Live data from Hacker News

EU Age Control: The trojan horse for digital IDs

juraj.bednar.io

71–80 of 222 posts

Re: EU Age Control: The trojan horse for digital IDs

#71
post #68
post #66

Earlier quoted context omitted.

> Relying upon the Internet being there for ID purposes is a massive fail. Why would you need internet? Document holder smartphone can cache the document for years and present it over NFC (including photo, signature, etc). Just like existing biometric passports work, but replace the physical passport with smartphone app.

To check against $your-local-law-enforcement-agency database, $your-local-immigration-agency for history of entry, etc. The internet requirement is not there for the person presenting the document, it's for the person/system checking it.

System checking it just verifies the signature is valid and thus all data presented is valid? Your browser doesn't need to query any Root CAs to trust SSL certificate, https works without internet.

History of entry and visas/etc could be stored on device as well

Re: EU Age Control: The trojan horse for digital IDs

#72
post #71
post #68

Earlier quoted context omitted.

To check against $your-local-law-enforcement-agency database, $your-local-immigration-agency for history of entry, etc. The internet requirement is not there for the person presenting the document, it's for the person/system checking it.

System checking it just verifies the signature is valid and thus all data presented is valid? Your browser doesn't need to query any Root CAs to trust SSL certificate, https works without internet. History of entry and visas/etc could be stored on device as well

If you want to argue for a theoretical system that is self-contained, only relies on the data that is present on either the physical (or the theoretical cryptographically signed digital) passport, you're free to do that.

But in the real world, the systems that deal with processing people's entries already cross-reference multiple other existing databases, require internet connectivity to do so, and I think you'll have hard time convincing anyone to stop doing that.

Re: EU Age Control: The trojan horse for digital IDs

#73

> Real cryptographic unlinkability schemes like BBS+ or CL signatures would produce uncorrelated proofs even on reuse. This is not that. This discussion was already led ad nauseam with the Swiss eID proposal (which is supposed to be EUID compatible) and the reason why the system relies on rotating signatures instead of ZKPs is that the cryptography hardware modules in most phones don't support algorithms such as BBS+…

> Overall, as with every digital ID thread, it would help if some of the fearmon gering commentators would read the actually EUDI specs for once in their lives

Yeah

I'm getting really really tired of the "crying wolf" crowd

Re: EU Age Control: The trojan horse for digital IDs

#74
post #54

Digital ids are inevitable in my view, just as digital currency has become inescapable because it is more convenient and efficient, these ids will be issued and things like paper proofs of identity will fall away over time. Physical tokens like bank cards and driving licenses are neither necessary nor a good solution in a networked world. Our focus therefore should be controlling what governments can do with them - f…

> just as we should disallow removing citizenship. However lots of countries do allow removing citizenship In the UK it is a political decision too. Lots of countries allow locking people out of other things (e.g. freezing bank accounts). I therefore doubt we an effectively prevent this. I do not see the problem with physical tokens. They are simple, do not create a single point of failure (if I lose my phone I still…

The drawback of physical tokens is that you can't use them online. I don't want to spend an hour waiting in queue at the city hall for something I can do online in 10 minutes.

The ideal state is having both physical and digital ID. But that will lead to a slow erosion of the willingness to carry physical ID, even if it stays available (which I believe it will for many decades. Even if national ID cards and drivers licenses were to go digital only, passports won't)

Re: EU Age Control: The trojan horse for digital IDs

#75

It's not a trojan horse, it's spelled out in the decision, debates, and legal texts to be the explicit goal. The age verification requirement was picked both as a means to prove the technology is sound and as a simple starting point for a full digital ID solution. The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that au…

> The digital wallet solution is an extension to that system that will allow foreign EU citizens to authenticate themselves more easily

Is there a roadmap and/or a timeframe for that? I have a Slovak ID same as the author, when will it be useful for accessing internet services?

