[HN Gopher] Hacker downloads close to 300k personal ID photos fr...
       ___________________________________________________________________
        
       Hacker downloads close to 300k personal ID photos from Estonian gov
       database
        
       Author : chrismeller
       Score  : 247 points
       Date   : 2021-07-29 07:33 UTC (15 hours ago)
        
 (HTM) web link (news.err.ee)
 (TXT) w3m dump (news.err.ee)
        
       | beezischillin wrote:
       | Last year my government (Eastern Europe) started requiring some
       | extra documentation to be submitted by companies, yearly, after
       | it passed a law to do so. It being a strange time in human
       | history they had to twist themselves in all sorts of knots to try
       | and make that possible so they gave in and - I assume - they put
       | out a giant government contract searching for an IT company to
       | make that happen. And make it happen they did, through usual
       | nefarious means or otherwise, that much is unknown but they
       | created a portal. You could enter your details and it would
       | return you a document to download and sign and hand off to the
       | nearest government agency that was officially supposed to handle
       | these. And so my friend got to work... first thing he noticed:
       | the whole thing was insanely slow and then he took a look at the
       | URL and found that it was basically someone's Windows PC, just
       | serving the entire C:/ drive on a public URL. Even worse, all the
       | documents generated (which contained all data, private and public
       | related to the company owner - even ID data) were named in an
       | incremental fashion. Meaning that you could've, were you a bad
       | actor, dump pretty much the entire country's privately owned
       | business owners' details with a simple bash script.
       | 
       | So he took it upon himself and called the specific government
       | branch...
       | 
       | ... and within an hour the whole portal was offline and the
       | deadlines ended up being extended. This year was the earliest
       | time I needed to submit said paperwork.
       | 
       | Handling stuff online is not easy and sometimes goes very wrong.
       | That being said, for most general company admin things you need
       | to do here you can buy a hardware cert and avoid this entire risk
       | and they're supposed to be rolling out IDs with similar features
       | and a similar promise in August. Though as to how that will
       | function, I have no idea as I couldn't find any info on it.
        
       | rrrrrrrrrrrryan wrote:
       | This is sad.
       | 
       | Estonia's government is exceptionally forward-thinking when it
       | comes to embracing technology (they've had internet voting since
       | 2005, for example), but ultimately they're still a smaller nation
       | and it sucks to see them get burned.
       | 
       | Some more info:
       | https://www.newyorker.com/magazine/2017/12/18/estonia-the-di...
        
         | Proven wrote:
         | If they were forward thinking they wouldn't have collected that
         | PII
        
         | systemvoltage wrote:
         | Appearance of forward-thinking and actual boots-on-the-ground
         | situation can vary widely. Especially with governments - you
         | might be suprised how many things are just held on stilts
         | behind the scenes. When it comes to security, I have zero trust
         | in the government ID programs.
        
         | codedokode wrote:
         | Internet voting that cannot be independently verified and
         | monitored is just a fraud.
        
       | roddux wrote:
       | So when can we expect ThisEstonianDoesNotExist?
        
       | DocG wrote:
       | It was a oversight in picture program. Basically you can always
       | request your own photo and the hacker already had names and ID
       | codes and was able to use legimate access to download photos. He
       | did use botnet, with many computers so it seemed legimate
       | traffic. And was apprehended literally the next day.
       | 
       | Stolen pictures were not forwarded, so they even got the leaked
       | data back.
       | 
       | Dunno, not a big deal.
       | 
       | Only thing was he was downloading pictures en masse. Names and ID
       | codes got from elsewhere beforehand. ID code is not a secret here
       | either, you can reconstruct it with high accuracy just by knowing
       | persons birthday and city he lives.
       | 
       | Tho I think this triggered a fast lane for upgrading some legacy
       | stuff that was to be updated soon. So good scare I think.
        
         | thih9 wrote:
         | > Stolen pictures were not forwarded, so they even got the
         | leaked data back.
         | 
         | Can we be certain that the hacker didn't make any copies?
        
       | codedokode wrote:
       | Does truly democratic society need identity card and databases?
       | Do people need to be tracked since their birth as if they were
       | someone's property?
       | 
       | Also, such leaks can be dangerous. If someone is hiding from
       | authoritarian government then the stolen data can be used to
       | track and assasinate them.
        
       | flemhans wrote:
       | Why were they storing them in the first place?
        
         | Dma54rhs wrote:
         | Very few governments don't store data like that, America and it
         | lack of standardized documentation is an outliner in the
         | developed world.
        
           | drstewart wrote:
           | Do you have a source for this? I'm curious to see a chart of
           | "centralization of standardized documentation" by country to
           | validate your claims.
        
