Live data from Hacker News

Privacy-preserving features in the Mobile Driving License

security.googleblog.com

41–50 of 79 posts

Re: Privacy-preserving features in the Mobile Driving License

#41
Are we seriously looking at the possibility of handing over control of government-issued driver licenses to a private for-profit entity whose main way of making money is by monetizing citizen data? For real? Like many others here, my immediate thought upon reading this was, "W.T.F.?"

Re: Privacy-preserving features in the Mobile Driving License

#42
post #35

Would there be any way for similar protections to come to digital auto insurance cards?

Why would you need that? Insurance cards have zero security on them anyways. There's no standard format for paper cards as is is. All I have ever had is a piece of paper that I ran off on my printer, and it says "EVIDENCE OF INSURANCE" in Times New Roman and lists off a bunch of crap that the police can't verify. Some states, having a card is pointless, because if you lose your policy, the state finds out and already…

In Hawaii, insurance cards are printed on special paper and must be mailed by your insurer. Printed PDFs or copies aren't accepted.

Re: Privacy-preserving features in the Mobile Driving License

#43
post #14
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

Until the bouncer (or the bar's contracted developer) thinks it's easier or more secure to use the "Request all data" feature, and logs everything to an unprotected MySQL database. When a bouncer looks at your ID he doesn't write down or save any of that information. This really seems like a solution looking for a problem.

Yes they do, bouncers now scan the IDs they look at with a machine.

Re: Privacy-preserving features in the Mobile Driving License

#44
In India this has been a thing for a while now. Just that it is provided by the central Govt itself - https://digilocker.gov.in.

You can keep many Govt issued IDs in there and those are all good to be accepted and treated as valid across the country - for example DL and vehicle ownership docs when checked by cops. You can keep some non Govt IDs as well e.g. insurance docs.

I do have some privacy/safety concerns but I'd trust my Govt (that issued most of these docs in the first place) more than a corporation who are known as a business with privacy invasion as their primary function - in fact almost anything they do revolves around this core idea.

Re: Privacy-preserving features in the Mobile Driving License

#45
post #14
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

Until the bouncer (or the bar's contracted developer) thinks it's easier or more secure to use the "Request all data" feature, and logs everything to an unprotected MySQL database. When a bouncer looks at your ID he doesn't write down or save any of that information. This really seems like a solution looking for a problem.

As a sibling mentioned, they already have ID barcode scanners in many bars, and then sell your data to marketing companies.

I think I'd be fine walking away from a bar that used this system to request everything, rather than just a simple "over 21?" verification question. There are plenty of bars out there and I don't have to patronize shitty ones.

Re: Privacy-preserving features in the Mobile Driving License

#46
post #40
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

As ID to get into a bar, I think minimally they'd need access to your photo too, to ensure you haven't just borrowed (or bought) a phone.

Fair, but that's fine and reasonable, I think. If I'm entering their establishment they're well within their rights to have cameras inside that can take my photo, so giving them access to my ID photo doesn't sound like a big deal to me.

Re: Privacy-preserving features in the Mobile Driving License

#47
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

A pretty common way to get a fake id is to borrow a real id from someone else. Bouncers ask you how old you are or what your house number is as a check on that. That seems like a plausibly useful feature, or are there other ways to tell that the virtual id matches the real person holding the phone?

Is this common, though? In my 18 years of legally entering bars, that has literally never happened to me, even when I was in my early 20s.

Re: Privacy-preserving features in the Mobile Driving License

#48
post #5

> Crucially, the mDL application can ask the user to approve which data to release and may require the user to authenticate with fingerprint or face — none of which a passive plastic card could ever do. I kinda feel like most people, when threatened by an authority figure with a gun, will approve whatever data that person asks for. The place where I do think this is valuable is when showing ID to get into a bar, or a…

But it will be bar policy to have your name/address/email info or their reader won’t authenticate you.

I'm perfectly happy not patronizing those establishments.

With the current system, I could easily believe that not all bars scan the barcode for a nefarious reason, but do it just to make it easier to avoid a bad manual reading (different ID layouts per state, darkness making it hard to read, etc.).

With this kind of digital ID, requesting anything more than my age and photo is an immediate flag to me that they're explicitly looking to do something shady (or at least they're incompetent and don't know how to use the reader properly). I would deny everything but the age and photo request, and if they balk, I'd ask to speak to a manager or just walk away.

