Live data from Hacker News

India orders smartphone makers to preload state-owned cyber safety app

reuters.com

751–760 of 783 posts

Re: India orders smartphone makers to preload state-owned cyber safety app

#751
post #742

Earlier quoted context omitted.

Yes, but those "certain areas" are mandatory for functioning in society. And that ID is managed by a single central authority. The US by contrast, has a distributed system where there are many authorities that can issue IDs that are valid for the activities of daily life. The only common nationally issued ID in the US is a passport and people only get that for international travel -- and it wasn't even until 2024 tha…

With many authorities then you have as many more possibilities to break them, right? Note that the central digital ID used in e.g. Sweden is not the same as a central place for storing your private information.

Someone only needs one ID from one authority

Re: India orders smartphone makers to preload state-owned cyber safety app

#752
post #715

Earlier quoted context omitted.

Buddy, you're talking about 4000 VOLUNTEERS in a country of 11 million people (0.04%). We can probably find more crack addicts in Sweden... Let put the brakes on these slippery slopes, otherwise we'll be afraid of our own shadows soon. Scepticism is fine, paranoia isn't.

Those 4000 are bellwethers for whatever other impressionable idiots will follow them. (I'd forgotten it was that many, I thought it was a fraction of that.) Then it becomes mandatory, then compulsory, like so many other things. You mention crack addicts there. Yeah, they're kind of similar. With a new drug like cocaine, it starts with a handful of impressionable people who get given it cheap. Then they influence othe…

Those things you mention are private initiatives and you're blaming governments for them.

Governments are far from perfect, but why attack governments when - again - this is about private individuals and businesses?

Don't put ideology ahead of logic.

Re: India orders smartphone makers to preload state-owned cyber safety app

#753

Earlier quoted context omitted.

UK isn't commandeering anything. The UK government hasn't decided yet how digital ID will work, currently it's just a talking point. Probably it will be an app that you install, like the NHS app. Nobody is proposing that it be installed by default. Apple separately announced that a Digital ID feature will be built into iOS[0] which the UK may use or not use. > few who don't, so I'm curious what the plan is to bring t…

You do not need any form of photo or biometric id to work in the UK. I have never given anything of the sort, and have worked here for decades. All that is required is a national insurance number (equivalent of Social Security Number in US).

Your employer is supposed to check that you have the right to work. This can be done in a variety of ways, depending on your citizenship, looking at your British/Irish passport is one of the ways.

https://www.gov.uk/government/publications/right-to-work-che...

Re: India orders smartphone makers to preload state-owned cyber safety app

#754
post #708

Earlier quoted context omitted.

Yes you can, eID means that you can prove your identity online using your digital signature.

Can is the key word here. As implemented today, users can choose whether to use digital ID. In my opinion, problems would only start if the users had no choice and the government was the one choosing for them.

And of course absolutely no government ever, ever, decided that it was legitimate to choose for its citizens.

Re: India orders smartphone makers to preload state-owned cyber safety app

#755

Earlier quoted context omitted.

No, because with classic ID documents, the government doesn't know if I went to a specific healthcare provider, if I opened a social media account, if I bought a train ticket, or even where my bank accounts are (reporting is yearly, not in real time). Accessing all of this data is possible but bears a lot of friction, which prevents mass surveillance (or at least increases the costs). Once the eID system is set up an…

What is happening in China? I haven't been there in many years. There have been stories in the West about a social credit score system they had, but it turns out they didn't really follow through with that one.

You can't take a train if your social credit is too low.

https://www.theguardian.com/world/2019/mar/01/china-bans-23m...

Re: India orders smartphone makers to preload state-owned cyber safety app

#756

Earlier quoted context omitted.

No, because with classic ID documents, the government doesn't know if I went to a specific healthcare provider, if I opened a social media account, if I bought a train ticket, or even where my bank accounts are (reporting is yearly, not in real time). Accessing all of this data is possible but bears a lot of friction, which prevents mass surveillance (or at least increases the costs). Once the eID system is set up an…

With digital ID, they don't either.. You just have no clue what you're on about and it shows

With digital ID each time you open an account it pings a government server.

Re: India orders smartphone makers to preload state-owned cyber safety app

#757

Earlier quoted context omitted.