             | Dma54rhs wrote:
             | Source for what, it's so common knowledge that you should
             | list countries that don't do centralized id besides USA in
             | the developed world. Search for voting id laws is probably
             | a good start.
             | 
             | https://www.consilium.europa.eu/en/press/press-
             | releases/2019...
             | 
             | These are from 2019,but the documents have always existed.
             | And each country is using this guideline for their
             | countries.
        
               | johannes1234321 wrote:
               | having a givernment issued ID neither means all data is
               | being stored, nor that itnis stored centralized.
               | 
               | In Germany for instance most data is held by the
               | municipality and centralization happens slowly and
               | centralizing pictures is only a recent proposal.
        
               | croes wrote:
               | Because it's not necessary. Since 2017 police and secret
               | agencies can access all photos 24/7 per web access.
        
               | est31 wrote:
               | The centralization proposal the person you are replying
               | to was done because that API access you are talking about
               | apparently hasn't been implemented in a wide spread
               | manner. So now each Bundesland can create their own
               | database.
               | 
               | https://www.golem.de/news/trotz-kritik-smartphone-
               | ausweis-un...
        
           | wil421 wrote:
           | Not according to comments on this post. Lots of governments
           | in Europe keep records at the city and state level. Unless
           | they are passports.
        
             | sofixa wrote:
             | Like which ones? I can't see the comments you're referring
             | to.
        
               | wil421 wrote:
               | Look at johannes1234321 comment below.
        
             | Dma54rhs wrote:
             | Its all centrally forced, the security, the implementation.
             | They are printed the same place, same way, a lot of
             | directives straight from Brussels.
        
             | sp332 wrote:
             | And the passports have photos, right?
        
             | onion2k wrote:
             | The UK isn't technically in Europe any more (except
             | geographically), but there are no city or state (county)
             | level photo IDs here. Everything is national and managed by
             | the central government.
        
               | ithinkso wrote:
               | It's in Europe the same way it has always been. UK is no
               | longer in the EU
        
               | alibarber wrote:
               | And even within the EU I'd still wager that there are
               | many different systems in different countries. Almost
               | like it's a block of diverse individual nations and not
               | just a single entity that you can make lazy comparisons
               | with.
        
         | djbebs wrote:
         | Are you asking why the estonian government was storying
         | identity information?
        
           | wutwutwutwut wrote:
           | Yes, he was. Many people in US specifically does not seem to
           | have knowledge about how other countries are governed.
        
             | vletal wrote:
             | Well, is not it simply because the rest of us living
             | outside of the US are frequently exposed to US politics via
             | mainstream media? Since there is 160+ countries in the
             | world, this exposure can be hardly symmetrical.
        
               | wutwutwutwut wrote:
               | I'm sure, but even as a person living in the US, having
               | knowledge on how your own country differs from all others
               | make sense.
        
             | Symbiote wrote:
             | Presumably the US government stores passport photographs,
             | and the state governments store driving license
             | photographs.
             | 
             | (Estonia has a similar population to Maine or New
             | Hampshire, 1.3 million people.)
        
               | runako wrote:
               | Only ~30% of Americans have a passport, so the passport
               | database is nothing like comprehensive.
        
               | yostrovs wrote:
               | They do now. There was a time when you could go to the
               | DMV and switch places with your friend right before the
               | photo for the ID was taken. If you were under 21 and your
               | friend was older, you had a real fake ID made for you by
               | the state. At least in Illinois that was the case when I
               | was still underage. Now they do see the older photo come
               | up when renewing a license, presumably to prevent
               | swapping.
        
               | code_duck wrote:
               | Someone I know did this with his brothers documents
               | without his brother being involved. He took the documents
               | to the DMV and said he lost his license. Pretty much all
               | they had to go on was basic appearance metrics and
               | questions like where you got your license last time. This
               | was in the 90s so it's possible it might not be as easy
               | now.
        
               | ghaff wrote:
               | In my state, and I assume most/all(?) others, it's all
               | electronic. When I had to replace a lost license a few
               | years back, it was very easy. Go to a website and pay $25
               | or whatever. But there's no new photo involved.
        
               | adolph wrote:
               | A distant acquaintance did that in the early 90s, only
               | that person asked for a new drivers license. The clerk
               | attempted to offer a duplicate instead of a new license
               | and the nervous license getter refused until the clerk
               | said, "look I'm trying to save you some money, we still
               | take your picture and give you the license today!"
        
               | Aaargh20318 wrote:
               | > There was a time when you could go to the DMV and
               | switch places with your friend right before the photo for
               | the ID was taken.
               | 
               | But wouldn't that mean your friend no longer had a valid
               | drivers license ?
        
