Earlier quoted context omitted.
> but it's a privacy nightmare. I've gone the other way from Denmark to UK. And I've often had to mail copies of my passport or other identity documents via email. And my bank requires me to regular scan my face to check that it aligns with the picture in my passport.
It's the same in the US. We're really lucky that it's technically impossible for fraudsters to email pictures of stolen passports (or stolen pictures of passports) to banks and other companies for fraudulent purposes.
Tell HN: MitID, Denmark's digital ID, was down
171–180 of 194 posts
Re: Tell HN: MitID, Denmark's digital ID, was down
#172Liberal democracy is a very young experiment and people do not realise how fragile it is. In the 1940s less than 10% of countries were democratic, and we could go back there again easily.
Re: Tell HN: MitID, Denmark's digital ID, was down
#173I am surprised this is even a frontpage topic, 3 years after it was rolled out, we saw downtime every week or so. So much so that we implemented automatic pop ups for our customers, and no on-call, signaturgruppen a subsidiary of NETS didn't even file this incident as a major outage lol. There is also no alternative, you simply can't access banking apps without MitID, so without it people in Denmark are just screwed, 3D Secure (online payments doesn't work for most merchants), login to government and banking sites doesn't work.
The main issues are that we have a central provider NETS whom are known for NemID its predecessor, and card payments in Denmark. They're huge in this space, at least for Denmark.
The government and the banks wanted more control over MitID, so the responsibility was split between the major banks, Digitalstyrelsen (the government), and NETS.
Basically, customers, middle man and NETS the vendor.
It was truly a shit show. The middleman (Digitalstyrelsen - Agency for Digital Government was technically illiterate, either by contract, or because they wanted to be in control, had inserted themselves in-between customer and vendor, and now we suddenly couldn't provide feedback, or talk to the vendor at all, this meant that the vendor had full control over how they interpreted the contract.
During development they shipped a version of the product that had a single flag set to false, preventing a login. NETS weren't allowed to ship a fix for this for 3 months. Many of the customers had to use burp suite during their testing simply to progress with development.
Finally when the vendor had "delivered" to their contract, the customer was sitting back with a half-baked product, and because it was Digitalstyrelsen that was the primary arbiter of whether they'd fulfilled the contract, NETS got away with having delivered at that point 1 year past schedule.
I've never had so many support tickets. For such a technically tiny product, we saw so much trouble getting people to use MitID over NemID. It was incredible.
What is even more insane is that each provider implementation of MitID is technically an independent implementation, some are React, Preact (if using nets provided version), etc. All the providers have to provide a pixel perfect replication to be allowed to issue MitID credentials.
Also this was designed when OAuth was really hot, so most implementations are like 3 levels deeply nested of OpenID Connect and OAuth2, it gets pretty nuts.
Talk about an amount of wasted effort.
As with many other huge projects especially government lead. It is just a big power play, and as it turns out, power wins. In this case NETS.
Re: Tell HN: MitID, Denmark's digital ID, was down
#174Dane by choice (refugee). Would just add as a counterweight to the negative views from people outside the country. From a technical and user point of view, MitID have had less outages than Cloudflare, AWS and MS Azure in the last year. While I agree with the single point of failure, I also like that I setup my startup with all government and banking online via a login I had the last decade, painless and faster than m…
They're very light on reporting issues, in this case Signaturgruppen a subsidiary of NETS, didn't even mark this as a full outage.
Re: Tell HN: MitID, Denmark's digital ID, was down
#175Terrifying to live in a digital economy when something like this happens. You're usually about 1 service away from realising that the "money you have" is just an int32, that, if everything works properly, you can modify. Otherwise you have nothing except a pretty little plastic card. (I'm aware that payments systems are not affected, but it's a sobering realisation that I've had a couple of times, but it works enough…
Re: Tell HN: MitID, Denmark's digital ID, was down
#176I'm a British expat with a Danish job. I really dislike MitID and the Danish centralised world of (very good) public services that come with it. Each person has a number, CPR, which effectively defines your life solely to the state. Visit a library, doctor, tax man, anything official, and your ID is recorded. Buy alcohol online, go grocery shopping, use your bank card -- and sign in with it. This undoubtedly makes th…
NETS have always been very sparse with their post mortems, they don't act like a SaaS provider. Not even as a partner did we get postmortem. They're well and truly into the jaded territory. During two jobs, both as a provider (customer of NETS), and as a consumer of a provider of MitID
Note this is as a customer. The provider and in turn their customers pay pr login and a quite hefty fee at that. NETS are just too big.
They were down every few weeks for a short while (between 2020-2023), so I guess this is probably still the norm
Re: Tell HN: MitID, Denmark's digital ID, was down
#177Don't banks have their own id:s as well? At least in another nordic country, you have quite many login possibilities to many services. Banks even provide cross-login.
It is to avoid the banks needing their own id for customers, as people would need to go into the banks using their passports etc to register.
Some banks do have their own logins and IDs for various purposes, but you often need MitID somewhere in there simply to verify the actual identity of the person with the account. All the other logins simply give you access to the ID it doesn't actually verify it. MitID does that.
For example Lunar doesn't need MitID during 3D Secure (online payments), but that is only because you used MitID at some point to store your proof on your phone, that you can unlock with a secure enough method, and then do the payment. This is considered enough, as you still use an identity that has been verified by MitID at some point.
Re: Tell HN: MitID, Denmark's digital ID, was down
#178Re: Tell HN: MitID, Denmark's digital ID, was down
#179I'm a British expat with a Danish job. I really dislike MitID and the Danish centralised world of (very good) public services that come with it. Each person has a number, CPR, which effectively defines your life solely to the state. Visit a library, doctor, tax man, anything official, and your ID is recorded. Buy alcohol online, go grocery shopping, use your bank card -- and sign in with it. This undoubtedly makes th…
Italian living in Sweden, Malmö, and lived in the UK in the past. I don't get the obsession you Brits have against IDs, in Europe you are pretty much the only ones. But a lot of what you say resonates with my observations: - single point of failure: absolutely, but so is the "sign in with Google" or equivalent. It's just too convenient. I'd rather have a public service do it than a private company that can cut you ou…
I'm not British but to me it's extremely clear why they are against IDs when e.g. the Danish aren't. Media like 1984, animal farm, V for Vendatta etc. all came from the UK for a reason, they've always had a government entrenched in a strong class system with authoritarian tendencies.
That said, if you're Italian you should probably be wary of IDs for very similar reasons.
Re: Tell HN: MitID, Denmark's digital ID, was down
#180Earlier quoted context omitted.
Imagine someone "enthusiastically digitized" (as much as possible) in a foreign country alone and then they lose their iPhone Plane tickets, all hotel reservations, they don't remember any phone numbers. They use ApplePay and other mobile payments. Cards may be in the same wallet case. Without a trusted device or Recovery Key, Apple may impose a security delay (24 hours to several days) before allowing a password res…
What's the difference to losing your backpack containing all these separate items? And conversely, it's very possible to carry a recovery Yubikey, a single-use login code etc. in a separate bag. Getting a new (e)SIM abroad can be very annoying, depending on the mobile network, which is why I try to avoid mandatory SMS authentication as much as possible.
Nobody ever lost everything by dropping a backpack in a public toilet.
A phone, on the other hand…