and the same.
- kccqzy 15d agoI think the author is Claude.
- antonvs 15d ago[dead]
- occams_chainsaw 15d agothe first part of the article was interesting, but I couldn't finish it because it reads so heavily in claude's 'voice'
- piratejon 15d agoThat's really neat! Seems potentially adaptable to paper currency--a verifiable QR code digital signature of the bill's serial number creates a cryptographically hard obstacle to counterfeiting!
- kqp 15d agoCopy known good serial number + signature.
- teravor 15d agocombine with a central authority server network and make it blind signatures and you have untraceable e-cash.
- mitxela 15d agoNo government wants untraceable e-cash. They want it fully traceable.
- teravor 15d agoit would depend on the government and the situation. I suspect most don't realize this is possible. a small government can generate immediate demand for their currency doing this.
- lxgr 15d agoThe original e-cash paper is from 1983. Governments absolutely know this is possible. It's just much "too private" to get any political traction. At the very least, I suspect an acceptable modern alternative would either have caps on what can be sent/received completely anonymously (e.g. per recipient and timespan) or want non-anonymous recipients (to allow for VAT/sales tax accounting etc.)
- lxgr 15d agoBlind signatures don’t work like that. Once you unblind them, they are very traceable. Chaumian e-cash can only be spent once for that reason.
- KingMachiavelli 15d agoAll of this is nearly pointless unless the photo itself is in the barcode and also signed. You only need a leak of a few hundred real IDs to cover all of the identifiable characteristics (hair, eye, skin color, approx height and weight). Leak a few hundred thousand a year and now you can’t even flag leaked IDs without some false positives. A fake photo plus a valid barcode will pass any current check right? Unless you still do a secondary proprietary photo lookup that I don’t think exists.
- kccqzy 15d agoI wonder if we might have the equivalent of Certificate Revocation List for IDs leaked this way.
- crote 15d agoAnd it's a classic case of Not Invented Here as well: this problem was solved decades ago and the solution is widely-deployed in passports and most European identity documents - just use NFC! Cryptographic NFC chips are basically free these days, and any modern smartphone can read them. The photo issue is solved by having the chip contain a copy of the photo, as a few extra kilobytes of data isn't an issue when you aren't using barcodes. The copy issue is solved by having the chip sign a verifier-provided nonce together with the data, and having the government sign the chip's public key instead.
- lxgr 15d agoBiometric passports, including US ones, have supported the same protocol for decades at this point.
- lxgr 15d agoThe Austrian ID card does that. It’s a really blurry black-and-white photo only, but it’s still recognizable and I find it quite impressive that any type of photo (in addition to its public key signature) can fit into a QR code at all.
- miki123211 15d ago
- RockRobotRock 15d agoI had a fake ID, and it being scannable was a huge selling point. Convenience stores all scan, and don't seem to care if you look underage. I was only turned down two or three times, usually at bars and restaurants.
- NDlurker 15d agoThe other thing I remember was California fakes folding in half and not breaking
- RockRobotRock 15d ago[dead]
- wildzzz 15d agoThe flex of the plastic is always a good way to check. Although I've held a fake NY ID and a legit one at the same time and could not tell any difference. Even did a double blind test.
- CSSer 15d agoWeirdly when I first got my California DL I thought it felt fake compared to my home state because it was so much thinner. Maybe it’s better for the environment.
- anon_cow1111 15d agoThe first thing I do with a real ID is widen the reference bars on the sides so the checkout scanner can't read it. If they want my birthday they can type it in manually, I don't need all my info in some store database.
- anon291 15d agoDefacing a photo Id(driver's license or passport) is technically a crime.
- bzmrgonz 15d agoIt baffles that people think it's a bad thing to disclose a public key. That's their purpose actually. Sure we now have the post quantum computer threat, and some state actors are harvesting keys, but quantum computer is going to disrupt so much, that Id verification won't even matter really.
