Earlier quoted context omitted.
Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?
I used to work for my state's DMV. They'd sell vehicle registration data to various companies, which is how and why you get those "we've been trying to reach you about your car warranty" phone calls. I don't know about CA, but KY had a problem with tracking who ordered and who paid for that data. When I worked there, we found a number of "purchasers" who only paid for Year 1 but stopped paying afterwards. Federal law…
Hackers had a live feed of every ID verification company scanned for over a year
151–160 of 263 posts
Re: Hackers had a live feed of every ID verification company scanned for over a year
#152Earlier quoted context omitted.
I don’t really trust anyone to get PKI right. There’s enough mistakes in the www realm that pretty well prove bad actors will get through. The alternative is do it offline.
eID PKIs have very little in common with the web PKI. There's a national root of trust with strong attestation. It's a very simple trust relationship. You already trust the respective government to issue IDs. Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem. Doesn't even need ZKP, the CA can just issue an attestation.
Sorry. Wrong.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#153Earlier quoted context omitted.
The US Government is one of the reference implementations of PKI. Unfortunately, IDs are issued 50 different ways by the less competent states. Combine that with accusations that getting new IDs constitutes systematic racism (a widely held belief on HN), ignoring that the ruralest of India has been able to do this successfully, and you're not getting digital ID any time soon.
IDs being required for voting is essentially a poll tax the way that it's argued for in the US. There's a minimum amount you have to spend to even get one that will expire in a certain amount of years. That's also assuming you can get all the documents you need for the initial ID. If you don't already have all the essential documents you'll need multiple appointments at government facilities. The local social securit…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#154Earlier quoted context omitted.
Passkey?
I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)
It is not true. You can move passkeys between OSs if you have a password manager or an OS that has this ability. For example, I store my Passkeys in iCloud Keychain and I have them synced on all my Apple devices.
There are cases though, where the website can force the requirement of a device bound passkey, but that is something it is not very likely you will encounter.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#155This is a sacrifice we just have to be willing to make as a society if we want to project kids from the horror of using the internet
This is precisely why the authority doing these checks needs to be the government that already issues the IDs . Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place . I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue…
Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so. Which means that the only way for it to actually be secure is for the implementation to also required locked down computing devices. Hence why the EU scheme insists on proprietary Apple/Google devices, and why Google research has written nerd sniping blog posts to market it.
There, now you know!
Re: Hackers had a live feed of every ID verification company scanned for over a year
#156Earlier quoted context omitted.
IDs being required for voting is essentially a poll tax the way that it's argued for in the US. There's a minimum amount you have to spend to even get one that will expire in a certain amount of years. That's also assuming you can get all the documents you need for the initial ID. If you don't already have all the essential documents you'll need multiple appointments at government facilities. The local social securit…
So… requiring an ID to buy a gun is also an unconstitutional tax on a right?
Re: Hackers had a live feed of every ID verification company scanned for over a year
#157Earlier quoted context omitted.
I think with passkey you don't own the private key. It's in your device and managed by the OS. That's one of the reasons I don't use passkeys (the other being that if I lose the device I can't access my account)
My passkeys are in my self-hosted Vaultwarden. If I can't put them there, I don't use them. It's not all sunshine and roses, though. Despite having Bitwarden set as the only passkey provider in my Android setup, the phone persistently only offers me Google. Which is empty, because as I said, I won't use one tied to things I can't control. Works great on desktops, though. Passkeys can theoretically require you to be o…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#158Earlier quoted context omitted.
so... for military grade identification systems instead of face photo with id document next to it, you make banghole photo with id document next to it?
It's all good and fine until a scan of your combined face ID / bunghole ID is for sale on a russian based internet crime forum. https://www.google.com/search?num=10&client=firefox-b-d&hs=Y...
Re: Hackers had a live feed of every ID verification company scanned for over a year
#159Earlier quoted context omitted.
In Google Maps Timeline you can definitely see it (if you set it up and you brought your phone)
Isn't it turn on by default?
Re: Hackers had a live feed of every ID verification company scanned for over a year
#160If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.
Am I missing something? What do you mean the DMV makes tens of millions of dollars a year selling data to itself?