Live data from Hacker News

Google Is Bringing Electronic IDs to Android

venturebeat.com

61–70 of 77 posts

Re: Google Is Bringing Electronic IDs to Android

#61

Earlier quoted context omitted.

There is no easy way. What is an important distinction, since there exist situations when even hard to follow procedures are better than a centralized option. Those are just not your daily "how do I know if I can show you my credit card" situations.

There's no cryptographically secure way as far as I'm aware.

You do get in front of the other person and exchange public keys. Or you ask for help from a set of trusted middle-man. Those are perfectly fine ways to run a PKI, they are just not fit for the "entire web" PKI.

Re: Google Is Bringing Electronic IDs to Android

#62

Earlier quoted context omitted.

There's no cryptographically secure way as far as I'm aware.

You do get in front of the other person and exchange public keys. Or you ask for help from a set of trusted middle-man. Those are perfectly fine ways to run a PKI, they are just not fit for the "entire web" PKI.

Those methods really don't scale by the fact that we haven't had a single system like that catch any popularity. It's usually just too cumbersome and not more trustworthy.

Re: Google Is Bringing Electronic IDs to Android

#63

Earlier quoted context omitted.

> they keep pushing this "identity theft" narrative to make it seem like the unlucky victims of bank's incompetence have some sort of intrinsic involvement! But how is it that it's not really a problem in Estonia, where we have strongly e-identity attached to a citizen. Or are you saying our banks, institutions, telecom and other companies are somehow more competent? You also have SSNs which is a government-mandated…

> But how is it that it's not really a problem in Estonia, where we have strongly e-identity attached to a citizen I have no idea how your dispute process looks in Estonia. What happens if you lose your national ID card, don't realize it for a week, and someone has used it to do a bunch of things in your name? The sensible answer is that anything unauthorized should be rolled back or otherwise not attributed to you.…

> What happens if you lose your national ID card, don't realize it for a week, and someone has used it to do a bunch of things in your name?

If you were stupid enough to attach the PIN codes to the card then you're liable for anything done with it by law. Dispute process is trough the court system.

> so I certainly wasn't trying to be "holier-than-thou" in some kind of nationalist cheerleading.

Then I take back my passive aggressiveness.

> The USian political philosophy discourages any sensible regulations that would reign this in

Right now maybe, but who knows what'll happen in ten years.

> In Estonia, how would you deal with a supermarket deciding to make it so that customers wanting a sale discount card have to link their national ID?

It is already being done - national ID as loyalty program. Though it is not considered an issue because both card payments and loyalty programs already have all the same information - except the unique personal identification number which isn't considered a secret (composed of public data). There's also the national and EU privacy laws that give one the right to be forgotten.

Re: Google Is Bringing Electronic IDs to Android

#64

Earlier quoted context omitted.

It's not a real thing. Nobody is pro voter fraud. Nobody is in favor of non US citizens voting in US elections. They are against voter disinfranchisement. The problem is that the IDs can be made harder for some to get than others. See momocasa's post here: https://news.ycombinator.com/item?id=19879722

I think there probably are people that want to enfranchise mere residents. It doesn't seem to be catastrophic for New Zealand, for instance. There's a strong argument to be made that people participating in the economy and other parts of civic life deserve to have a voice in politics. It's convenient and popular to exclude them, that doesn't make it just. (I phrase my first paragraph the way I do because I haven't th…

I'm sure there are some, perhaps I was too colloquial when I said nobody, but there is no widespread movement to give non-citizens the ability to vote in US elections. My main point is that opposition to voter ID wouldn't have much to do with that because that's not how voter registration works in the US. The post I had responded to was a mischaracterization of the reasons people are opposed to voter IDs.

On the topic of residents voting, a city near me had a policy+budget allocation vote that allowed anyone who lived there and was over 13. My opinion on that is that I think that's pretty neat at a city level, but I don't think it makes sense to allow non citizens to vote in a federal election.

Re: Google Is Bringing Electronic IDs to Android

#65

Earlier quoted context omitted.

There's no way to do one-to-one identity verification and authentication without centralized coordination and control. Just as an example, even if we really wanted to there'd be now way to let only one CA issue a certificate for a domain if any of the CAs is rogue.

There is no easy way. What is an important distinction, since there exist situations when even hard to follow procedures are better than a centralized option. Those are just not your daily "how do I know if I can show you my credit card" situations.

> even hard to follow procedures are better than a centralized option

Sorry, I don't have nearly enough information to accept that.

Re: Google Is Bringing Electronic IDs to Android

#66

Earlier quoted context omitted.

You can use the app store without setting up payments.

You can't use the app store meaningfully without setting up payments.

Downloading free apps isn't meaningful?

Re: Google Is Bringing Electronic IDs to Android

#67
post #40

Earlier quoted context omitted.

I would say, let Google develops the tech and figures out where are the blocking points, and then it could eventually become a standard and be implemented by other actors. About making the technology reliable and secure, I do trust Google more than my bank.

Banks are the worst but they are in the game for centuries and there are thousands of laws and jurisprudence for banks. And mark my words, laws will be too little, too late. We need to stop the "move fast and break things" now, we should put ethics side by side with "because we can" otherwise people will suffer the.consequences

[deleted]

Re: Google Is Bringing Electronic IDs to Android

#68
post #40

Earlier quoted context omitted.

I would say, let Google develops the tech and figures out where are the blocking points, and then it could eventually become a standard and be implemented by other actors. About making the technology reliable and secure, I do trust Google more than my bank.

Banks are the worst but they are in the game for centuries and there are thousands of laws and jurisprudence for banks. And mark my words, laws will be too little, too late. We need to stop the "move fast and break things" now, we should put ethics side by side with "because we can" otherwise people will suffer the.consequences

> We need to stop the "move fast and break things" now,

I understand your concerns, but I believe we should upgrade the Democratic system to give people more direct and more often opportunities to change the law rather than slow down technology progression

Re: Google Is Bringing Electronic IDs to Android

#70
I get that Google is very powerful and it lives off of our data and I get how this may be construed as an attack on our privacy but the amount of misinformation and conspiracy theories I am seeing on this thread is appalling. First, Google is just implementing an electronic ID standard that will work as a replacement for traditional paper ID cards. They are also working on a mechanism to display the ID card even when the phone doesn't have enough power to boot.

I don't get the concerns about it being mandatory because you can't expect everyone to have the same set of IDs and besides it's just a convenience feature like storing our membership cards or our emergency contact information in a wallet.

There is justifiable concern over the privacy aspect as we don't know if the IDs are stored locally on the device or if it's synced to the cloud. It will be troubling if it's the latter but criticising Google about this even before the feature has been finalized and released seems perplexing to me.

Post reply on HN