4 ms·
The verification server won’t know what e-mail address or credit card statement you used in order to get the badge, only that it was created by a particular iss
by spindritf 12y ago
The verification server won’t know what e-mail address or credit card statement you used in order to get the badge, only that it was created by a particular issuer.
That's pretty clever but in case of serious leaks, and they do suggest it could be used by government employees, it doesn't provide much additional protection. Investigators will need two subpoenas/warrants instead of one.
Some verification services could simply not keep logs of what they verified, and documents they used. The problem here is that there is no way for the issuer to prove they really don't.
Heard is starting out by running one that verifies whether you’re a “tech industry insider” by checking to see if you have an email address from one of about 20 major technology companies.
Another problem is that your employer will know that you signed up for an anonymous gossip/leak site.
- hawk678 12y agoGetting the two subpoenas will not help you, because you cannot associate the information from the badge issuer with the information in the badge consumer. there is no link there at all.
- spindritf 12y agoThere is some cryptographic token. It should be a pretty strong link since otherwise the whole system unravels.
- klint 12y agoThat does seem to be the biggest limitation -- you have to trust that the issuer is running an unmodified version of the open source code. "Another problem is that your employer will know that you signed up for an anonymous gossip/leak site." Only if they check your email logs and see that a verification code was sent, which you could plausibly deny having requested. Of course, if you're the only person at your company to sign-up, and you're therefore the only one with one of those codes, that would obviously expose you.
- sophacles 12y agoVerification services can avoid some of the "your employer will know that you signed up for an anonymous gossip/leak site" problem by: 1. determine if it really is $Person by using personal verification independent of employer controlled email/sms/etc then 2. verifying $Person actually is employed in such a capacity. However, the log thing is a problem. As is the problem of "how do we know the verification services aren't just lying to us about $Person's identity/credentials"?