> "If these clowns can be used as a casus belli to declare war and use the US military against the civilian population, then..." That hasn't happened though. Deploying the national guard to stare down and maybe tear gas some clownish protestors is pretty typical stuff, not a civil war. By the way, I was in Seattle when the CHAZ stuff was happening and saw firsthand how both sides of the media were lying about the rea…

Well then it sounds like there's no reason to send the national guard in at all, and that it's quite wasteful to do so. So why are they sending in the national guard?

It's a very typical thing to do in response to protests. Maybe it's just worthless posturing, I don't know. I do know it doesn't constitute a civil war.

Re: India orders smartphone makers to preload state-owned cyber safety app

#758
post #636
post #436

Earlier quoted context omitted.

True, but that's already a much less clean separation between the credential issuer's and my domain on many dimensions other than security. As an example, this was the security model for mobile contactless payments for the longest time, and arguably as a result these never really took off until Google came up with a software-only alternative for Android. The potential for rent seeking of the hardware vendor is often…

Some of the current EU ID cards are actually smartcards, so in terms of privacy guarantees and separation of concerns, we are moving backwards. I am also more comfortable with a low-tech solution that is not linked to my personal devices. Something like a FIDO passkey would be ideal as those are also able to verify the identity of the other side, but are relatively low-tech and won't serve to track me.

ICAO biometric travel documents, the underlying standard which almost all EU ID cards implement these days, aren't suitable for remote identity verification though, as they don't have any way of verifying whether the legitimate holder or a thief/fraudster is using them.

Selfie or video face verification is susceptible to deepfakes, and remote fingerprint reads would also require trusted reader hardware.

Some countries have domestic schemes implemented on the same cards (e.g. Germany), but these are not interoperable across the EU, and many countries just don't have any non-ICAO scheme on their cards to begin with, and are instead implementing eIDAS (the current EU digital signature scheme) using some alternate scheme.

Re: India orders smartphone makers to preload state-owned cyber safety app

#759

Earlier quoted context omitted.

Mate, this isn't even remotely "nationalist". This stuff is being pushed across the world. Digital ID? The only people really desperate for it are our rulers.

How so? In Sweden we have digital ID and it's great! Super practical and I struggle to think of how it would be used to spy on citizens, given that it has the same legal protections as banks have regarding your account transactions etc. Like sure you could in theory see every document I've ever signed if you have a warrant for BankID servers, but you could probably glean most of that if you had a warrant for the bank…

> I struggle to think of how it would be used to spy on citizens

Hacker News has a unique user base. Professional Software Engineers, many of whom are Senior or Principal or Staff in level. Leaders and Managers and Architects.

I think, anytime we design a new system, we need to carefully think about how it can be used and what can go wrong. Not just with the current owners and users of that system, but future users and owners too.

Discrimination is one of those areas where identity management can go wrong. Discrimination and deliberate but undetectable Denial of Service "bugs" that always seem to hit the same types of users in the legs.

And getting evidence of wrongdoing like that takes years. It's nothing to an institution, but a lifetime to an individual. Sometimes there aren't even recordings or logs of individuals trying to ensure service and legal contracts are upheld. And again, the legal process is nothing for a large institution but soul crushing for an individual. And the solution always seems to be more institutional power, not individual power.

That kind of education in Engineering Ethics is common nowadays in University and College.

A lot of us who grew up self-educated in the early days or specialized in other schools may have missed out on those lessons early in our career.

And a person who goes through a Brazil-esque nightmare like that comes out at the end with a broken reputation. And always whispers and subtext floating around even after justice.

And there may be technically sophisticated intelligence services that can detect that kind of subtle tampering. But it's not the responsibility of other country's intelligence services to protect citizens of countries other than theie own.

Going through that I can say strength wouldn't be enough.

Re: India orders smartphone makers to preload state-owned cyber safety app

#760

Earlier quoted context omitted.

I don't think the government is going to treat it like a local district website. IRCTC, UPI, e-Filing portal seem to be working fine for the most part, so pretty sure they can make this work eventually.

IRCTC is a private company. UPI isn't government either. Which e-filling portal is working nicely for you? My ITR was stuck for more than a year because some lame ass dev couldn't show proper error message other than suggesting that something needed to be done by my bank (which wasn't the case and only a year later did I decide to dig into th3 dev tools). To praise Indian government is the most unlikely thing one sho…

> IRCTC is a private company.

Lol, at least do your research before writing random things.

Post reply on HN