[HN Gopher] Estonian Electronic Identity Card and Its Security C...
___________________________________________________________________
Estonian Electronic Identity Card and Its Security Challenges [pdf]
Author : IndrekR
Score : 59 points
Date : 2021-04-09 17:11 UTC (5 hours ago)
(HTM) web link (dspace.ut.ee)
(TXT) w3m dump (dspace.ut.ee)
| julienreszka wrote:
| E-garbage. Those kind of products should be constitutionally
| forbidden. Same stands for electronic voting. Only safe ballot is
| paper ballot and only in person not by mail. If you work in tach
| and disagree you're either naive or incompetent.
| motohagiography wrote:
| End of section 2.4 contains this gem, "The manufacturing of ID
| cards has always been a closed, non-transparent activity, not
| open to scrutiny even to the manufacturer's contracting partner -
| the Estonian state. The personalization protocols and procedures
| have never beenpublicly documented, leaving the security aspects
| of this process to bedetermined by the competency of the ID card
| manufacturer. As described inSection 6.8 of this work, this lack
| of supervision oversight allowed the ID cardmanufacturer to
| engage in activities that compromised the ID card securitywithout
| it being detected for years."
|
| Card personalization is the bootstrapping problem, and there is
| another one with potentially hostile readers creating DoS
| conditions. I've worked on ID cards and digital identity in a few
| areas in both private and public sectors, and the threat model
| basically disappears into a cloud of spooky agencies, and it
| comes out the other end as a vague consensus to just move
| forward. If you think voting machines are unreliable you haven't
| seen anything until you've looked into digital identity, as it's
| a massive host of unresolved political problems tossed over the
| fence onto technologists, and then laundered back through opaque
| entities like the ones in this doc, then presented as a good
| idea.
|
| My impression of identity is it's not a technology problem, but
| there are lots of people who will take your money to let you say
| that it is.
| c-linkage wrote:
| I can't believe I get to say this: I actually worked on the pre-
| cursor to this card!
|
| The project was started in 2001 and was to develop ID cards for
| immigrant workers that regularly crossed the border for work. The
| purpose was to create an ID card that could not be forged or
| tampered with.
|
| The cards looked very similar to those in section 3.1 --
| identifying information and a picture, with a passport-like
| encoding. Unlike the picture in section 3.1, all of the
| information was placed on the front of the card. When a new card
| was produced, the software created a cryptographic hash of the
| identifying information and the picture which was stored both on
| the card's mag-stripe and in a central database.
|
| When users were authenticated at the border, the card was placed
| face-down on an optical scanner much like you see at airports
| today. The software then computed a hash of both the personal
| information and the picture. In offline mode the system would
| compare the hash only to the hash on the mag-stripe, but in
| online mode the system would connect to the central database to
| verify the mag-stripe hash matched and existing entry in the
| central database.
|
| I think the Estonian government used that system for two or three
| years.
|
| The best part of this setup was that the system did not in any
| way create a national registry. Instead, it proved the the ID
| (token) was not tampered with and that the token had indeed been
| created by a registered government authority.
|
| Funny story: In early testing, I created an ID using my manager's
| name and a photo of my co-worker's ass. I still have the card at
| home somewhere. Who knows... it may still be in the database!
| Etheryte wrote:
| For context, this is the PhD thesis of Arnis Parsovs [0], a cyber
| security researcher who has written on topics pertaining to the
| Estonian electronic ID system since as early as 2013. You would
| be hard pressed to find many people more familiar with the matter
| -- even the public government reports aren't as detailed as this
| is.
|
| [0] https://www.etis.ee/CV/Arnis_Parsovs/eng
| Bluestein wrote:
| Proud e-resident here :)
| toomuchtodo wrote:
| US citizen here trying to champion such a system in the US.
| Would you be willing to share pros and cons from your
| experience using the system day to day?
| Mediterraneo10 wrote:
| US policy entangles US citizens and permanent-residency
| holders in tax and banking nightmares for years. Often even
| after a person has renounced their citizenship or residency,
| banks in other countries will treat them as US tax subjects
| anyway and impose onerous and privacy-violating reporting
| requirements. I can't imagine the USA becoming a popular
| country for e-residency until its tax policies are more
| similar to other countries.
| toomuchtodo wrote:
| Apologies for not being clear, this is to support digital
| ID modernization efforts, not support US e-residency for
| those outside of the US.
| Bluestein wrote:
| Happy to!
|
| I will probably post something somewhere when I actually get
| to availing myself of the Residency status for what it was
| planned for - the pandemic put the brakes on that a bit ...
|
| So far, I can speak for the ease of the sign up process,
| quality of the documentation, clarity and community behind
| the effort. Oh, and, the tech. The tech is very well done.
| Thoughtful integration -everywere-. Deep buy-in from the
| state itself (this is a must, and - methinks - what makes it
| all tick).-
|
| To clarify: the tech is not "ground breaking" (yet?). It is
| very run-of-the-mill cryptography, certificates, etc ...
|
| It's the -degree- to which it has been implemented in the
| whole "administrative stack", from government to stakeholders
| (CPAs, SMBs, the self-employed), and how it has been
| integrated into a coherent effort, that makes it work.-
|
| Edit: To add to the insightful point below. Yes. A modern,
| innovative and forward-thinking regulatory framework is a
| sine qua non, and what has actually made any of this
| possible. That regulatory overhaul (first) and support is the
| the most important form "government buy-in" takes ...