- what 15d agoWhere did you get the impression the author thinks it’s a bad thing? From the article: > These are public keys, which are meant to be published - recovering one lets anyone check a signature, not forge one.
- isomorphic 15d agoI think GP and TFA mean that some of the states are afraid of public-key disclosure.
- prophesi 15d agoTFA is a bit obtuse about it, and assumes you've read their previous article on the topic, but from what I gathered, it's about whether the AAMVA would standardize cryptographically signing the barcodes of driver licenses to mitigate creating fakes in the US/CA. Cali showed it's entirely possible, but there's still no pressure for the standard to change across the board.
- cuoder 15d agoits even called "public" lol
- morsch 15d agoThink about it, the key analogy is just terrible. In the origin domain, losing a key is always bad, and making a key available to all is a non sequitur. It's not like non-technical people understand asymmetric cryptography. Or even technical people, for that matter. Maybe we should refer to the public key as an address, and the private key is just a password again. You can send stuff, securely, to an address. And you can verify the sender when you have their address (ie check the signature).
- EPWN3D 15d ago> Before signing, the encoder fills the field with a placeholder (0), repeated for the field's exact length - signs the entire payload including that placeholder, and then writes the real signature over the top of it. To verify, you put the placeholder back. I hate shit like this. Do not let your crypto layer know about the structure of what it's signing. Keep security stupid.
- lazide 15d agoCounterpoint - every real world crypto algo needs to do somewhat content aware padding or the crypto is much easier to break. Either that, or go so overboard on randomness that it adds a lot of overhead. When you look at the details underneath more crypto, there is a lot of ah hah - and ‘doh’ - moments due to implementation realities.
- woodruffw 15d agoAs far as compact encodings go, this kind of patch-and-fill technique isn't particularly egregious. The alternative mentioned (where the verifier has to be aware of a bitfield that defines the to-be-signed elements) is much easier to mess up!
- samlinnfer 15d ago[dead]
- foresto 15d agohttps://web.archive.org/web/20260917035309/https://ryan.science/blog/keys-not-included https://web.archive.org/web/20260917035309/https://ryan.scie...
- jsejcksn 15d agoRyan: The style of your blog is easy to read except for the pixelated monospace font. Thanks for sharing this post!
- Ryan5453 15d agoThank you! Just updated it to use the the browser default monospace for inline text.
- kccqzy 15d agoI loved that pixelated mono space font. It’s a personal site; the author is allowed to have some whimsical elements and not conform to your readability standards. You can always change the font yourself in the browser.
- davemultifactor 15d agothis is cool
- samsullivan 15d agoShould credit the authors of the Verifiable Credential library. The vendor isnt the one to credit here. Digital verification is going to matter a lot more for objects we own rather than the objects that proxy for that (currently the main function of an ID). Identity fraud is only problematic because ownership is tied to a loose record of SIN/DL. Having a physical medium represent ownership just shifts the burden to the state and allows for social engineering and fraud to persist.
- domh 15d agoThis is such a better design than whatever the UK is trying to do[1]. Why make a 3rd party app a requirement for this? I will never install such an app, especially one not made by the government itself. [1]: https://www.dailystar.co.uk/news/latest-news/digital-id-update-burnhams-government-37663221 https://www.dailystar.co.uk/news/latest-news/digital-id-upda...
- harvey9 15d agoLooks like the criteria were 1. No cost to the government/taxpayer. 2. Minimal work for the civil service.
- domh 15d agoYeah it's tragic. Short sighted and less secure. I don't think the politicians understand the risks involved of normalising uploading your ID to 3rd parties. I've tried emailing my MP but it falls on deaf ears.
- dmurray 15d agoThis is a great investigation but I have two small nits: > the ZNB field is not empty and not garbage: it contains a well-formed 71-byte DER ECDSA signature, correctly Ascii85-encoded, with the right prefix and a plausible length. But it fails the cryptographic check instantly, because it was signed with somebody else's key. Seems doubtful! I expect the forgers used a real signature from another card instead, so it has the right key but the wrong data. Reverse engineering the process as the author did and making up their own key wouldn't be of any value to the forgers. > I built a little demo to check the signatures across California, New York, and Virginia: take a picture of the barcode and check it here. This is not wrong, but should come with a little warning. A real verifier needs to additionally check the encoded data matches the human-readable data on the front of the card.