               | code_duck wrote:
               | The old license is not effectively invalidated in any
               | way. Almost nobody you presented the license to would
               | know that another one has been issued, besides possibly a
               | police officer. It would be fairly easy to tell them that
               | you got a replacement and then found the old one.
        
               | Aaargh20318 wrote:
               | > The old license is not effectively invalidated in any
               | way. Almost nobody you presented the license to would
               | know that another one has been issued
               | 
               | That's strange. Where I live, if you get a new ID you
               | have to turn in your old one. You can keep a passport if
               | you want (some people like to if they have a ot of stamps
               | from their travels) but in that case they punch a couple
               | of big holes through the entire booklet before returning
               | it to you (basically, it removes the chip and some other
               | security measures).
        
               | code_duck wrote:
               | They do ask you to do that, but what if you lost it?
        
               | Aaargh20318 wrote:
               | If you lost it you have to go to the police and report it
               | lost. Then you need to hand over the police report when
               | you request a new one. Reporting it lost or stolen also
               | invalidates your drivers license meaning you can't drive
               | while you wait for your new license.
        
               | code_duck wrote:
               | I see. In what region are you referring to? I have never
               | lived in a state with any sort of concept of rendering
               | your license invalid because you lost a physical license,
               | nor have I been told to file a police report.
               | 
               | I looked it up for my state and they said you only must
               | file a police report if you believe your license has been
               | stolen, not lost, and you desire a new number. I'm sure
               | policies differ among states.
               | 
               | I picked Michigan at random. Their website merely warns
               | that the old license will be invalidated electronically
               | and cannot be used for border crossing while encouraging
               | use of online replacement services.
               | 
               | https://www.michigan.gov/sos/0,4670,7-127-1627_8669_53328
               | ---...
        
               | nly wrote:
               | Seems like a dumb thing for your friend to do for you
               | when that photo will be part of a permanent database.
        
               | Talanes wrote:
               | The purpose of that anecdote was to demonstrate that
               | there was no database at that time.
        
               | sneak wrote:
               | State governments have to turn over all of the DL/ID data
               | to the feds these days under the new backdoor federal ID
               | law ("Real ID").
        
               | code_duck wrote:
               | From what I recall, in a fairly recent traffic stop in my
               | home state the police officer had access to all of my
               | license information including the photo.
        
             | flemhans wrote:
             | I'm from Denmark, not the US, and they don't store my
             | picture by default. The passport picture is stored in the
             | chip and then supposedly discarded.
        
         | chrismeller wrote:
         | Multiple reasons, just like CBP in the US can pull up your
         | photo to make sure the one on the ID and standing in front of
         | them is actually the person the system says it is.
         | 
         | They also compared my old ID photo with the new photo I was
         | submitting when I renewed it recently for the same reason.
         | 
         | Though I've never had this particular problem, I believe the
         | police will also do the same thing to verify they're arresting
         | or ticketing the right person.
         | 
         | Also keep in mind that Estonia is the size of a (quite) small
         | state in the US, so they're storing things like a driver's
         | license photo just like your state would. You actually don't
         | need a physical driver's license with you in Estonia as long as
         | it's linked to your ID card, so it's really an "all your eggs
         | in one basket" kind of system.
        
       | TekMol wrote:
       | IDs have become a joke. People have been handing them out for
       | copying to hotels, websites and apps like candy.
       | 
       | We need to replace IDs with chips that do not give away their
       | secret key but only sign stuff you throw at them.
       | 
       | So when a website or hotel wants to know "Hey, are you really Joe
       | Doe?" it sends this message to the "ID" and the "ID" sends it
       | back with "yes" and signed.
       | 
       | This way we can identify ourselfes without giving the other party
       | the ability to identify as us from now on.
        
         | Taylor_OD wrote:
         | Wait till you hear about SSN. Which were created specifically
         | not to be used for identification.
        
           | jaanjalgratas wrote:
           | Why are you scared of sharing SSN? In Estonia it's called
           | Personal Code and it doesn't have any special status, just
           | your unique digital name. We have left these days behind
           | dozen years ago when banks used asking Personal Code as a
           | security measure.
        
             | labster wrote:
             | SSN is not a Personal Code. It's just a number. Add or
             | subtract one, and you get the a valid number for the people
             | in your home town who were born nearest to your birthdate.
             | There are no checks and it's very difficult to change. Some
             | people in the USA would like a better system, but we can't
             | have it because national IDs and vaccines are tyranny.
        
             | rtuulik wrote:
             | Estionian Personal Code number works just as a unique
             | identifying number. American Social Security Number work
             | both as an unique identifying number AND as a verification
             | of identity. Basically its similar to estonian ID number,
             | but instead of PIN1 and PIN2 you have just the SSN.
        
