Live data from Hacker News

Tell HN: MitID, Denmark's digital ID, was down

news.ycombinator.com

11–20 of 194 posts

Re: Tell HN: MitID, Denmark's digital ID, was down

#12
post #4

First, we saw Russian hacking campaigns in Ukraine before the invasion of the country. [1][2] Are we seeing the same in Denmark/Greenland with the USA? [1] https://www.europarl.europa.eu/RegData/etudes/BRIE/2022/7335... [2] https://en.wikipedia.org/wiki/2022_Ukraine_cyberattacks

given the very sparse info on the actual problem i find it suspicious as well.

Re: Tell HN: MitID, Denmark's digital ID, was down

#13

Don't banks have their own id:s as well? At least in another nordic country, you have quite many login possibilities to many services. Banks even provide cross-login.

As I understand it, BankID in Sweden is still run by one organisation co-owned by the big banks, and banks handle verification for issuance. There is still a single point of failure for the operation of the system.

Re: Tell HN: MitID, Denmark's digital ID, was down

#14

The Swedish BankID has the same potential weak point. Any centralised system does. The way TLS on the Web works is better: as long as the CA is up some time during the period I need to renew it is fine. Digital IDs should really work that way (probably with relatively short life spans just like let's encrypt: the digital ID could need to be renewed once a week for example, and it would opportunisticly renew when less…

For anything as high stakes as eID you need real-time revocation checks, which brings you back to at least some level of centralization.

Re: Tell HN: MitID, Denmark's digital ID, was down

#15

Don't banks have their own id:s as well? At least in another nordic country, you have quite many login possibilities to many services. Banks even provide cross-login.

No. Many/most of them support login through hardware ID on your smartphone (i.e fingerprint/TPM-style pin), but the actual authorization of transfers or any privileged access is entirely MitID

Re: Tell HN: MitID, Denmark's digital ID, was down

#16
post #6

Should have stuck with NemID a previous paper alternative or only offered MitID as a digital alternative. The rush to go all digital is coming back to bite them in the .....

How would you use a paper ID online? (Securely, i.e. not the insane thing of taking a selfie holding it or something similarly bizarre in an age of powerful GenAI.)

Re: Tell HN: MitID, Denmark's digital ID, was down

#17
Terrifying to live in a digital economy when something like this happens.

You're usually about 1 service away from realising that the "money you have" is just an int32, that, if everything works properly, you can modify.

Otherwise you have nothing except a pretty little plastic card.

(I'm aware that payments systems are not affected, but it's a sobering realisation that I've had a couple of times, but it works enough of the time that I forget about it... it's a bit like the meme about backups where a computer takes too long to boot, the person slowly builds panic and starts wishing they had backed up and published all their important work - then when the computer works they say "*phew*, thank god I don't have to do any of that".

Re: Tell HN: MitID, Denmark's digital ID, was down

#18
post #14

The Swedish BankID has the same potential weak point. Any centralised system does. The way TLS on the Web works is better: as long as the CA is up some time during the period I need to renew it is fine. Digital IDs should really work that way (probably with relatively short life spans just like let's encrypt: the digital ID could need to be renewed once a week for example, and it would opportunisticly renew when less…

For anything as high stakes as eID you need real-time revocation checks, which brings you back to at least some level of centralization.

Revocation lists can be distributed.

Re: Tell HN: MitID, Denmark's digital ID, was down

#20
post #17

Terrifying to live in a digital economy when something like this happens. You're usually about 1 service away from realising that the "money you have" is just an int32, that, if everything works properly, you can modify. Otherwise you have nothing except a pretty little plastic card. (I'm aware that payments systems are not affected, but it's a sobering realisation that I've had a couple of times, but it works enough…

Now go read about fractional reserve banking
Post reply on HN