[HN Gopher] Estonian Electronic Identity Card and Its Security C...
       ___________________________________________________________________
        
       Estonian Electronic Identity Card and Its Security Challenges [pdf]
        
       Author : IndrekR
       Score  : 59 points
       Date   : 2021-04-09 17:11 UTC (5 hours ago)
        
 (HTM) web link (dspace.ut.ee)
 (TXT) w3m dump (dspace.ut.ee)
        
       | julienreszka wrote:
       | E-garbage. Those kind of products should be constitutionally
       | forbidden. Same stands for electronic voting. Only safe ballot is
       | paper ballot and only in person not by mail. If you work in tach
       | and disagree you're either naive or incompetent.
        
       | motohagiography wrote:
       | End of section 2.4 contains this gem, "The manufacturing of ID
       | cards has always been a closed, non-transparent activity, not
       | open to scrutiny even to the manufacturer's contracting partner -
       | the Estonian state. The personalization protocols and procedures
       | have never beenpublicly documented, leaving the security aspects
       | of this process to bedetermined by the competency of the ID card
       | manufacturer. As described inSection 6.8 of this work, this lack
       | of supervision oversight allowed the ID cardmanufacturer to
       | engage in activities that compromised the ID card securitywithout
       | it being detected for years."
       | 
       | Card personalization is the bootstrapping problem, and there is
       | another one with potentially hostile readers creating DoS
       | conditions. I've worked on ID cards and digital identity in a few
       | areas in both private and public sectors, and the threat model
       | basically disappears into a cloud of spooky agencies, and it
       | comes out the other end as a vague consensus to just move
       | forward. If you think voting machines are unreliable you haven't
       | seen anything until you've looked into digital identity, as it's
       | a massive host of unresolved political problems tossed over the
       | fence onto technologists, and then laundered back through opaque
       | entities like the ones in this doc, then presented as a good
       | idea.
       | 
       | My impression of identity is it's not a technology problem, but
       | there are lots of people who will take your money to let you say
       | that it is.
        
       | c-linkage wrote:
       | I can't believe I get to say this: I actually worked on the pre-
       | cursor to this card!
       | 
       | The project was started in 2001 and was to develop ID cards for
       | immigrant workers that regularly crossed the border for work. The
       | purpose was to create an ID card that could not be forged or
       | tampered with.
       | 
       | The cards looked very similar to those in section 3.1 --
       | identifying information and a picture, with a passport-like
       | encoding. Unlike the picture in section 3.1, all of the
       | information was placed on the front of the card. When a new card
       | was produced, the software created a cryptographic hash of the
       | identifying information and the picture which was stored both on
       | the card's mag-stripe and in a central database.
       | 
       | When users were authenticated at the border, the card was placed
       | face-down on an optical scanner much like you see at airports
       | today. The software then computed a hash of both the personal
       | information and the picture. In offline mode the system would
       | compare the hash only to the hash on the mag-stripe, but in
       | online mode the system would connect to the central database to
       | verify the mag-stripe hash matched and existing entry in the
       | central database.
       | 
       | I think the Estonian government used that system for two or three
       | years.
       | 
       | The best part of this setup was that the system did not in any
       | way create a national registry. Instead, it proved the the ID
       | (token) was not tampered with and that the token had indeed been
       | created by a registered government authority.
       | 
       | Funny story: In early testing, I created an ID using my manager's
       | name and a photo of my co-worker's ass. I still have the card at
       | home somewhere. Who knows... it may still be in the database!
        
       | Etheryte wrote:
       | For context, this is the PhD thesis of Arnis Parsovs [0], a cyber
       | security researcher who has written on topics pertaining to the
       | Estonian electronic ID system since as early as 2013. You would
       | be hard pressed to find many people more familiar with the matter
       | -- even the public government reports aren't as detailed as this
       | is.
       | 
       | [0] https://www.etis.ee/CV/Arnis_Parsovs/eng
        
       | Bluestein wrote:
       | Proud e-resident here :)
        
         | toomuchtodo wrote:
         | US citizen here trying to champion such a system in the US.
         | Would you be willing to share pros and cons from your
         | experience using the system day to day?
        
           | Mediterraneo10 wrote:
           | US policy entangles US citizens and permanent-residency
           | holders in tax and banking nightmares for years. Often even
           | after a person has renounced their citizenship or residency,
           | banks in other countries will treat them as US tax subjects
           | anyway and impose onerous and privacy-violating reporting
           | requirements. I can't imagine the USA becoming a popular
           | country for e-residency until its tax policies are more
           | similar to other countries.
        
             | toomuchtodo wrote:
             | Apologies for not being clear, this is to support digital
             | ID modernization efforts, not support US e-residency for
             | those outside of the US.
        
           | Bluestein wrote:
           | Happy to!
           | 
           | I will probably post something somewhere when I actually get
           | to availing myself of the Residency status for what it was
           | planned for - the pandemic put the brakes on that a bit ...
           | 
           | So far, I can speak for the ease of the sign up process,
           | quality of the documentation, clarity and community behind
           | the effort. Oh, and, the tech. The tech is very well done.
           | Thoughtful integration -everywere-. Deep buy-in from the
           | state itself (this is a must, and - methinks - what makes it
           | all tick).-
           | 
           | To clarify: the tech is not "ground breaking" (yet?). It is
           | very run-of-the-mill cryptography, certificates, etc ...
           | 
           | It's the -degree- to which it has been implemented in the
           | whole "administrative stack", from government to stakeholders
           | (CPAs, SMBs, the self-employed), and how it has been
           | integrated into a coherent effort, that makes it work.-
           | 
           | Edit: To add to the insightful point below. Yes. A modern,
           | innovative and forward-thinking regulatory framework is a
           | sine qua non, and what has actually made any of this
           | possible. That regulatory overhaul (first) and support is the
           | the most important form "government buy-in" takes ...
        