             | lazide wrote:
             | SSN is used by many, many entities as a 'secret security
             | code' essentially. Including (still) many banks, government
             | offices, etc.
             | 
             | It's also used for things like tracking of tax liabilities
             | - so if someone has your SSN, with some minor fudging of
             | other data there have been historic issues like claiming
             | tax overpayments and getting checks from the government.
             | 
             | It's incredibly dumb, but it is what it is (mostly still).
             | 
             | At least most of the big players aren't quite as dumb about
             | it as they used to be.
        
         | 2Gkashmiri wrote:
         | You know, that was the original idea with indian "Aadhar". I am
         | talking about keeping up with its news on tech magazines back
         | in 2007 when it was lauded as a FOSS achievement. The idea from
         | what I can recall now was "yinput your id, you put your finger
         | on.the reader and the backend sends a "yes/no" with a hash of
         | the authentication. Thats it"
         | 
         | Over subsequent years, politics fucked it up bad. They made it
         | "compulsory". Then people started asking for photocopies. Then
         | scans. Then people would keep and then buy and sell these scans
         | in bulk. Then people started putting phones with multiple
         | cards, like entire villages would be one computer operator who
         | would keep his own phone for "otp". That operator would then
         | sell access which would be bought for buying Sim cards, shit
         | and frauds.
         | 
         | Then you have the political appiontees who run this Aadhar
         | system, those pompous assholes claim they are unhackable. Come
         | on.
         | 
         | Sadly they built a Pandoras box now with 1.3 billion almost
         | demographic data, biometric data and that is scary.
        
         | IfOnlyYouKnew wrote:
         | I don't know how copies of my ID being made turns it into a
         | joke? There isn't anything secret on my ID, and just knowing
         | the information and having a picture is to impersonating me as
         | putting on running shoes is to drawing an owl.
        
         | w3ll_w3ll_w3ll wrote:
         | Most newly issued identity cards in Europe work that way. They
         | have a private key stored in the chip, that can be used to
         | prove identity, without giving the ability to the other party
         | to impersonate the citizen.
         | 
         | Unfortunately most places still check these type of cards
         | visually, but I hope that electronic verification will become
         | more common in a few years.
         | 
         | For example these cards can be checked very easily simply using
         | an NFC Android phone and the right app.
         | 
         | In US for something similar you can look at ICAO passports and
         | Enhanced driver's license,
        
           | rjzzleep wrote:
           | For a lot of things I have to send photos of passports
           | around, in wechat, whatsapp, line and whatever other BS other
           | people request. The other day I was requested to give a new
           | copy of my updated passport to a local telco with abysmal
           | security, just to be able to return a SIM card to get my
           | security deposit back. WHY?
           | 
           | It's infuriating. Governments still use a 100 year old system
           | of stamping each others documents in overseas missions to
           | confirm the authenticity of a document that is based in an
           | era where there was neither telephone nor internet. The whole
           | world runs on a bad joke.
           | 
           | The thing that's different about the three baltics is that
           | their crypto is open source and has had many iterations. They
           | even sued Gemalto for an insecure revision IIRC. All of the
           | signing code is open source on top of that.
           | 
           | The way Germany works is that they design something in a
           | committee for 20 years in private, then they push it out to
           | public. Then the CCC finds security issues in there, then the
           | government ignores it and changes the law to force you to use
           | it anyway. One thing I will give the Germans is that in legal
           | interaction with their official institutions they will allow
           | you to blacken out PII from the identity card. But no private
           | institution does that so it's kinda pointless.
        
             | w3ll_w3ll_w3ll wrote:
             | Yes it will be a long time until we are able to change this
             | old habits.
             | 
             | But you can put it another way: if someone commit am
             | identity fraud using a picture of your ID, you can defend
             | yourself showing that you were required by many different
             | entities to send a copy of your ID. So there are many
             | parties that could have leaked your ID and a picture of you
             | ID cannot be considered a prove that you authorized or
             | allowed anything.
             | 
             | Case dismissed :)
        
               | rjzzleep wrote:
               | Unfortunately no, when people commit identity fraud using
               | your ID, you're the one that needs to prove your
               | innocence. In the US for example it's so easy to commit
               | identity fraud, but really hard to get out of the damage
               | someone else may have done to you.
        
               | mikem170 wrote:
               | You mentioned the burden of proof being on the victim of
               | identity theft. Is that applicable to anything besides
               | ones credit report?
               | 
               | If creditors want to get a judgement to garnish wages or
               | seize assets they have to go to court. I wonder if the
               | burden of proof is any different there, or if the
               | parent's defence (everybody has a copy of my
               | identification!) could work at that point?
        
