Live data from Hacker News

Privacy-preserving features in the Mobile Driving License

security.googleblog.com

1–10 of 79 posts

Re: Privacy-preserving features in the Mobile Driving License

#3
I like this idea in theory, but... I wonder if the mDL apps can be generic enough that you can implement one and load a credential from any issuer into it, or if it's going to be a single (probably proprietary) app per issuer.

This is something I'd like to be able to use on non-Android and iOS platforms, but that's unlikely if it's not possible for anyone but the issuer to write an mDL app.

Re: Privacy-preserving features in the Mobile Driving License

#4
" For additional protection, mDL apps will have the option of both requiring user authentication before releasing data and then immediately placing the phone in lockdown mode, to ensure that if the verifier takes the device they cannot easily get information from it."

That's an interesting feature. I wonder if it's going to result in pressure from law enforcement to unlock the device.

Re: Privacy-preserving features in the Mobile Driving License

#5
> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do.

I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for.

The place where I do think this is valuable is when showing ID to get into a bar, or at a store when purchasing alcohol. The only bit of info the bouncer/cashier needs is whether or not you are of legal drinking age; they don't need to know your actual age/birthday or your name or address.

Re: Privacy-preserving features in the Mobile Driving License

#8
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

>I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for.

It's not supposed to be a foolproof solution. The point is to prevent the officer from casually looking through your photos/texts after you gave him the phone.

Re: Privacy-preserving features in the Mobile Driving License

#9
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

A pretty common way to get a fake id is to borrow a real id from someone else. Bouncers ask you how old you are or what your house number is as a check on that.

That seems like a plausibly useful feature, or are there other ways to tell that the virtual id matches the real person holding the phone?

Re: Privacy-preserving features in the Mobile Driving License

#10
And DMV will get, by default, all our contacts, location history 24/7, installed app list, clipboard texts, what more? But of course we as developers will be the first to deny because we know how to disable most of that. And 10 years from now, Facebook will upload everybody’s license by mistake, oops. But by that time, DMV will already be selling everything for a couple of dollars. And everybody will say well, nothing illegal was done. But of course, downvote me, everything I’ve said is speculation and we are so smart that we’ll never let that happen
Post reply on HN