Live data from Hacker News

EU Age Control: The trojan horse for digital IDs

juraj.bednar.io

61–70 of 222 posts

Re: EU Age Control: The trojan horse for digital IDs

#61

Earlier quoted context omitted.

I think even digital IDs will tend to exist as physical tokens? Also worth noting that you can have a digitized and cryptographically signed ID on "paper" which can serve much the same purpose (security, machine readability) as an electronic one. Where electronic tokens shine (for IDs or otherwise) is attesting to the physical possession of a single copy.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days.

OK. I'll bite. Why are they unnecessary?

Passports have two things. They have information on them, which can be read by looking at them. And they have information on them in chip form, which can be scanned, and is also cryptographically signed by the issuing authority (eg, a government).

To verify a passport you can look at it visually, but you can also scan and validate the info, including photo, in digital form. All you need is the CSCA, the 'country signing certificate' to do so, and there aren't may of those. Small readers exist which are updated with these certs, and so even in the middle of a war zone, with RF jamming, you can verify a country signed what you're looking at.

Relying upon the Internet being there for ID purposes is a massive fail. You'd don't need a networked reachable database to validate that your ID is valid, in a digital way, which can be really helpful with 1M refugees show up at your door during a war, or when the capital city of the issuing nation has been bombed.

You may think this unimportant, but the edge cases are what 99.999% uptime is all about. And the edge cases with ID really need 100% uptime. The last thing you need during a natural disaster is an inability to ... well, do anything.

So even if you have biometric methods to identify someone, you'll also want a local, on person method which has those on chip, and signed by a government saying who you are.

Having ID network connected is also a massive, huge, immense fail. There should be no network connected databases of anything about anyone, in any form. Why? It'll be hacked. This will never, ever, ever change. Never. Paper records can't be hacked en masse, and you can get the same protections by storing records on individual chips with other associated info in paper form.

Dismantling this infrastructure and replacing it with buggy, hackable, online databases just to get digital ID verification is a complete move in the wrong direction. Verifying digitally signed information is not.

And passports can be scanned by phones.

Which means that the info, cryptographically signed, can be verified by anyone in the world too.

Really, what we need is to have everyone chipped, like a pet. Because that's where this ends up, and that's also the only way to always have your ID with you.

As a snarky aside, I've spent my entire life interacting with society all the time, yet only in the last decade has it been necessary to be "carded" constantly to do so. We've literally taken a privacy conscious society, and turned it into a nightmare. I'm identified when I go buy a loaf of bread, the most dystopian, totalitarian government anyone could ever conceive of, is a joke compared to the amount of control and tracking now exercised over people's lives.

So I guess my point is...

If it's annoying and difficult to have to carry around a physical identifier of who you are? And use it regularly?

Why is the solution to make it easier to submit to slavery?

Think that's an over the top statement?

We all know how the US government has pivoted on many things during the current administration. We also know it has had, and continues to have (via private enterprise) a robust degree of information about every fiscal transaction made.

If you look at the McCarthy hearings, they literally went so far as to find documents from decades prior, paper records of course, of people joining socialist clubs in university. Eg, simply sign-in sheets, or their names listed in the minutes of such orgs.

Decades later, that information was used to blacklist careers, destroy lives, not for any proof of malfeasance by those accused, but simply because they were curious in college about socialism.

Those same accused were then used to "name names".

My point is, from the financial data currently being stored about people, anything that makes you stand out in any way could be turned into a problem 10 years down the road. Not to mention, how credit card usage, and digital tracking, and location tracking might hit some pattern.

No one who lived through the McCarthy hearings, just watching them, or lived through how Germany or Russia controlled the lives of their citizens, would ever think any of this increased fingerprint of people is a good idea.

It's all just very dumb. And it will not end well at all.

Re: EU Age Control: The trojan horse for digital IDs

#62

> There will be no single EU app, despite what the honchos of EU say. This shows that the EU commission is systematically lying. This problem used to exist in the past with Leyen - she is ultimately a lobbyist and that has to stop. Friedrich Merz too by the way - there is a reason why recent polls indicate that the german voters want him out of politics at once. The EU needs to reform. Right now lobbyists have too mu…

When did any EU representative ever lie about this? It has been very clear from the beginning that every member state would make their own apps.

I don't really see what internal German politics and lobbying has to do with anything.

As for the "Google" part, that's up to the member states to decide. In essence, the law states that apps should be secure and untampered. It doesn't specify any remote attestation partner, nor even the strict need for remote attestation although it's hard to accomplish any kind of phone-based authentication security without it. Android's native attestation solution also exists and works for phones sold without Google services, though it's an absolute pain to work with.