               | lazide wrote:
               | The damage of identify theft is the damaged credit
               | report, and the fact you now have to explain to every
               | entity you do business with what happened - and hope they
               | believe you. Many won't because it isn't worth the risk
               | to them.
               | 
               | Garnished wages are pretty rare from what I've heard, and
               | yes it rarely gets to that point. It's still a nightmare
               | for many people with real world consequences if it
               | happens to you.
        
               | mikem170 wrote:
               | I understand the impact a problem on a credit report can
               | have for most people.
               | 
               | Over the years I've been trying to minimize my dependence
               | on credit reports. It's been frozen for most of a couple
               | decades, and I'd like to keep it that way. I've paid cash
               | for vehicles, use secured credit cards, put down a
               | deposit for my utility service, have a pay as you go
               | phone, rent from people I know, and hope to remain self-
               | employed, or work for people who know me enough to know
               | that I can be trusted. I'd rather not deal with BigCorp.
               | I realize that not everyone wants to or can do these
               | things.
               | 
               | But that left me wondering about what would happen in a
               | trial to get a judgement if someone was able to
               | fraudulently open a line of credit in my name. I'm hoping
               | that a judge would require more than a forged signature
               | to seize my wages/assets. Personally this is what I worry
               | about, not so much my credit report.
        
               | lazide wrote:
               | It has happened, it is rare though. Also know of a few
               | cases of folks selling peoples houses out from under them
               | by fooling the title company when they were on a long
               | vacation. Realistically, most thieves are far too lazy,
               | and it's real (and risky) work doing that compared to
               | doing a bunch of credit card fraud.
        
               | skeeter2020 wrote:
               | "Identity fraud" or worse, "identity theft" are BS terms
               | made up by the organizations responsible for the actual
               | underlying crime. Example: a criminal gets credit cards
               | issued in your name and your bank screams "Identity
               | Theft!" when this is just good ol' fashioned fraud
               | enabled by their crappy process and antiquated security.
               | The difference is the former is your problem while the
               | latter is all theirs. Plus they get the chance to sell
               | you another service to protect you from their mess.
               | $PROFIT !!!
        
               | flotzam wrote:
               | "I seem to have my identity, whereas you seem to have
               | lost several thousands of pounds."
               | https://www.youtube.com/watch?v=CS9ptA3Ya9E
        
             | Spooky23 wrote:
             | The old stuff is still around because it works.
             | 
             | New fancy integration, digital signatures, etc are still
             | protecting a process that's unreliable fundamentally. It's
             | all anchored to your birth certificate, and in the US
             | that's controlled by thousands of jurisdictions with
             | varying competence.
             | 
             | The most secure scenarios (cleared employees), tie your
             | credentials to biometrics, and vet your origin as a control
             | for fraud. Everything else increases the risk of fraud as a
             | trade off for convenience or privacy. (Your cellphone
             | carrier doesn't need to vet where you went to elementary
             | school)
        
               | LeifCarrotson wrote:
               | It works for the requirements of the people who are
               | running it, not necessarily those who use it.
               | 
               | The differentiator is that when an incompetent
               | jurisdiction gives away your ID, it's your loss, not
               | theirs. When hackers spoof a business with your
               | credentials to perform industrial espionage or plant
               | ransomware, it's the business that loses, not you. An
               | incompetent jurisdiction can continue operation
               | indefinitely, they just have unhappy, powerless citizens.
               | An incompetent business will suffer financial losses and
               | fail.
        
               | Spooky23 wrote:
               | It's more nuanced than that.
               | 
               | The village clerk in some Indian reservation in South
               | Dakota probably doesn't have a process that looks like
               | the NYC department of Health for vital records. But
               | people live for a long time, and errors and omissions do
               | too.
               | 
               | The point is, you can establish identity, but it's a pain
               | in the ass. I need to provide a drivers license to open a
               | savings account, but anyone with my SSN can open a credit
               | card.
        
               | RaptorJ wrote:
               | Any day now Equifax is going down. The real difference is
               | that humans have some institutional power over political
               | jurisdictions and how they are run and exactly none over
               | how (large enough) businesses are.
        
             | ectopod wrote:
             | They add friction to any outgoing payment because some
             | proportion of customers will walk away and then they will
             | have more money.
             | 
             | Other organisations (especially banks) will collect far
             | more information than is legally required for KYC because
             | they can use it for marketing.
             | 
             | But why does a 50 cent SIM card need a security deposit?
        