| gumby wrote:
| The e-resident system is a great idea though the banking
| support for e-residents is limited, mainly due to the (anti
| money laundering) and anti fraud issues. That being said it's
| still great: you can still open a company, have a local
| presence, open a bank account and do business as an EU
| entity, but certain domains are not accepted by every bank
| (e.g. cryptocurrency), especially for e-residents who are
| also resident (not necessarily citizens) of the USA.
|
| Friends who are actually resident in Estonia tell me it's
| pretty handy in their actual life.
|
| A strong counterexample is Germany whose ID card also has a
| similar SIM and robust encryption support. There the legal
| implementation was seemingly designed in a way to thwart
| adoption, by privatising the wrong part of the system such
| that uptake has been nonexistent.
|
| You can still sign something with a government-guaranteed key
| by plugging your card into your computer, but that will only
| help you communicate with other nerds. Fun to do once, but
| other than that useless.
| atlasunshrugged wrote:
| Are you working with a specific org or initiative? I'm also
| an American interested in this (and an e-resident who
| formerly worked for the Estonian government).
| toomuchtodo wrote:
| Mostly activist citizen efforts from the outside, as
| legislation is going to be required to appropriate funding
| and direction from Congress, and the legislators I
| interface with are busy with arguably more pressing work
| (unfortunate but entirely understandable, such are the
| times).
|
| I intend to apply at the USDS for the Login.gov team in
| some capacity to help on the tech side if the necessary
| legislation can be put in place to support such an
| initiative. Their system already supports the DOD CAC
| (common access card), which is a short walk away from a
| citizen digital ID card (would be a different org and PKI
| root to administer and govern citizen cards, to grossly
| simplify).
|
| Login.gov recently expanded to support city and local gov
| IAM needs (when they have ties to federal programs) [1]
| [2], so there is roadmap momentum and executive branch
| will. "Digital identity is a big deal. [3]" They're already
| serving 30 million users, and 500k DAUs, really just a
| matter of scaling up.
|
| [1] https://www.gsa.gov/blog/2021/02/18/logingov-to-
| provide-auth...
|
| [2] https://www.govloop.com/login-gov-expands-use-to-
| cities-stat...
|
| [3] https://www.youtube.com/watch?v=YaZdpEp0eYs
| atlasunshrugged wrote:
| Cool, I've heard good things about USDS. My understanding
| from Estonia is that really the challenge here isn't
| technical (e.g. the tech exists and just needs to be
| implemented) and what is really needed is legislative
| changes but I certainly don't think it hurts to have
| advocates in influential agencies in apolitical role. I
| recently moved to DC and am trying to do some networking
| and figuring out how I can influence some of these
| topics. If you're considering USDS I recommend also
| looking at Techcongress and Presidential Innovation
| Fellows
| Bluestein wrote:
| > the challenge here isn't technical (e.g. the tech
| exists and just needs to be implemented) and what is
| really needed is legislative changes
|
| Totally on point.
| dogman144 wrote:
| I get the spirit and a m familiar with the CAC and
| general benefits, and using that for all .gov stuff is
| attractive (taxes, bills, FASFA, etc)
|
| I think you're glossing over two major implementation
| factors that need to be part of the discussion from get-
| go:
|
| * how much CAC use is dependent on fairly specific govt
| tech infra to be widely deployed, and how will that work
| for everyone (ever tried to setup a CAC on a civ
| computer)
|
| * key control, either extremely decentralized like the
| iPhone (lock yourself out of your passport?), or
| extremely centralized and the newest honeypot OPM holds
| (root cert for all e-citizen PKI). US currently doesn't
| have the internal cybersec chops to run that at all
| (closest equivalent is CISA).
| toomuchtodo wrote:
| You're right to point this out, but my counter argument
| is that these are solvable pain points for such an
| implementation (either done today in competent zero trust
| security architectures in progressive orgs or at nation
| state levels such as Estonia). You won't need a CAC
| reader on computers, for the most part, if you have
| mobile apps that can perform the identity proofing (such
| that's already done with examples like Apple's biometrics
| systems, FIDO2/WebAuthn, Apply Pay, etc). You'd still
| have the card for interfacing at endpoints (banks, postal
| service, IRS/SSA offices, other trust anchors and
| government services endpoints). I already login to my US
| CBP Global Entry account with Login.gov and 2FA, why can
| I not today use the same IAM system to login to my Social
| Security account? Or my IRS tax account? Or to attest to
| my citizenship or other attributes that I'd normally need
| a certified document for ( _yuk!_ ).
|
| I'm not arguing for such a system without robust support
| and reasonable downgrades for failure scenarios (identity
| reproofing if you lose your digital ID, for example). I'm
| arguing for, admittedly challenging, digital ID
| modernization without disenfranchisement. I genuinely
| appreciate you pointing out the challenges, as they must
| be addressed.
|
| US DHS CISA is absolutely a resource that needs to be
| leaned on heavily to implement what I describe, and to
| ensure a strong security posture throughout the federal
| government's infrastructure.
___________________________________________________________________
(page generated 2021-04-09 23:01 UTC)