Live data from Hacker News

California DMV Digital ID Pilot Program

dmv.ca.gov

71–80 of 95 posts

Re: California DMV Digital ID Pilot Program

#71
post #30

The Estonian e-ID system and Qualified Electronic Signature in the EU are good ideas. The government issues you a signed identity. You can use that signed identity to counter-sign challenges in places you'd otherwise (in the US) need to use a Social Security Number and a convoluted private market identity-verification system (for example, the stupid "were you associated with this address 4.5 years ago" things). Like…

This says mDL. The QR code is at most a cryptographically signed attestation of relevant attributes (eg age, name, etc). Not sure if this made it in, but originally the ISO group had been talking about also signing >18/>21 of sharing the actual birthday for things like restricted sales. I don’t recall discussing QR codes as it was supposed to be NFC but maybe that changed (don’t see a mention of QR codes on the site)…

This implementation is QR code based, which ruins a lot of the value in terms of low-battery use and makes standardization and acceptance difficult.

Anyway, for anything to work in the US, there needs to be an incentive for businesses to use this system, and right now, there isn't one for point-of-sale driver's license use, in my opinion. It's technology (perceived as unreliable, slow, expensive) that can break, vs. looking at an ID, which isn't without its faults but is a simple system everyone understands.

If there were a really fast, simple, cheap, readily available system for age verification which was pushed to bars, I could see this system catching on, but "limited private pilot programs" aren't it.

And that's pretty much my point - starting with places where technology is already required (banking etc.) makes more sense in many ways than starting with driver's license replacement. The issue here is that the horribly broken identity system in the US is Federal (Social Security) while these electronic systems are State.

Re: California DMV Digital ID Pilot Program

#72
post #62

I received this, and it seems cool. However, there are some issues. First, it cannot be used as identification at airports, for rental cars, or in bars. There is a kiosk at SFO, but every time I’ve visited, it was out of order. Another annoyance is that it’s not integrated with Apple Wallet. Knowing how the government in California operates, this will likely become a money pit. They will probably abandon the project,…

Maybe the app needs some more updates. They claim in the app “the card has been added to your wallet” and nope, it’s not there.

Re: California DMV Digital ID Pilot Program

#73
post #59

I can't seem to get past the setup phase where the app "scans" your face via your phone's camera. A dozen attempts, different backgrounds and lighting and I keep getting "try again". Loving this AI-powered future we're in.

"pay with your palm" at Whole Foods-Amazon grocery store, right next to the self-service checkout.

Re: California DMV Digital ID Pilot Program

#74

I played around with it. Not worth while at this point. Too many privacy risks (e.g. requires you hand over your phone to police unlocked).

You can use guided access to restrict access outside of the app. Here in Colorado, they just scan the barcode on the back and pull up the info on their own device.

Only maybe 1/10 people even know about guided access. It’s also time consuming to setup.

Apple could add an API to wrap apps in guided access automatically … or lock the device on app exit. But that’s not going to happen because they want wallet apps to go though their Apple Wallet APIs

Re: California DMV Digital ID Pilot Program

#75
post #16
post #7

I assume the app will attempt to tie my device identifiers such as IMEI, phone number, and advertiser ID to my government digital ID. Then they can tie it to other ID's such as Facebook or other app ID's on the device that also read device identifiers. It probably would fail to install on my Graphene phone that treats all apps as hostile by blocking them from reading any device identifiers. I would rather wait with t…

Speculating like this with no evidence just to peacock to everyone that you're privacy conscious is not actually helpful for anyone.

It is not speculation. I assume every app is hostile and trying to grab information until it can be proved that it does not. Until the app is open sourced and/or people do network analysis on it, this is the safest default assumption.

Re: California DMV Digital ID Pilot Program

#76
post #19
post #7

I assume the app will attempt to tie my device identifiers such as IMEI, phone number, and advertiser ID to my government digital ID. Then they can tie it to other ID's such as Facebook or other app ID's on the device that also read device identifiers. It probably would fail to install on my Graphene phone that treats all apps as hostile by blocking them from reading any device identifiers. I would rather wait with t…

iOS apps also can’t get device identifiers. Besides, wariness is wise but assumptions are not.

Don't Iphones have advertiser ID's available to apps?

Re: California DMV Digital ID Pilot Program

#77
post #16

Earlier quoted context omitted.

Speculating like this with no evidence just to peacock to everyone that you're privacy conscious is not actually helpful for anyone.

It is not speculation. I assume every app is hostile and trying to grab information until it can be proved that it does not. Until the app is open sourced and/or people do network analysis on it, this is the safest default assumption.

It absolutely is speculation if you haven't done the legwork and just want to throw out quick and easy takes like this.

Re: California DMV Digital ID Pilot Program

#78
post #34
post #30

The Estonian e-ID system and Qualified Electronic Signature in the EU are good ideas. The government issues you a signed identity. You can use that signed identity to counter-sign challenges in places you'd otherwise (in the US) need to use a Social Security Number and a convoluted private market identity-verification system (for example, the stupid "were you associated with this address 4.5 years ago" things). Like…

> Then simply share your TruAge QR code at checkout at select retail locations in Sacramento to safely and securely verify your age, while protecting your privacy. Right now, bars/clubs will scan my ID and have all my information (name, birthdate, etc). They don't need that. all they need is a yes/no that I'm over 21.

Many bars, clubs, concerts and festivals scan your ID's barcode on the back and both store the data and retrieve data from a threat database. It's actually surprising more don't as the technology is in all of our pockets.

Not saying I agree with it but in many cases we're beyond the binary check.

Re: California DMV Digital ID Pilot Program

#79
post #30

The Estonian e-ID system and Qualified Electronic Signature in the EU are good ideas. The government issues you a signed identity. You can use that signed identity to counter-sign challenges in places you'd otherwise (in the US) need to use a Social Security Number and a convoluted private market identity-verification system (for example, the stupid "were you associated with this address 4.5 years ago" things). Like…

Now imagine they are under obligation to accept it, and you can get to the point where you can leave your wallet at home. With car keys being Bluetooth, I now don’t carry keys in my pocket. To not carry a wallet to drive to the grocery store either would be a joy. I like a physical lightness.

> With car keys being Bluetooth

https://francozappa.github.io/post/2023/bluffs-ccs23/ and a related but slightly different threat: https://news.ycombinator.com/item?id=38661182 are why I have no interest in that end of the convenience---security spectrum. For clarity, I'm not yucking your yum, just hoping the future is not made up entirely of c libraries written by.. security insensitive.. developers protecting my house and car

Post reply on HN