           | 0xffff2 wrote:
           | >In US for something similar you can look at ICAO passports
           | and Enhanced driver's license,
           | 
           | I'm not sure what you mean be "Enhanced driver's license",
           | but my RealId driver's license doesn't seem to have a chip in
           | it, just an excess of holographic overlays.
        
             | rrrrrrrrrrrryan wrote:
             | Enhanced driver's licenses are different: they have a chip,
             | and right now they are only available in 4 states near the
             | Canadian border.
             | 
             | https://blog.americansafetycouncil.com/enhanced-drivers-
             | lice...
        
           | gumby wrote:
           | Unfortunately Germany deliberately borked the encryption
           | ecosystem so it's useless there. And many of the the smaller
           | countries have trouble building out the infrastructure with
           | everything else on their plate (Estonia being a significant
           | exception).
        
             | w3ll_w3ll_w3ll wrote:
             | Do you have more information on how Germany deliberately
             | borked the encryption ecosystem?
        
               | gumby wrote:
               | Sure. The key is "ecosystem". A technical flaw
               | notwithstanding, the PKI itself seems fine (Estonia also
               | had a technical problem in this regard).
               | 
               | However the cards were simply rolled out: essentially the
               | only practical difference for anyone between the old
               | cards and the new was that there was a chip in it. But
               | there was no surrounding infrastructure: government
               | didn't take it, banks didn't take it -- there was no
               | practical benefit. There were no mandates for use, no
               | examples or or incentives. The country made greater
               | provision for spelling reform than they did for the E-ID.
               | There was a lot of unease about the idea of all that
               | tracking...yet the card itself already leaks lots of
               | unnecessary personal info (e.g. address) to anyone who
               | glances at it.
               | 
               | Compare this to countries like Estonia who made a point
               | of using the card as the easiest way to unlock government
               | services and made it easy for companies to do the same.
               | 
               | This is touched on in English in this recent article:
               | https://www.theguardian.com/world/2021/may/22/new-id-law-
               | aim...
        
               | rjzzleep wrote:
               | Don't know what he means, but there were a couple of
               | security vulnerabilities in the past. The German gvt.
               | didn't really address how it was improved, but gave a
               | security certification award to it.
               | 
               | https://www.ccc.de/de/updates/2010/sicherheitsprobleme-
               | bei-s...
        
               | zeeZ wrote:
               | Their problem with the German ID was that cheap readers
               | did not have a keypad, so you'd have to enter your PIN on
               | the PC, which could be infected with a trojan.
               | 
               | It's sad that this myth that "eID is insecure" has stuck
               | around, because it's just not true. Their problems have
               | all been with auxiliary devices or software, not the eID
               | itself.
        
               | tinus_hn wrote:
               | I'm pretty sure you can read people's birthdays using NFC
               | where the N for near is up to the attacker.
        
           | disabled wrote:
           | Yep. All European Union countries are eventually going to use
           | electronic IDs (eID) with Smartchips that can be read by a
           | Smart Card reader.
           | 
           | A number of governments already use eIDs, and have elaborate
           | databases for citizens, such as Croatia. See:
           | https://gov.hr/en
           | 
           | There are also other forms of government facilitated
           | authentication (e.g. electronic signatures or citizen
           | services), and depending on the level of security needed.
           | 
           | It's amazing that the United States does not have this
           | functionality, which would be useful moving from state to
           | state.
           | 
           | I guess the US passport card is the closest example, but it
           | is useless except as identification.
        
             | cromka wrote:
             | >All European Union countries are eventually going to use
             | electronic IDs (eID) with Smartchips that can be read by a
             | Smart Card reader.
             | 
             | As far as I know there's a deadline for it and we just
             | passed it.
        
             | dragonwriter wrote:
             | > It's amazing that the United States does not have this
             | functionality, which would be useful moving from state to
             | state.
             | 
             | The US does have it, used in both passports and "Enhanced
             | Driver's Licenses" meeting the federal requirements for
             | that label. I think only a couple states currently issue
             | EDLs.
             | 
             | > I guess the US passport card is the closest example, but
             | it is useless except as identification.
             | 
             | Almost any place that requires government ID, IME, accepts
             | passports; they aren't at all useless as ID.
        
               | disabled wrote:
               | The point I was trying to make is that in many countries
               | in Europe, we can use our electronic IDs to do a lot of
               | things in everyday life that cannot be done online in the
               | US. You can see all of the services we can access in
               | Croatia here: https://gov.hr/en/catalogue-of-services/10
               | 
               | The eIDs also require a biometric picture of your face
               | and 2 fingerprints, which are encoded into the card, as
               | required by European Union regulation.
               | 
               | When I am ready to I can even apply for my European
               | Engineer license online on that portal, with my eID using
               | a Smartcard reader on PC (highest level of security for
               | authentication of credentials).
        
