Live data from Hacker News

Privacy-preserving features in the Mobile Driving License

security.googleblog.com

21–30 of 79 posts

Re: Privacy-preserving features in the Mobile Driving License

#21
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

But it will be bar policy to have your name/address/email info or their reader won’t authenticate you.

Re: Privacy-preserving features in the Mobile Driving License

#24
post #18

It will be interesting to see how teenagers hack this to fake the "are you over 21 signal?" in order to get alcohol while underage.

They can use someone else's phone/smartwatch.

The image would still need to match

Re: Privacy-preserving features in the Mobile Driving License

#25

This is horrible, it should remain a card. Why should a cell phone, or any technological device now be required for participation in society or to validate yourself to any government official? At that point, where do you draw the line of privacy? You're carrying with you an object that you can't trust 100% and can work against you anytime. This is truly chilling dystopian type stuff. Soon a cell phone will be require…

But why? Why do people have to carry a wallet everywhere, unless they want to?

I have my payment cards on my watch. Pre-pandemic, my gym membership card was on my watch. If I had my ID on my watch as well, I don't ever have to worry about a wallet being stolen because I wouldn't carry one.

Sure, people can steal your watch at gunpoint- but it can be remotely disabled (even if you were forced to give your passcode under duress), and you'd still have a physical ID card at home you can use.

Re: Privacy-preserving features in the Mobile Driving License

#26
No. Nope. No. No. No. There's nothing wrong with plastic card drivers' licenses. Don't fuck up and complicate a system that already works perfectly.

I don't want my identity in society controlled by a fucking Google app. I don't know when they'll lock me out. I don't know if I'll always have a working, charged smartphone on me. I don't see a single advantage to this approach.

Re: Privacy-preserving features in the Mobile Driving License

#27

This is horrible, it should remain a card. Why should a cell phone, or any technological device now be required for participation in society or to validate yourself to any government official? At that point, where do you draw the line of privacy? You're carrying with you an object that you can't trust 100% and can work against you anytime. This is truly chilling dystopian type stuff. Soon a cell phone will be require…

Yes, I think so too. I am professionally a SWE but more and more I feel like a Luddite, and more and more distant from the predominant HN demographic.

Re: Privacy-preserving features in the Mobile Driving License

#28

Earlier quoted context omitted.

They can use someone else's phone/smartwatch.

The image would still need to match

A rather common joke that I've seen on social media and also have personally witnessed in real life is that within the US, the person making the comparison is of one race and has difficulty accurately comparing a person of a different race with the picture supposedly of that person.

Consequently, two people who don't really look alike can essentially share the same ID card as the person doing the comparing doesn't want to invite accusations of racism.

Re: Privacy-preserving features in the Mobile Driving License

#29

What a stupid idea. After a weekend in nature, you now have to worry, you phone still has power to drive a car. And more stupid, hand over my phone unlocked to the police or to everybody who wanna see the license. More worse, until now, they just checked and it was ok. From now an, everybody is always saved after that in a DB. And why is that more secure? If you cheated until know and showed a false ID, so you show n…

> so you show now just a false phone

You'd be sending a message cryptographically signed by the government to someone else's device, so it doesn't matter what's on your screen—if you can't produce that signed message, you can't do anything.

Re: Privacy-preserving features in the Mobile Driving License

#30
This reads a lot like simply another way to tie users up into a smartphone specific Eco-system, not to mention the privacy implications.

There is a much better approach that doesn't have the privacy problems that the proposed solution has: https://certisfy.com

Use good old PKI with the verification process for generating certificates delegated to suitable third-parties.

Post reply on HN