Live data from Hacker News

Privacy-preserving features in the Mobile Driving License

security.googleblog.com

11–20 of 79 posts

Re: Privacy-preserving features in the Mobile Driving License

#12
This is horrible, it should remain a card. Why should a cell phone, or any technological device now be required for participation in society or to validate yourself to any government official?

At that point, where do you draw the line of privacy? You're carrying with you an object that you can't trust 100% and can work against you anytime.

This is truly chilling dystopian type stuff. Soon a cell phone will be required for every "person."

Re: Privacy-preserving features in the Mobile Driving License

#13
> In both cases, the verifier manually compares the appearance of the individual against a portrait photo, either printed on the plastic or transmitted electronically

So now I have to put my image in the store's database too? Way more invasive than plastic card, which doesn't electronically transmit my image.

Re: Privacy-preserving features in the Mobile Driving License

#14
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

Until the bouncer (or the bar's contracted developer) thinks it's easier or more secure to use the "Request all data" feature, and logs everything to an unprotected MySQL database. When a bouncer looks at your ID he doesn't write down or save any of that information. This really seems like a solution looking for a problem.

Re: Privacy-preserving features in the Mobile Driving License

#15

This is a very US-centric approach to set a standard for having your ID on your phone. Why not calling it simply Mobile ID and having the driver license as one of the data records or features? That would be more natural design.

It's an ISO standard for a driver's license and the US isn't the only party involved in it (although it may be unique in that it plays the role of a national ID there).

Re: Privacy-preserving features in the Mobile Driving License

#16
What a stupid idea. After a weekend in nature, you now have to worry, you phone still has power to drive a car. And more stupid, hand over my phone unlocked to the police or to everybody who wanna see the license. More worse, until now, they just checked and it was ok. From now an, everybody is always saved after that in a DB. And why is that more secure? If you cheated until know and showed a false ID, so you show now just a false phone.

Re: Privacy-preserving features in the Mobile Driving License

#20
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

The barcode at the back of a physical license card has all sorts of information that may not be printed at the front. For example, for noncitizens in the US it can have some information about visa status.

If there is a standard (name, DOB, photo, address, height, weight) that's probably more than enough.

Post reply on HN