           | jjcc wrote:
           | Most of the ID verification systems use "What you know"(PIN
           | or password), "What you have"(ID Card or Phone),"Who you
           | are"(biometrics, i.e. finger print hash), using 1 factor or
           | combination of 2 factors. For verification, storing hash on
           | server is good enough.
           | 
           | If we use safely stored finger print hash in ID
           | cards/Passports/Phones (Iris is better but expensive), the
           | stolen IDs from server have less value to hackers. ICAO
           | standard already includes secure storage of the biometrics
           | data long time ago but not many countries implement yet.
           | Finger print sensor is widely adopted in mobile phones.
           | Anyway the technology exists. Maybe some identity theft
           | incidents will push the government and the industry to
           | implement the solutions
        
         | SavantIdiot wrote:
         | So I just steal your ID. You still need a PIN and/or biometric
         | authentication.
        
         | GoblinSlayer wrote:
         | What if the website sends "Hey, do you want to take a large
         | credit?"?
        
           | w3ll_w3ll_w3ll wrote:
           | Authentication and digital signatures (like for signing
           | contracts) are usually kept separate on electronic cards.
           | There are already standards for that.
        
         | megous wrote:
         | I don't think I have many ID cards without chips anymore. Maybe
         | EU health care insurance card doesn't have one. Everything else
         | has wireless chips.
        
         | foepys wrote:
         | This is already possible with the German ID card (nPA). It can
         | also verify if you are over a certain age without giving out
         | your data. You also cannot read the nPA without a PIN code. It
         | even includes a pseudonymity function where every service you
         | authenticate with receives a different pseudonym so tracking
         | isn't (easily) possible.
        
           | codebeaker wrote:
           | I'm a recently naturalized German citizen, could you say more
           | about how I can use my Perso this way. It seems nobody uses
           | the "smart" features.
           | 
           | So far, it seems like a "mini passport" and an enormous risk
           | to carry around literally everything someone needs to know to
           | rob and/or impersonate me, but yet we're legally required to
           | do so.
        
             | MilaM wrote:
             | Adoption of the online ID function has been incredibly
             | slow. I haven't had a need for it yet. Some online banks
             | allow you to open an account using it. You can also file
             | taxes with it. Most applications require a NFC reader of
             | some kind. But there is also an official app for iOS and
             | Android which can be used to read the ID with your
             | smartphone.
             | 
             | There is an online portal where you can read more about it:
             | 
             | https://www.ausweisapp.bund.de/en/ausweisapp2-home/
        
             | gumby wrote:
             | Germany deliberately set up the authentication ecosystem
             | around private actors it appears pretty much to ensure this
             | would not ever happen. I use my Estonian ID to sign certs
             | from time to time, but my kid has never even bothered to
             | open the envelope with the codes (PUK etc) for his German
             | Ausweis.
        
             | IfOnlyYouKnew wrote:
             | You're not legally require to carry your ID around, only to
             | have an ID. You can leave it at home without worry,
             | although there may be situations where that is
             | inconvenient.
             | 
             | As to how to use the smart features: not knowing how to use
             | them is really what makes you German. Welcome onboard!
        
           | zeeZ wrote:
           | This is not entirely correct. The eID can be read without the
           | PIN. There is a six digit CAN (card access number) printed on
           | the front that can be used to read the card online, but
           | legally only for cases where an agent checks your identity
           | instead. It's more of an easy way to copy most of the data
           | that is printed on the card (some information such as sex,
           | eye color, height is not digitally available to online
           | services). It's mostly a way to prevent mistakes from copying
           | and to check validity.
        
         | walshemj wrote:
         | No we need to do away with the European "papers please" concept
         | of mandatory ID cards.
        
         | aloisklink wrote:
         | The funny thing is, Estonia already has this feature in their
         | ID cards (although, as I'm not Estonian, I'm not sure how often
         | people actually use this feature).
         | 
         | https://learn.e-resident.gov.ee/hc/en-us/articles/3600006244...
         | 
         | Their ID cards can cryptographically sign documents/anything
         | using a PIN that only the user should know, so even if the ID
         | card is stolen, it still can't be used to sign
         | documents/messages.
         | 
         | The problem is, the certificate (public key) purposely contains
         | the full-name/public personal ID code, so that people can prove
         | who (and which ID card) signed the message.
         | 
         | I'm unsure if making the photograph public was purposeful;, the
         | Wikipedia article is quite vague (it says that "personal data"
         | is publicly associated with your certificate, but I can't find
         | whether photos are included under "personal data" on the
         | English language government site).
        
