Earlier quoted context omitted.
Yes, I'd definitely echo that, a huge amount of tax implications are based on individual residency/permanent establishment so if you're living in say, Germany, for 1/2 of the year + 1 day, you should be expecting to pay at least your personal income taxes there, and likely the business taxes if you're a sole prop without local employees and local business. Of course, if you're a true 'digital nomad' who doesn't estab…
Even if my personal account was in an Estonian bank?
Estonian Electronic Identity Card: Security Flaws in Key Management
51–60 of 82 posts
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#52Earlier quoted context omitted.
Even if my personal account was in an Estonian bank?
Having a personal account in a local bank may be a data point if you want to make a case about where you should be taxed but it won't automatically make you have permanent establishment or tax resident in Estonia
Yeah I should definitely check with an accountant in the country where I will end up residing.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#53I'm from the EU and considering incorporating my next company in Estonia. Anyone else in a similar situation has any recommendations or ideas about this?
Make sure to understand the tax laws when it comes to the company tax residency in scenarios where you're physically not operating in Estonia nor employing people there, nor having majority of your clients there. See my older comment [1] for some related topcis to research. [1] https://news.ycombinator.com/item?id=21321451
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#54Earlier quoted context omitted.
Yes, I'd definitely echo that, a huge amount of tax implications are based on individual residency/permanent establishment so if you're living in say, Germany, for 1/2 of the year + 1 day, you should be expecting to pay at least your personal income taxes there, and likely the business taxes if you're a sole prop without local employees and local business. Of course, if you're a true 'digital nomad' who doesn't estab…
Even if my personal account was in an Estonian bank?
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#55Earlier quoted context omitted.
Having a personal account in a local bank may be a data point if you want to make a case about where you should be taxed but it won't automatically make you have permanent establishment or tax resident in Estonia
Ah, right. Yeah I should definitely check with an accountant in the country where I will end up residing.
I personally had a good working relationship with 1Office in particular and recommend them (wasn't a client but they were a partner when I worked for the e-Residency program and a buddy's GF works there who I trust and who does good work)
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#56Earlier quoted context omitted.
Thinking that compulsory id cards "Papers Bitte" are not a good thing is not an uncommon view.
It's not about it being compulsory, but the system being unverifiable end-to-end and any criticism of that being laughed at. If you put it into business terms, would you trust an employee or vendor who told you that everything was alright, did not allow you to perform checks and audits and mocked both your and external partners concerns [0] about it? I don't think so. If the government is indeed for the people and no…
- voting systems inevitably have to be closed source, loaded on easily compromisable USB stick, connected to internet unguarded and sitting that way for years. In what reality is this nihilistic fatalism a reasonable expectation?
- voter has no way of independently verifying that their vote has been processed correctly. First of all, this is simply ignorant as there are many cryptographical schemes that allow verification, but most importantly - how do you know that your vote has been processed correctly in our current system? You don't, there is no way for you to do that.
- US hacking machines are routinely exploited at Defcon. That's right. You know what else is routinely exploited there? Physical safes, which are used for storing you know paper ballots. Also cars. And Air Force has promised to bring a fucking satellite next year. Something having vulnerabilities in the past does not mean it still has them, something having vulnerabilities currently does not mean they are easy to exploit in practice or can't be detected and mitigated, some products in a certain category having vulnerabilities does not mean all products in this category will inevitably have vulnerabilities in the future and we should just give up on ever fixing them.
- trusting a person in a voting booth to vote for you would be ridiculous, but filling a ballot yourself and trusting that it will get counted correctly along the way is somehow self obvious - I guess because in the first case you clearly see that a human is involved in the process and in the second example it sort of feels like the process is finished once you physically put your vote into a box?
- the average voter won't understand checksums. Well, maybe the average voter shouldn't worry about bad bytes in that case? And how come deterministic and auditable cryptography is a problem while demonstrably non-deterministic process of current paper voting (look at how results always differ ever so slightly when votes are recounted) is a non-issue?
- transferring votes over internet is problematic because you can't trust software on either end. Right, because you know (never mind trust) everybody that will handle your vote on the path from voting booth to the whatever-governing-body-is-announcing-results-in-your-country?
- central computer could be manipulating your votes and only a few people will have an opportunity to inspect it. Well, how many voting boxes have you been allowed to inspect in your life? Are you allowed to go to the central location where your votes are aggregated and recount all of them personally? How do you know that officials in your voting location, precinct or at a national level haven't agreed to manipulate the results?
- casting doubts on the election is easy to do with electronic voting and nearly impossible with paper voting. Have you heard this cute story about medical masks becoming a conspiracy and symbol of oppression among certain population in US? Has nothing to do with electrical circuits and everything to do with politics. If a current incumbent happens to lose an election there you can be sure that election results will be called fake, no matter paper or digital.
- malware exists, so voting from personal devices is ridiculous. Just as ridiculous as doing e-commerce or banking? Or in case of Estonia getting pretty much any other official business done, or so I hear.
- a single vulnerability in someones computer can be scaled to millions of computers. Ok, let's say someone is still using Windows XP and got infected with something after downloading GTA from Pirate Bay. How does that affect people voting from their iPhones?
- anecdotes, anecdotes, anecdotes
tl;dr: Stop spreading FUD.Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#57Earlier quoted context omitted.
Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the " digital results in riggin…
> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. How many more votes would the party in second place at the last election have needed in order to have won instead? > If some party suddenly receives a lot more votes than they polled for - it will be noticed. Is there a mechanism by which the election could be run again (before the winners of the electio…
It's a multiple party proportional representation system so who "wins" doesn't really matter that much.
> Is there a mechanism by which the election could be run again (before the winners of the election have a chance to prevent this)?
I'm not an electoral law expert, but complaints about election process go to National Electoral Committee, which can have its decision contested in Supreme Court.
> Or it's an argument that a voting system should have both hand-counting and digital counting, because rigging both counts is at least twice as difficult as rigging one.
The e-voting over here is actual e-voting - the vote is purely digital and done remotely. Not in any way related to the digital vote counting machines used in the US.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#58I'm from the EU and considering incorporating my next company in Estonia. Anyone else in a similar situation has any recommendations or ideas about this?
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#59Earlier quoted context omitted.
Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the " digital results in riggin…
> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. How many more votes would the party in second place at the last election have needed in order to have won instead? > If some party suddenly receives a lot more votes than they polled for - it will be noticed. Is there a mechanism by which the election could be run again (before the winners of the electio…
Unless the party rigging the counts is the one currently in power. Which in my opinion is the main risk, however minuscule and unrealistic.
Re: Estonian Electronic Identity Card: Security Flaws in Key Management
#60Earlier quoted context omitted.
Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. All the election results end up roughly similar to all the various independent polling results. If some party suddenly receives a lot more votes than they polled for - it will be noticed. Also Estonia already has a history of (non-digital) election rigging [1] so rhetoric of the " digital results in riggin…
> Rigging (digital or not) would be hard to hide, because it could only be a minor adjustment to remain plausible. As candidates & parties become more competitive, the difference in their voting shares tends to narrow. Eventually you end up with large coalitions that split the electorate fairly evenly. A small adjustment is all it'd take to tip the scales. If landslide victories are common, I'd say your political sys…
This reads like a pure American exceptionalism.