Sailfish, pmOS, or any other mobile OS could implement the security requirements if they ever get enough serious popularity to convince governments to make apps for them.

Re: EU Age Control: The trojan horse for digital IDs

#63

Earlier quoted context omitted.

I think even digital IDs will tend to exist as physical tokens? Also worth noting that you can have a digitized and cryptographically signed ID on "paper" which can serve much the same purpose (security, machine readability) as an electronic one. Where electronic tokens shine (for IDs or otherwise) is attesting to the physical possession of a single copy.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

For one thing, it increases resilience in the event of outages. It is a tangible aspect - just like citizens are encouraged to keep cash at home at least in my country (Sweden)

Re: EU Age Control: The trojan horse for digital IDs

#65
Many countries have digital IDs for years now.

It's not for digital IDs. It's for surveillance.

Digital IDs are fine (and desired even) if you are only requiring it for GOVERNMENT (same entity that released them) communication. Push for age control is scheme to make that info available for private companies and that's the trojan horse here.

Re: EU Age Control: The trojan horse for digital IDs

#66
post #61

Earlier quoted context omitted.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. OK. I'll bite. Why are they unnecessary? Passports have two things. They have information on them, which can be read by looking at them. And they have information on them in chip form, which can be scanned, and is also cryptographically signed…

> Relying upon the Internet being there for ID purposes is a massive fail.

Why would you need internet? Document holder smartphone can cache the document for years and present it over NFC (including photo, signature, etc). Just like existing biometric passports work, but replace the physical passport with smartphone app.

Re: EU Age Control: The trojan horse for digital IDs

#67
post #61

Earlier quoted context omitted.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. OK. I'll bite. Why are they unnecessary? Passports have two things. They have information on them, which can be read by looking at them. And they have information on them in chip form, which can be scanned, and is also cryptographically signed…

This is not how the world already works.

If CBP's systems go down, they will not process (foreign, they'll process US citizens still) arrivals [1], even with physical passports in front of them. I assume the EU ESS works the same.

"If the internet goes down, your border checkpoint is down" is not some terrifying future we need to protect against, it's the reality of the world as you live in right now.

[1]: I've had to wait for an hour, at SFO of all places, because of exactly that happening.

Re: EU Age Control: The trojan horse for digital IDs

#68
post #66
post #61

Earlier quoted context omitted.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. OK. I'll bite. Why are they unnecessary? Passports have two things. They have information on them, which can be read by looking at them. And they have information on them in chip form, which can be scanned, and is also cryptographically signed…

> Relying upon the Internet being there for ID purposes is a massive fail. Why would you need internet? Document holder smartphone can cache the document for years and present it over NFC (including photo, signature, etc). Just like existing biometric passports work, but replace the physical passport with smartphone app.

To check against $your-local-law-enforcement-agency database, $your-local-immigration-agency for history of entry, etc.

The internet requirement is not there for the person presenting the document, it's for the person/system checking it.

Re: EU Age Control: The trojan horse for digital IDs

#69
> Real cryptographic unlinkability schemes like BBS+ or CL signatures would produce uncorrelated proofs even on reuse. This is not that.

This discussion was already led ad nauseam with the Swiss eID proposal (which is supposed to be EUID compatible) and the reason why the system relies on rotating signatures instead of ZKPs is that the cryptography hardware modules in most phones don't support algorithms such as BBS+. This creates a tradeoff where the states would have to essentially roll their own crypto storage and bank on this being safer than simply rotating through batches of signatures generated by the hardware cryptography modules (which is largely unproblematic in the grand scheme of things). The major advantage of using the hardware module is that it makes it much harder for attackers to extract the actual secret should the device ever fall into someone else's hands, something that happens to phones from time to time.

Overall, as with every digital ID thread, it would help if some of the fearmon gering commentators would read the actually EUDI specs for once in their lives as it already addresses most of the concerns copy-pasted into these threads https://eudi.dev/1.6.0/architecture-and-reference-framework-....

Re: EU Age Control: The trojan horse for digital IDs

#70

Digital ids are inevitable in my view, just as digital currency has become inescapable because it is more convenient and efficient, these ids will be issued and things like paper proofs of identity will fall away over time. Physical tokens like bank cards and driving licenses are neither necessary nor a good solution in a networked world. Our focus therefore should be controlling what governments can do with them - f…

> for example disallowing blocking/removing someone’s id

If I lose my passport I am obliged to call the police so that they revoke it, if I lose my phone with my digital ID on it they also need to be able to revoke that ID.

Post reply on HN