           | Zanfa wrote:
           | Since the Estonian ID-card infrastructure has been around
           | almost 20 years (didn't even realize it's been this long
           | already), it's used literally everywhere. Every time you
           | interact with the government or a bank, utilities or even
           | loyalty programs at stores, you'll use your digital ID.
           | 
           | These days, you also have the option of signing with Mobile-
           | ID (using a secure SIM application provided by your phone
           | carrier) or SmartID (a regular Android/iPhone app) are
           | probably more convenient since you don't need the smart card
           | reader.
           | 
           | I can't remember the last time I had to physically sign
           | something in Estonia, only when dealing with foreign
           | companies, where you need to pretend to print, sign & scan
           | the document. They don't seem to mind copy-pasted PDF
           | signatures though...
        
             | chrismeller wrote:
             | Oddly enough both of my leases in Estonia have wanted a
             | hand-signed copy (though both times I also did the digital
             | PDF signature). No clue why, but I can't remember anything
             | else that ever has...
        
           | jnsaff2 wrote:
           | AFAICT the photo service is a convenience feature for the
           | user itself. When I use the ID-card desktop utility or the
           | national web service it offers to show me my own photo. It
           | may be used by govt agencies internally (and obv for issuing
           | it) but I have yet to see an actual use case beyond showing
           | it to myself.
        
           | jaanjalgratas wrote:
           | Estonian ID-cards contain 2 key pairs: authentication and
           | signature. Certificates' DN contain both: owner's full name
           | and Personal Code. Personal Code contains your sex and birth
           | date. Also, there's data file on chip containing all textual
           | data seen on the card, no image. So it's easy to use ID-card
           | in both, physical stores (reads data file for Personal Code)
           | and e-shops (reads certificate after auth). This document
           | image service was just a convenience service to download your
           | document image. Problem causing the issue was that auth
           | certificate path was not verified during authentication, so
           | you could impersonate by generating fake auth certificates.
        
           | tiku wrote:
           | I'm an e-resident and we also get a digital ID. It uses 2 pin
           | numbers, a normal pin and a second pin to sign stuff. Works
           | great.
        
         | sneak wrote:
         | It will still have your name and face on it, and they will
         | still stick it in an optical scanner when you hand it over to
         | them for use, and the scan will still get stolen from an
         | unprotected S3 bucket with millions of others.
        
         | vesinisa wrote:
         | Ironically enough, Estonia is the global forerunner of exactly
         | the type of tech you just described.
         | 
         | However, having a smart chip on your ID card does not do away
         | with requirements for good operational security.
        
         | EE84M3i wrote:
         | >hotels
         | 
         | Fwiw some countries, including Japan, require the hotel to keep
         | a record of a copy of your passport/residence card (for non
         | citizens at least) to meet regulatory requirements. It's not up
         | to the hotel to choose to collect it or not.
        
           | lobochrome wrote:
           | Travelled a lot in Japan. Happens rarely tbh but happens.
           | Used to happen in hotels everywhere around the globe though.
        
             | EE84M3i wrote:
             | https://www.japantimes.co.jp/community/2020/02/17/issues/ho
             | t... says copies of passports have been required since at
             | least 2014.
             | 
             | I seem to recall I had a similar experience in Canada.
        
         | deanclatworthy wrote:
         | I literally just went to a well known department store in my
         | city and in order to get an advertised discount, I was asked to
         | become a member. This required a SSN rather than just email. I
         | don't trust them with this info and with the SSN alone you can
         | call the bank and identify yourself, the police, and the tax
         | authorities. You can even identify yourself over the phone to
         | healthcare authorites
        
           | ARandomerDude wrote:
           | Wow. What store?
        
             | deanclatworthy wrote:
             | Stadium, Finland.
        
             | walshemj wrote:
             | Damm - In the UK I remember being read the riot act that
             | any misuse of NI numbers out side of a small number tiny
             | permitted uses was a disciplinary offence.
        
       | raunometsa wrote:
       | They have my photo now
        
         | saurik wrote:
         | Is that not a photo of yourself in your Twitter bio (as if so
         | that would mean we all had your photo already)?
        
           | draugadrotten wrote:
           | Having the photo AND the connection to the true identity is
           | the important part. Photos are everywhere. The identities are
           | everywhere. The link between is worth a lot.
        
             | SavantIdiot wrote:
             | However, this person uses their real name and even provides
             | a personal website with lots of information about
             | themselves.
        
           | raunometsa wrote:
           | Not exactly the same photo, but yes - same face!
        
       | [deleted]
        
       ___________________________________________________________________
       (page generated 2021-07-29 23:01 UTC)