Earlier quoted context omitted.
You guy don't have to show cock and balls to the military commission? It's a standard practice in post-Communist countries, including NATO ones.
There's a guy in the US military intake processing facility (MEPS) whose job is, among other things, to inspect your bunghole https://www.google.com/search?client=firefox-b-d&q=MEPS+assh... But more serious and non joking answer, the new thing from the "department of war" is testosterone level lab exams for existing servicemembers. https://news.google.com/search?q=US%20military%20testosteron...
Hackers had a live feed of every ID verification company scanned for over a year
91–100 of 263 posts
Re: Hackers had a live feed of every ID verification company scanned for over a year
#92The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…
I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.
Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem.
Doesn't even need ZKP, the CA can just issue an attestation.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#93Earlier quoted context omitted.
I understand the sentiment, but your government you can actually fix by voting. If Apple (or another large international company) suffers from decreasing margins, gets a new CEO and decides to turn the data it sits on into money there is absolutely nothing you can do, and you might in fact still stay a "forced" customer because of network effects (=> just consider whatsapp being an important communication channel in…
You can fix companies by voting a government too. In fact, governments are quicker at fixing companies than themselves.
Indirectly only. This is typically also always too late; instead of doing "the right thing" in the first place, companies are disincentivized by regulation from doing "bad things" again.
Regulations are like scar tissue, they don't help against getting burnt in the first place.
Preemptive regulation typically sucks, and is admittedly extremely difficult to get right; most governments don't even bother trying.
Corporation know this and exploit it ruthlessly-- there are almost never consequences as long as they keep to the letter of the law, even when acting with intent, against better knowledge and causing astronomical damage to society (just consider the whole leaded gas disaster for an extremely clear example).
Re: Hackers had a live feed of every ID verification company scanned for over a year
#94Earlier quoted context omitted.
You know, it always bugged me that the NSA (and more directly Google, and my phone company, and so on) know where I was at exactly this time a year ago, but that I do not.
In Google Maps Timeline you can definitely see it (if you set it up and you brought your phone)
Re: Hackers had a live feed of every ID verification company scanned for over a year
#95The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proo…
I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#96Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.
We also have a Danish wallet now, AltID, which implements an anonymized (assuming no collusion between issuer and eavesdropper or service provider) age verification protocol based on batches of single-use tokens which contain no personal information (except that they can be traced back to you by the issuer). It's been released and in production since summer. Since then, several social networks have apparently started…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#97This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet
I still don't understand why the simplest approach isn't used: ban kids from using the Internet unsupervised. There's really no good reason why a six year old should have internet access.
I dunno if I agree but I think that's the thrust of it.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#98Earlier quoted context omitted.
As a citizen under the France Passoire[1] and in an increasingly fascist chauvinist nationalist drifting in the geopolitical landscape, I wouldn’t be that found of delegating too much of these responsibilities to some centralized governmental institutions. Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which…
I live in the UK and was having this exact discussion with someone recently - I'd actually prefer Apple to be the owners of my digital identity over the UK government who would happily throw you in jail for expressing support for Palestine Action.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#99Earlier quoted context omitted.
There's a guy in the US military intake processing facility (MEPS) whose job is, among other things, to inspect your bunghole https://www.google.com/search?client=firefox-b-d&q=MEPS+assh... But more serious and non joking answer, the new thing from the "department of war" is testosterone level lab exams for existing servicemembers. https://news.google.com/search?q=US%20military%20testosteron...
so... for military grade identification systems instead of face photo with id document next to it, you make banghole photo with id document next to it?
https://www.google.com/search?num=10&client=firefox-b-d&hs=Y...
Re: Hackers had a live feed of every ID verification company scanned for over a year
#100We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible. ‘Just make the encryption secure and so we can read it’ ‘Just check everyone’s id but make it totally secure’
That is an unfair conclusion. These people run complex networks like the rest of us, they probably have a range of detection systems and, also like the rest of us, an almost impossibly large attack surface to consider internally and on their supply chain. The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know. I guess the awkward bit is market…