Earlier quoted context omitted.
>driver's licenses expire in the US, usually on a 5-10 year cadence Standard Arizona drivers licenses only expire when the licensee turns 65 years of age, and must be renewed every 5 years thereafter.
You don't have to update your picture? You can be wandering around using a 40 year old ID card? That doesn't sound right.
Hackers had a live feed of every ID verification company scanned for over a year
251–260 of 264 posts
Re: Hackers had a live feed of every ID verification company scanned for over a year
#252Earlier quoted context omitted.
isn't the immigrant question a real obstacle for political change towards fixing this problem? That we would have to come to some kind of consensus on what to do for illegal immigrants
As long gangs are running the political discourse (anti-id, anti-flock, etc) - good luck in having functioning society. I say that as someone who just spent 3 months in Europe and witnessing farcical bureaucracy.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#253Earlier quoted context omitted.
Your digital identity would then be under the jurisdiction of the US government, who (despite talking a big game) are arguably worse for that same sort of behaviour. If anyone has to have this type of control, better it be a local national government that you can in at least some small way influence.
No it isn't. The 1A is held strongly even by the most reactionary parts of American politics and jurisdiction. You will not be thrown into a jail just for expressing your support for a group as it happens in the UK.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#254Earlier quoted context omitted.
You don't have to update your picture? You can be wandering around using a 40 year old ID card? That doesn't sound right.
The photograph does have its own expiration timeline, which is not printed on the card. So yes, it was a little surprising to receive that letter, calling me into the office for another photo shoot.
So what happens if you just don't show up?
Re: Hackers had a live feed of every ID verification company scanned for over a year
#255Earlier quoted context omitted.
No, to the ID to prevent abuse if the card get stolen.
Which means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key. The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway. Your system effectively collects exactly the data ZKP i…
No third part would know how often you use your ID.
Why do people make up problems that are already solved?
OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.
Re: Hackers had a live feed of every ID verification company scanned for over a year
#256Earlier quoted context omitted.
I don't think people are against it, we already have the social security identifiers as a government layer... it's just that no one in the government is willing to do it for free in a way that is accessible to everyone
> I don't think people are against it Every time national ID gets moderately serious discussion it is revealed very clearly that yes, the people are against it. RealID—which was simply national standardization of state issued ID (when used for a variety of important purposes) had intense resistance, too—and its the closest policy to national ID that has passed. Social Security identifiers are not ID for the person, a…
give people a moderate benefit to do it, like a tax credit, and I think you'll find the majority of people hold their beliefs not so rigidly
Re: Hackers had a live feed of every ID verification company scanned for over a year
#257Earlier quoted context omitted.
People are against national IDs because of privacy, not racism like a previous comment in this thread suggested People are against requiring certain types of IDs to vote as racism or other forms of voter suppression because it may cost money to get those IDs or be very very hard to do so, when there are other methods to authenticate a person for voting Those are two separate issues and complaints.
Just to add a bit. In a few different places in the US I've had multiple ID offices within easy driving (or bus) distance and wait times ranged from short to annoying but bearable. When I lived near the ghetto in a different state I had roughly 2 choices, one 30 minutes out and the other over an hour (by car without traffic). Bus? Hah! Have fun. Arriving at the nearer of the two within an hour or so of opening in the…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#258Earlier quoted context omitted.
That part seems to qualify as an unsolved problem. But could anyone have taken the scanned data (or the GIF file) and used it to open a bank account in your friend's name? That seems like the main issue that is genuinely solved by correct implementation of this type of system.
Already today nobody can open a bank account in my name with just a picture of my passport, as the original would be required. My passport doesn't have any of the "eID/CAs/ZKP/PKI", so the question of "what exactly the addition of it solves" remains open. My national ID card supposedly has some of it, the 17-year olds who want to pass as 18-year olds usually show a doctored gif file of their ID card, with a year of b…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#259Earlier quoted context omitted.
Already today nobody can open a bank account in my name with just a picture of my passport, as the original would be required. My passport doesn't have any of the "eID/CAs/ZKP/PKI", so the question of "what exactly the addition of it solves" remains open. My national ID card supposedly has some of it, the 17-year olds who want to pass as 18-year olds usually show a doctored gif file of their ID card, with a year of b…
Actually it does. Biometric passports (and IDs) have a chip which is read via NFC and the information the NFC provides is signed by a CA which is the government that issued the passport. ICAO compiles a database of public keys corresponding to each government (plus countries exchange their public keys via bilateral agreements). Unless somebody is doing purely visual inspection, any time a passport is scanned there's…
Re: Hackers had a live feed of every ID verification company scanned for over a year
#260Earlier quoted context omitted.
Which means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key. The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway. Your system effectively collects exactly the data ZKP i…
Nope, your ID could work like a YubiKey with a fingerprint reader or you could add a OTP. No third part would know how often you use your ID. Why do people make up problems that are already solved? OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.
But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glitch the device to extract the private key. ... and of course all the power hungry / extra complex ZKP machinery means less resources spent on preventing glitch attacks.