           | gumby wrote:
           | The e-resident system is a great idea though the banking
           | support for e-residents is limited, mainly due to the (anti
           | money laundering) and anti fraud issues. That being said it's
           | still great: you can still open a company, have a local
           | presence, open a bank account and do business as an EU
           | entity, but certain domains are not accepted by every bank
           | (e.g. cryptocurrency), especially for e-residents who are
           | also resident (not necessarily citizens) of the USA.
           | 
           | Friends who are actually resident in Estonia tell me it's
           | pretty handy in their actual life.
           | 
           | A strong counterexample is Germany whose ID card also has a
           | similar SIM and robust encryption support. There the legal
           | implementation was seemingly designed in a way to thwart
           | adoption, by privatising the wrong part of the system such
           | that uptake has been nonexistent.
           | 
           | You can still sign something with a government-guaranteed key
           | by plugging your card into your computer, but that will only
           | help you communicate with other nerds. Fun to do once, but
           | other than that useless.
        
           | atlasunshrugged wrote:
           | Are you working with a specific org or initiative? I'm also
           | an American interested in this (and an e-resident who
           | formerly worked for the Estonian government).
        
             | toomuchtodo wrote:
             | Mostly activist citizen efforts from the outside, as
             | legislation is going to be required to appropriate funding
             | and direction from Congress, and the legislators I
             | interface with are busy with arguably more pressing work
             | (unfortunate but entirely understandable, such are the
             | times).
             | 
             | I intend to apply at the USDS for the Login.gov team in
             | some capacity to help on the tech side if the necessary
             | legislation can be put in place to support such an
             | initiative. Their system already supports the DOD CAC
             | (common access card), which is a short walk away from a
             | citizen digital ID card (would be a different org and PKI
             | root to administer and govern citizen cards, to grossly
             | simplify).
             | 
             | Login.gov recently expanded to support city and local gov
             | IAM needs (when they have ties to federal programs) [1]
             | [2], so there is roadmap momentum and executive branch
             | will. "Digital identity is a big deal. [3]" They're already
             | serving 30 million users, and 500k DAUs, really just a
             | matter of scaling up.
             | 
             | [1] https://www.gsa.gov/blog/2021/02/18/logingov-to-
             | provide-auth...
             | 
             | [2] https://www.govloop.com/login-gov-expands-use-to-
             | cities-stat...
             | 
             | [3] https://www.youtube.com/watch?v=YaZdpEp0eYs
        
               | atlasunshrugged wrote:
               | Cool, I've heard good things about USDS. My understanding
               | from Estonia is that really the challenge here isn't
               | technical (e.g. the tech exists and just needs to be
               | implemented) and what is really needed is legislative
               | changes but I certainly don't think it hurts to have
               | advocates in influential agencies in apolitical role. I
               | recently moved to DC and am trying to do some networking
               | and figuring out how I can influence some of these
               | topics. If you're considering USDS I recommend also
               | looking at Techcongress and Presidential Innovation
               | Fellows
        
               | Bluestein wrote:
               | > the challenge here isn't technical (e.g. the tech
               | exists and just needs to be implemented) and what is
               | really needed is legislative changes
               | 
               | Totally on point.
        
               | dogman144 wrote:
               | I get the spirit and a m familiar with the CAC and
               | general benefits, and using that for all .gov stuff is
               | attractive (taxes, bills, FASFA, etc)
               | 
               | I think you're glossing over two major implementation
               | factors that need to be part of the discussion from get-
               | go:
               | 
               | * how much CAC use is dependent on fairly specific govt
               | tech infra to be widely deployed, and how will that work
               | for everyone (ever tried to setup a CAC on a civ
               | computer)
               | 
               | * key control, either extremely decentralized like the
               | iPhone (lock yourself out of your passport?), or
               | extremely centralized and the newest honeypot OPM holds
               | (root cert for all e-citizen PKI). US currently doesn't
               | have the internal cybersec chops to run that at all
               | (closest equivalent is CISA).
        
               | toomuchtodo wrote:
               | You're right to point this out, but my counter argument
               | is that these are solvable pain points for such an
               | implementation (either done today in competent zero trust
               | security architectures in progressive orgs or at nation
               | state levels such as Estonia). You won't need a CAC
               | reader on computers, for the most part, if you have
               | mobile apps that can perform the identity proofing (such
               | that's already done with examples like Apple's biometrics
               | systems, FIDO2/WebAuthn, Apply Pay, etc). You'd still
               | have the card for interfacing at endpoints (banks, postal
               | service, IRS/SSA offices, other trust anchors and
               | government services endpoints). I already login to my US
               | CBP Global Entry account with Login.gov and 2FA, why can
               | I not today use the same IAM system to login to my Social
               | Security account? Or my IRS tax account? Or to attest to
               | my citizenship or other attributes that I'd normally need
               | a certified document for ( _yuk!_ ).
               | 
               | I'm not arguing for such a system without robust support
               | and reasonable downgrades for failure scenarios (identity
               | reproofing if you lose your digital ID, for example). I'm
               | arguing for, admittedly challenging, digital ID
               | modernization without disenfranchisement. I genuinely
               | appreciate you pointing out the challenges, as they must
               | be addressed.
               | 
               | US DHS CISA is absolutely a resource that needs to be
               | leaned on heavily to implement what I describe, and to
               | ensure a strong security posture throughout the federal
               | government's infrastructure.
        
       ___________________________________________________________________
       (page generated 2021-04-09 23:01 UTC)