- crote 15d ago> A real verifier needs to additionally check the encoded data matches the human-readable data on the front of the card. I mean, not really? Only the machine-readable part is signed, so it should be treated as the sole source of truth. Besides, only an idiot forger would put different data in the human-readable part - it would be the easiest way to get caught!
- dmurray 15d agoBut if the forger claims his name is John Smith (or his date of birth is xx/xx/2004) he will edit the human-readable part. If he pairs the edited human-readable part with a real barcode copied from a real license in someone else's name, then anyone inspecting the license will see the documentation matches his claim, and if they also use this site to check for fake barcodes it will confirm the barcode was really issued by the California DMV.
- gmueckl 15d agoIt depends entirely on the purpose of the forgery. Some grocery stores do ID checks by looking at the front of the ID. Others just run the ID across a scanner and the employees are so rushed they don't read it or check the picture. Similar things happen e.g. at bars or casinos. Incomplete forgeries can get you far enough under the right circumstances.
- bob1029 15d agoI think mDL is going to be a pretty big deal in some industries (e.g. banking). Apple announced an ecosystem around this at WWDC25. Very soon we are going to be in a world where you walk into a bank to open/maintain an account and the following occurs: 1. The bank emails/SMSes the customer a link 2. The customer takes out their iPhone, opens whatever email/messaging software & taps the link 3. The link takes the customer to a specially crafted page owned by the bank that triggers a native OS process for opening Apple Wallet and gathering requested ID details with consent. https://developer.apple.com/videos/play/wwdc2025/232 https://developer.apple.com/videos/play/wwdc2025/232 https://www.w3.org/TR/digital-credentials https://www.w3.org/TR/digital-credentials This is potentially a superior arrangement because it could eventually establish a strong cryptographic chain of trust all the way to the issuer (e.g. the State of Alabama). Right now there are some gaps in that chain but I see no reason they couldn't be closed over time.
- ds_opseeker 15d ago> there are some gaps in that chain for example, a reliance on apple wallet, instead of an open standard. With that quibble aside, I do like the basic structure of your solution.
- bux93 15d agoWalk into bank? The last time I opened a bank account (2023), I tapped my driver's license to my phone, it got my details+photo via NFC, I took a "liveness check" video and was onboarded. This has been the workflow for many years now for consumer account openings, or installing a banking app on a new phone. I think bunq did it first around 2017. As soon as (EUDI) wallets are more standardized, both neobanks and high streets banks will adopt that too.
- vel0city 15d ago> Very soon we are going to be in a world where you walk into a bank to open/maintain an account I've never in my life walked into a bank to open a bank account. I've got accounts with many different banks these days. Real banks and credit unions, not fake neo banks. The only times I've ever been in a bank was to get large denomination ($100s) currency, as most ATMs around me don't dispense those. And most of the time I didn't even bother going into a bank I had an account with, most will let you get cash for free with a debit card even if you don't normally do business with them.
- sneak 15d agoSo a private company sees a full set of PII for people in more than half of the states, with no opt out bc everyone MUST have a state ID to function. Time for a federal law banning the DMVs from outsourcing this stuff (or selling the bulk data like they do to insurers).
