Live data from Hacker News

Switzerland votes against electronic ID system provided by private companies

swissinfo.ch

421–423 of 423 posts

Re: Switzerland votes against electronic ID system provided by private companies

#421

Earlier quoted context omitted.

Every time you say "the people of Apenzell" you really mean roughly ~50% of the voting age population. Would you make this same argument if only one person was allowed to vote in Apenzell? What about when that one person starts rounding up the people in Apenzell he doesn't like and imprisoning them?

When you say “voting age population”, you really mean roughly 70% of all residents? You and I probably agree that a 12yo should not have the right to decide what the state should do with its might, but the argument is the same regarding how the legal voting population of this tiny state of 16k citizens decide to expand who gets to vote in their local elections. What I say is that I’m impressed by the federal governme…

You think people would really move away? It's just one guy, you just gotta knock him off a bridge.

And if the simplest solutions to problems of governance become violence, rather than the system itself, then you have failed at the main purpose of government.

Re: Switzerland votes against electronic ID system provided by private companies

#422

Earlier quoted context omitted.

> Balkanizing ID info between a gazillion government databases as we do in the US just creates inefficiency It improves security through the reduction in the scope of harm and eliminating single points of failure. If someone compromises your Candy Crush login they can't drain your bank account. > and raises the thirst for more intensive surveillance to counter the inefficiency with which the data is used. (Consider t…

> It improves security through the reduction in the scope of harm and eliminating single points of failure. If someone compromises your Candy Crush login they can't drain your bank account. "Security through ad-hoc redundancy" is going to replace one possible-good auth systems with a gazillion shity ones that no one has the budget or interest to secure. It's a greater attack service. > It improves security through th…

> What we got is more surveillance (NSA dragnets), not more efficient use of the data they already have.

Or we could just not do that anymore and still not have centralized authentication.

> "Security through ad-hoc redundancy" is going to replace one possible-good auth systems with a gazillion shity ones that no one has the budget or interest to secure. It's a greater attack service.

You mean attack surface. But that's the trade off.

Because none of them are actually secure. Even when you have a full time security team, there are still vulnerabilities. Before the attacker had to find a vulnerability at the DMV, then start over at the bank, then start over at every company's file server. Now instead the attacker only has to find one in the central authentication system and they get everything at once. Even if there aren't as many vulnerabilities, if there is even one, you're screwed beyond comprehension across all systems everywhere.

On top of that, widespread use cuts the other way. Suppose the system was originally deployed using sha1. That starts looking pretty weak so you begin the decade-long process of transitioning literally everyone to a system using something else. Then suddenly sha1 gets completely broken beyond all hope, but you can't stop using it because 15% of people haven't migrated away yet and that's too much of the world to abruptly cut off.

Whereas in the decentralized system only 15% of things would be vulnerable because the other 85% had already migrated and disabled sha1, and the important stuff like banks who have their own security teams would be in the 85%.

More to the point, there are other ways to reduce vulnerabilities without centralization. Use simpler, more stable software from vendors who spend more time on security and less time on feature bloat. Restrict local services to local users so they're not exposed to the internet. Use defense in depth so that a single vulnerability is not enough but the expense of finding five stackable vulnerabilities is uneconomically large relative to the value of compromising an individual system.

Whereas the only way to avoid the ominously large scope of compromise of centralized authentication is to decentralize it.

Re: Switzerland votes against electronic ID system provided by private companies

#423
post #232

Earlier quoted context omitted.

> There was a scandal in Estonia where they had to recall all the ID's because the main private key which signed them all got leaked (and that key was held by a private company) No.

Helpful comment. https://www.reuters.com/article/estonia-gemalto-idUSL8N1WD5J... > Estonia's Police and Border Guard Board (PPA) said in a statement Gemalto had created private key codes for individual cards, leaving the government IDs vulnerable to external cyber attack, rather than embedding it on the card's chip as promised.

It was helpful, you saw that what you wrote was technically VERY incorrect and without any proof.
Post reply on HN