Re: Privacy-preserving features in the Mobile Driving License

#49

What a stupid idea. After a weekend in nature, you now have to worry, you phone still has power to drive a car. And more stupid, hand over my phone unlocked to the police or to everybody who wanna see the license. More worse, until now, they just checked and it was ok. From now an, everybody is always saved after that in a DB. And why is that more secure? If you cheated until know and showed a false ID, so you show n…

> After a weekend in nature, you now have to worry, you phone still has power to drive a car

Who doesn't have a charging cable in their car for their phone?? Also if you're going to be in nature for a weekend, you can opt to carry your physical ID as a backup (or leave it in the car if you're comfortable with that).

> hand over my phone unlocked to the police or to everybody who wanna see the license.

The article covers this. You never hand over your phone; you send a grant to the other party's device to read only certain bits of information from the ID app. And the article mentions that the right way to implement it on the ID-holder's side is to require PIN/biometric unlock in order to approve the transfer, but then immediately go into a lockdown mode so if the LEO then takes your phone, it'll be locked.

> More worse, until now, they just checked and it was ok. From now an, everybody is always saved after that in a DB.

That already happens now; if you get pulled over, the cop isn't going to manually read your ID and copy it into their squad car's computer. They scan the barcode on the back and all of it gets sucked in. (Even many bars and convenience stores that sell alcohol will scan the barcode and get way more information than they need.)

> And why is that more secure? If you cheated until know and showed a false ID, so you show now just a false phone.

Sure, you can borrow someone else's phone, but presumably your photo won't match theirs. And if it's close enough, then yeah, you can probably get away with it. But just because something doesn't close all the loopholes, it doesn't mean it's not worthwhile. A discouragement for this particular thing is that the person you've borrowed the phone from will probably not want to give up their phone for an entire night!

Personally, I'm torn on this. If it really would allow me to selectively give only the bits of information from my ID that various parties actually need, that would be nice. But I worry more about how the ID data will be secured on whatever non-government third-party's backend this will inevitably be outsourced to.

Re: Privacy-preserving features in the Mobile Driving License

#50
post #37

What a stupid idea. After a weekend in nature, you now have to worry, you phone still has power to drive a car. And more stupid, hand over my phone unlocked to the police or to everybody who wanna see the license. More worse, until now, they just checked and it was ok. From now an, everybody is always saved after that in a DB. And why is that more secure? If you cheated until know and showed a false ID, so you show n…

The thing that kills me is the fact that if you are driving your own car, the police already know who you are and if you have a license when you get pulled over. The whole requirement to have a card on you is bogus bullshit, and only serves to make you a criminal if you happen to forget it. If you drive the car of a person who has a suspended license, you will get pulled over. Their ALPR system will automatically fla…

> The thing that kills me is the fact that if you are driving your own car, the police already know who you are and if you have a license when you get pulled over. The whole requirement to have a card on you is bogus bullshit, and only serves to make you a criminal if you happen to forget it.

It seems pretty common to loan a car to a friend, or to use a car registered to another family member, or to rent a car form either a traditional rental company or a service like Turo. In those instances they have no idea who you are.

> If you drive the car of a person who has a suspended license, you will get pulled over. Their ALPR system will automatically flag you, and the officer will tell you that he ran your plates and pulled you over because the owner has a suspended license.

I don't find that unreasonable at all. And that's a fine counterexample to your original complaint; in this case it's good that you have a license that you can produce to prove you're not the owner with the suspended license.

> BUT at the same time, if you know your DL number, or even your name and address, there's no reason the cops can't look you up to verify who you are.

There are all sorts of ways to defeat that. Perhaps you give your sibling's name and address, and your photos look close enough that you get away with it. And why would I bother to memorize my DL number? It's far easier to just carry the card.

These sorts of systems and processes are designed to avoid loopholes and make things more certain for the cop. Asking a cop to "just trust you" based on self-provided information also just begs them to decide based on their unconscious (or conscious) biases, which reduces justice for anyone who happens to be a member of an often-discriminated-against group. I think cops should try to be flexible and give people the benefit of the doubt when it's appropriate to do so, but deciding when that's the case isn't always easy, so I'd rather we just require people to carry their license with them when they drive. It's not hard, and if you're going to be assuming responsibility for a one-ton metal and plastic ballistic object traveling fast enough to kill, then you damn well can also take on the responsibility for carrying a physical license.

Regardless, out of all the things that the government does that's shady and reeks of wanting to control people's lives, requiring you to carry around a little card with you when you drive a car is not even in the top 100 for me.

Post reply on HN