- deleted 15d ago[deleted]
- clarkevans 15d agoColloquially, we could say: States now issue drivers licenses cards having both a readable number and an authentication code; the state could provide a way for the public to check if the drivers license is true by verifying the authentication code, but they don't provide this service. .. When discussing asymmetric cryptography with less technical folk, a lock analogy breaks down quickly as locks are conceptualized as being symmetric. Hence, "key" is a poor word that came from symmetric cryptography; one really needs to discuss the signature or authentication code. A better analogy may be a transparent display case, where only authorized people can put things into the case. To check a copy outside the case is true, one would want to go to the official display case and compare. This isn't a great analogy because there's no analog to the signature, but it gets the asymmetry across. Perhaps we might do a bit better? Suppose your friend gave you a poster copy of a famous painting from the Metropolitan Museum. On the poster is the curatorial accession number. You could go to the MET and check if your poster matches the painting, which should have matching accession number on the label. So far our analogy covers asymmetry but is still centralized. The museum also distributes a catalog of its posters/paintings. Catalog entries have a thumb print of the painting and its accession number. So, if you could find a trusted copy of that catalog, say at your local library, you might also use this to check the painting's authenticity without having to travel to the museum. Alas, this analogy fails since the whole catalog need not be shared (just the public key). These analogies are still problematic. This is an involved and novel cryptographic process, and for the interested policy maker or their trusted advisors, it's probably much better if we teach the real process with worked examples.
- Retr0id 15d agoThe analogy is right there in the name: Signatures. But rather than identifying forgeries by inspecting the handwriting details and ink pigments or whatever, we have math.
- oriettaxx 15d ago[flagged]
- deleted 15d ago[deleted]
- waltbosz 15d agoI didn't realize that "over the counter" delivery of drivers licenses was not the normal method. When I get a new driver's license at the DMV, I go to a self serve kiosk, have my picture taken, then walk over to a room and my license is already printed by the time I get there. They have 3 massive card printers (imagine a laser printer, but 6 ft/182.88 cm long). It event prints a pseudo-hologram. I have to surrender my old license to the person in the room. How does that work if your license is mailed to you? Do you get to keep the old one? (Delaware)
- Feathercrown 15d agoI got a temporary license and received the real one in the mail later. Yes, you can keep the old one.
- waltbosz 15d agoWhat's the temporary license printed on? Standard paper? My licenses have always been printed on a plastic card, but I remember seeing older licenses that were basically laminated photo paper.
- DaSHacka 14d agoIn the states I've lived in, its a piece of paper you keep in your wallet alongside your previous DL/permit that's now been hole-punched. You use both together to serve as your proof of authority to drive if you get pulled over. Of course, only until the real DL arrives in the mail, which usually takes a week or two.
- thaeli 15d agoHow it works in my state: For in person renewals/changes, they punch VOID into your old license, give it back to you, and give you a temporary license printout. Then your new license is mailed a couple weeks later. For remote renewals/replacements, they just give you a temporary license to print out and then mail you a new one. The old license never gets physically cancelled.
- 15d ago
- dog22212 15d agoThis post is uninformative and stupid. In fact it was a waste of my time. I bet the person who wrote it is lame and probably really likes trains. He probably likes trains a whole lot i bet. Anyways, thanks for nothing. dog signing out. -dog22212
- daft_pink 15d agoMaybe we should create petitions for each of the 31 states covered by IDEMIA and all the states covered by Canadian Bank Note to add this to the ID cards. I can't imagine Illinois, where I live that I believe uses IDEMIA from what I know about the Apple Wallet rollout wouldn't want to add this.
- yencabulator 15d ago> how to use the DMV's public key to check whether a California ID is real. That's not what the signature guarantees, though. It says the combination of textual information on the card is *someone's* valid driver's license. The signature doesn't even cover the photo! It just limits the forgeries to using identities of real people. Compare to https://en.wikipedia.org/wiki/Biometric_passport https://en.wikipedia.org/wiki/Biometric_passport that actually contains a digital photo, with a signature.
- returningfory2 15d agoIIUC, the forgery path then involves getting any legitimate California license and changing the photo only? I guess that works.
- yencabulator 15d agoThe forgery path is downloading the leaked database of 153 million driver's license images, picking one with the right gender, rough age, weight and height, and printing a card with that text+barcode and your photo.
- happyopossum 15d ago> The signature doesn't even cover the photo! Which makes sense, as the signature is for the barcode data...