Live data from Hacker News

Tell HN: MitID, Denmark's digital ID, was down

news.ycombinator.com

101–110 of 194 posts

Re: Tell HN: MitID, Denmark's digital ID, was down

#101
post #85

Earlier quoted context omitted.

Is it in anyway worse when the money you had was some strips of paper, or metal coins, or goats, or salt? All of those have some very annoying fail scenarios too.

yeah, it's worse. Someone trips over a cable and now your region of the world can't recognise that you have any wealth of any kind. Or, you can get debanked by the state. :) Hard to do that with coinage- but you can have your coinage destroyed in a fire (or via theft, of course).

I respectfully disagree, but each with their own personal annoyances.

Strips of paper and metal coins have a huge problem with forgery. Metal coins in particular can get very heavy very quickly.

Goats have this issue that they can get sick and die. They also need to be fed. Goats have a massive advantage that while heavy, they can move around on their own. Not easily fractionable though.

Salt is probably the best one in that list. Easily fractionable, not easy to forge. Can be used as seasoning and to dry things. It can get wet though.

Re: Tell HN: MitID, Denmark's digital ID, was down

#102

Earlier quoted context omitted.

With Digital passports and ID's the route to recovery starts to get hairy. 1. You need to verify yourself in person to get id or passport. You may need someone you know with you and have real interview. 3. But government gives only digital ID's so you need a phone to get it. 4. You can't buy a new phone or get a new SIM unless you can pay for it. You can't pay for it unless you have a phone and credit cards there. Bu…

Does any government in the world issue only digital IDs? There‘s always possibility to have your travel passport as a backup (and when traveling abroad your domestic ID is suitable for recovering passport).

Not yet. Soon.

Re: Tell HN: MitID, Denmark's digital ID, was down

#103
post #47
post #28

Earlier quoted context omitted.

I don't understand. We don't have real time revocation for passports, do we? In fact, we don't have real time revocation of any document until very recently...

don't we? We call somewhere and revoke the Passport, atleast in Germany.

But does that propagate to every entity worldwide using passports for identification, including all non-government-affiliated companies and KYC providers?

Re: Tell HN: MitID, Denmark's digital ID, was down

#104

I'm a British expat with a Danish job. I really dislike MitID and the Danish centralised world of (very good) public services that come with it. Each person has a number, CPR, which effectively defines your life solely to the state. Visit a library, doctor, tax man, anything official, and your ID is recorded. Buy alcohol online, go grocery shopping, use your bank card -- and sign in with it. This undoubtedly makes th…

> but it's a privacy nightmare.

I've gone the other way from Denmark to UK. And I've often had to mail copies of my passport or other identity documents via email. And my bank requires me to regular scan my face to check that it aligns with the picture in my passport.

Re: Tell HN: MitID, Denmark's digital ID, was down

#105
post #50
post #17

Terrifying to live in a digital economy when something like this happens. You're usually about 1 service away from realising that the "money you have" is just an int32, that, if everything works properly, you can modify. Otherwise you have nothing except a pretty little plastic card. (I'm aware that payments systems are not affected, but it's a sobering realisation that I've had a couple of times, but it works enough…

> that the "money you have" is just an int32 well, luckily, that's not how money is stored, but instead, they're transaction based. Aka, that number you have is a calculated value, not a stored, arbitrary value. Except...perhaps the central bank's, where they could really just generate that money as an arbitrary value to lend out to other banks. footnote: of course, your account balance is cached, so that it is not r…

Seems like a distinction without difference in this context. The result of the "what is account x's current/available balance" is still some integer or decimal number.

Re: Tell HN: MitID, Denmark's digital ID, was down

#106

I'm a British expat with a Danish job. I really dislike MitID and the Danish centralised world of (very good) public services that come with it. Each person has a number, CPR, which effectively defines your life solely to the state. Visit a library, doctor, tax man, anything official, and your ID is recorded. Buy alcohol online, go grocery shopping, use your bank card -- and sign in with it. This undoubtedly makes th…

Italian living in Sweden, Malmö, and lived in the UK in the past.