Re: EU Age Control: The trojan horse for digital IDs

#76

Digital ids are inevitable in my view, just as digital currency has become inescapable because it is more convenient and efficient, these ids will be issued and things like paper proofs of identity will fall away over time. Physical tokens like bank cards and driving licenses are neither necessary nor a good solution in a networked world. Our focus therefore should be controlling what governments can do with them - f…

> for example disallowing blocking/removing someone’s id If I lose my passport I am obliged to call the police so that they revoke it, if I lose my phone with my digital ID on it they also need to be able to revoke that ID.

Sure, I meant disabling without replacement, making someone an unperson. Obviously updates and replacements would be required as with passports.

I don’t think governments should be allowed to do that. They do it with passports and I think it’s deeply wrong but also it would be far more damaging and immediate with a digital id (which will inevitably be used for a lot of services) - similar to being refused a bank account.

Re: EU Age Control: The trojan horse for digital IDs

#77
post #42

Earlier quoted context omitted.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

I doubt everyone will still be carrying phones as we know them in a decade, so we might indeed be headed for a future where governments keep giant databases of biometric information. Works OK if you trust your government to handle that properly and not abuse it in the future. The real headache is crossing borders, where your details end up in the hands of a foreign state.

We are already in that future and have been for at least a decade. Passports contain biometrics which are in a central db too.

Re: EU Age Control: The trojan horse for digital IDs

#78
post #54

Earlier quoted context omitted.

> just as we should disallow removing citizenship. However lots of countries do allow removing citizenship In the UK it is a political decision too. Lots of countries allow locking people out of other things (e.g. freezing bank accounts). I therefore doubt we an effectively prevent this. I do not see the problem with physical tokens. They are simple, do not create a single point of failure (if I lose my phone I still…

The drawback of physical tokens is that you can't use them online. I don't want to spend an hour waiting in queue at the city hall for something I can do online in 10 minutes. The ideal state is having both physical and digital ID. But that will lead to a slow erosion of the willingness to carry physical ID, even if it stays available (which I believe it will for many decades. Even if national ID cards and drivers li…

I use credit cards online all the time. I have logins for government services so I do not need to queue (I had to verify my ID using an app once for one of them). Getting a new driving license (for a change of address) was done online.

Re: EU Age Control: The trojan horse for digital IDs

#79
post #54

Digital ids are inevitable in my view, just as digital currency has become inescapable because it is more convenient and efficient, these ids will be issued and things like paper proofs of identity will fall away over time. Physical tokens like bank cards and driving licenses are neither necessary nor a good solution in a networked world. Our focus therefore should be controlling what governments can do with them - f…

> just as we should disallow removing citizenship. However lots of countries do allow removing citizenship In the UK it is a political decision too. Lots of countries allow locking people out of other things (e.g. freezing bank accounts). I therefore doubt we an effectively prevent this. I do not see the problem with physical tokens. They are simple, do not create a single point of failure (if I lose my phone I still…

Yes and I find this deeply wrong - what politician would you trust with this decision? Debanking is also wrong in my view.

I think we should focus on laws against things like that which lead to tyranny rather than attempting to stop progress.

Cash in particular is expensive to produce/process and no longer honours the promise printed on it, it will be phased out as the transactions with it approach 0%.

Cards are really no different than a token in a phone and don’t work for long either in the absence of a network (both will work offline but do need to be reconciled). I haven’t habitually carried a card in about a decade, I think for similar reasons to cash they will die off by general consensus.

Re: EU Age Control: The trojan horse for digital IDs

#80
post #63

Earlier quoted context omitted.

I don’t see why they would bother with physical tokens nor would they be popular - things like passports are really quite expensive to manage and largely unecessary these days. An app or identity on people’s phone might be a good stopgap. However I suspect biometric methods of id verification will render carrying anything redundant long term. The databases for digital id already exist, they’re just not fully utilised…

For one thing, it increases resilience in the event of outages. It is a tangible aspect - just like citizens are encouraged to keep cash at home at least in my country (Sweden)

Does it though? Our world is now so networked that borders shut down if the network is down - see other responses on this thread.
Post reply on HN