Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

141–150 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#141
post #72

Earlier quoted context omitted.

> Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C. But they didn't. These people aren't that dumb, they told companies to settle on a standard, and now that we have a good standard that basically everyone follows they want to make a law to ensure everybody follows it. Bringing up a scenario where they did the right thing and argue "just imagine i…

It is the standard now, but should it be the standard forever? What happens when we want better features as new tech is invented?

> What happens when we want better features as new tech is invented?

The new tech would prove itself, somehow, and then the standard changed over after there's evidence that the new tech improves more than the cost of the change!

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#142
post #141

Earlier quoted context omitted.

It is the standard now, but should it be the standard forever? What happens when we want better features as new tech is invented?

> What happens when we want better features as new tech is invented? The new tech would prove itself, somehow, and then the standard changed over after there's evidence that the new tech improves more than the cost of the change!

How would a new tech prove itself if manufacturers aren’t allowed to use it in their product? If customers aren’t allowed to try something new, they are never going to be able to determine if customers prefer it.

The only way to ‘prove’ that a tech is better than another is by letting the market decide.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#143

Earlier quoted context omitted.

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

> A proper online identity framework is long due though [..] You're entitled to your opinion but for me, it's a firm "No, thanks". I feel considerably more comfortable* carrying a paper document which proves my vaccination/negative test than I do using any kind of government-approved app on my phone. * that's putting it mildly

You should be comfortable with carrying and using a document certifying a test result, but not with a document proving vaccination. The first is reasonable to due to its obvious utility in infection control, the second is not; it is now become a tool for sowing division and hatred in society.

If you care about limiting infections, get tested.

If you care about freedom, reject government certificates.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#144

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

> why do we need biometric level proofs for that?

There's generally two buckets of biometric auth:

1. Local biometric auth, with no metrics shared outside the local context, for convenience in authentication. This would be FaceID/TouchID/Windows Hello sorts of functions

2. Remote biometric auth to prevent certain types of 'friendly' impersonation, such as using a family member's identity for an age or background or credit check. This is say comparing a live camera capture against a previous photo.

You see #2 a lot in identity proofing, e.g. I presented an official document and it is legitimate, but how do they know it's actually the right person vs someone who did some lucky dumpster diving?

For digital identity credential systems which represent those documents, you have both cryptographic document verification and typically have a form of authentication by proof-of-possession of some key, but often people still feel the need for a remote biometric check. The reality is that they should be basing that on an actual need.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#145
post #144

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

> why do we need biometric level proofs for that? There's generally two buckets of biometric auth: 1. Local biometric auth, with no metrics shared outside the local context, for convenience in authentication. This would be FaceID/TouchID/Windows Hello sorts of functions 2. Remote biometric auth to prevent certain types of 'friendly' impersonation, such as using a family member's identity for an age or background or c…

My point is there is no actual need, and all needs are contrived by policy for policy's sake, usually caused by security nerds (my people) whose rationale is identity because identity, and then we index on geeking out on writing security protocols without product use cases for the people subject to it.

The real problems in identity proofing are things like task delegation, substitute decision makers in elder care, parents doing things on behalf of their kids and kids asserting their parents permission, federation of user attributes with privacy, etc. These aren't difficult technical problems, except you need some way to transfer risk and accountability, which is an absolute quagmire. Universal digital identity (because let's face it, that's what it necessarily is) approaches these problems with a necessary component of a solution, but that's not what it's mainly going to be used for.

Maybe this yields a thought experiment where let's say I write an app for parents and kids where kids can use it to show they have their parents permission to be in a park after dark, walk to school by themselves, participation in a class trip, travel by themselves on a train or plane, get consent for emergency medical procedures, etc. Then that kid grows up and it switches from their parents to being a drivers license, age of majority card, school graduation certificates, their last STD test, list of employers and past salaries, speeding tickets, criminal records, lowest rated tweets, sexual partners etc. Sounds like it could be a real product right? Except that kid never wanted the stupid app that monitors them, the hovering parents who imposed it on them just use them as a source of narcisistic supply, and then their entire life is one of being subject to some proxy for these helicopter parents. The app is capitivity, or more accurately, entry into a panopticon that deprives them of their basic humanity. This is why digital identity is a terrible idea in pretty much every version I've seen so far. It's not chosen, it's imposed, and that's not a product, that's a mandate laundered through tech.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#146
post #8

This did get posted a few weeks ago at the time it was written but didn't get much traction at that point, yet seems like a reasonably important issue. The EU has done worthy things for issues like privacy, but whatever pluses and minuses of regulating personal and business policy I'm a lot more dubious about government sticking its hand directly into how specific software (like browsers) functions. That seems like a…

The EU has neither the authority nor the competency to lay out such identity frameworks and I would say they would decrease security in any case. This is again about surveillance and attempts to get control on information.

HTTPS basic auth is secure and should always be an option. There, perfect interop.

There is not enough trust and political currency to accept such measures in my opinion. Formalized ID systems seem to net more attack vectors than what we currently have.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#147

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

The one application I would see is that government would be in control of biometric information. Today a lot of people share such markers with companies. But many also do not do that and they should also not be forced to do the same with government. That the EU enforced biometric passports without any benefit is bad enough.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#148
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

We spend trillions on e-commerce with "normal" user accounts that worked just fine. Some cases of thefts and other crimes that doesn't warrant any action in my opinion. Meanwhile we have a huge problem with governmental surveillance, which is a worse crime than theft depending on how you grade it.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#149
post #91

Earlier quoted context omitted.

I think you touch on the issue. Having a standard for Identity Management seems reasonable. Mandating that such a state-regulated identity be used for all on-line data passing on the internet seems like a nightmare waiting to happen. That may not be the step in between "collect underpants" and "profit" but it feels like it's coming. In the U.S., I'm sure something like this will be sold in the clothing of think-of-th…

> Mandating that such a state-regulated identity be used for all on-line data passing on the internet seems like a nightmare waiting to happen. They didn't mandate that though, the proposal was that it should be possible to use it, not that everyone should be forced to use it. You would still be able to log in using other means. Basically, facebook would be required to provide you with the option to use e-id to log i…

Please, we know how that works. Youtube age filter? Will be mandated for anything controversial as soon as such a system is in place to protect the children. Meanwhile we spend trillions on e-commerce. There is crime, but nothing that warrants such an ID scheme.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#150
post #9

Earlier quoted context omitted.

Perhaps I'm out of the loop, but the EU attempting to make it illegal to distribute web browsers that don't include certain features is unexpected (and deeply worrying) to me.

They are protecting their interest Why should a foreign country have control over my interests? Why should Mozilla DECIDE what I should and shouldn't trust? I am very glad that the public opinion decided to not trust Firefox at all (3% market share today)

Why should the EU? Mozilla doesn't decide that, it gives you the option while suggesting a standard to make surfing the web feasible, but you can revoke that trust at any time. The EU wants to change that.
Post reply on HN