I don't get the obsession you Brits have against IDs, in Europe you are pretty much the only ones. But a lot of what you say resonates with my observations:

- single point of failure: absolutely, but so is the "sign in with Google" or equivalent. It's just too convenient. I'd rather have a public service do it than a private company that can cut you out at any time without any explanation.

- Nanny State: 100% also in Sweden, actually worse here. But historically they have been pretty good at protecting freedoms, so far. The UK (or Italy) may be less nanny, but have got some very illiberal things going on these days (left or right government doesn't really matter, it seems).

- Happiest people on earth: I really doubt the surveys measure happiness. They tend to measure trust in institutions, which is very high in Scandinavia.

- It's an incredibly authoritarian society although no Dane would ever say that: exactly the same in Sweden! They would NEVER admit any failure in their society, no matter the hard evidence in front of their eyes. I guess that it's the other side of the same trust of the previous point.

- Drink more øl and get off the internet and go for a walk in a forest: At least you've got øl, in Sweden alcohol is taboo. Forests are nice, but become boring quite quickly :)

Re: Tell HN: MitID, Denmark's digital ID, was down

#107

I'm a British expat with a Danish job. I really dislike MitID and the Danish centralised world of (very good) public services that come with it. Each person has a number, CPR, which effectively defines your life solely to the state. Visit a library, doctor, tax man, anything official, and your ID is recorded. Buy alcohol online, go grocery shopping, use your bank card -- and sign in with it. This undoubtedly makes th…

> but it's a privacy nightmare. I've gone the other way from Denmark to UK. And I've often had to mail copies of my passport or other identity documents via email. And my bank requires me to regular scan my face to check that it aligns with the picture in my passport.

It's the same in the US. We're really lucky that it's technically impossible for fraudsters to email pictures of stolen passports (or stolen pictures of passports) to banks and other companies for fraudulent purposes.

Re: Tell HN: MitID, Denmark's digital ID, was down

#108
post #46

Earlier quoted context omitted.

NemID, the previous national 2-factor solution, used a small card with rows of pre-printed single-use codes. When you logged in to a bank or a public sector website, it would ask for a random code at a specific row and column number. Once the system registered that you had just a handful of codes left, a new card would be sent to you via snailmail. It worked fine for the time. The current system, MitID, depends on sm…

The big drawback of one time passwords is that it doesn't protect against man-in-the-middle attacks such as phishing, which is in practice one of the most common attacks on systems of this scale. The logistics operation involved in distributing codes is also very expensive and inflexible. You may need to authenticate payments a dozen times in an hour one day, when you are on a farmers market which doesn't take card p…

> You may need to authenticate payments a dozen times in an hour one day, when you are on a farmers market which doesn't take card payments or you are out dining with friends, and another day not at all.

It's very unlikely people would need to mess about with MittId/BankID if they can't use card payments at a market. Firstly, if they're doing the almost-unheard-of clunky approach of using their mobile banking app to make a bank transfer, it would probably be authorised using their touch/face ID instead of BankID/MittID. But far more likely, they'd use one of the ubiquitous mobile payment apps: Vipps (Norway), Swish (Sweden) or MobilePay (Denmark).

Re: Tell HN: MitID, Denmark's digital ID, was down

#110
post #89

Earlier quoted context omitted.

Imagine someone "enthusiastically digitized" (as much as possible) in a foreign country alone and then they lose their iPhone Plane tickets, all hotel reservations, they don't remember any phone numbers. They use ApplePay and other mobile payments. Cards may be in the same wallet case. Without a trusted device or Recovery Key, Apple may impose a security delay (24 hours to several days) before allowing a password res…

What's the difference to losing your backpack containing all these separate items? And conversely, it's very possible to carry a recovery Yubikey, a single-use login code etc. in a separate bag. Getting a new (e)SIM abroad can be very annoying, depending on the mobile network, which is why I try to avoid mandatory SMS authentication as much as possible.

Yeah losing is maybe a bad example. What about a software update bricking the device, or a hardware problem?
Post reply on HN