[HN Gopher] Hacker downloads close to 300k personal ID photos fr...
___________________________________________________________________
Hacker downloads close to 300k personal ID photos from Estonian gov
database
Author : chrismeller
Score : 247 points
Date : 2021-07-29 07:33 UTC (15 hours ago)
(HTM) web link (news.err.ee)
(TXT) w3m dump (news.err.ee)
| beezischillin wrote:
| Last year my government (Eastern Europe) started requiring some
| extra documentation to be submitted by companies, yearly, after
| it passed a law to do so. It being a strange time in human
| history they had to twist themselves in all sorts of knots to try
| and make that possible so they gave in and - I assume - they put
| out a giant government contract searching for an IT company to
| make that happen. And make it happen they did, through usual
| nefarious means or otherwise, that much is unknown but they
| created a portal. You could enter your details and it would
| return you a document to download and sign and hand off to the
| nearest government agency that was officially supposed to handle
| these. And so my friend got to work... first thing he noticed:
| the whole thing was insanely slow and then he took a look at the
| URL and found that it was basically someone's Windows PC, just
| serving the entire C:/ drive on a public URL. Even worse, all the
| documents generated (which contained all data, private and public
| related to the company owner - even ID data) were named in an
| incremental fashion. Meaning that you could've, were you a bad
| actor, dump pretty much the entire country's privately owned
| business owners' details with a simple bash script.
|
| So he took it upon himself and called the specific government
| branch...
|
| ... and within an hour the whole portal was offline and the
| deadlines ended up being extended. This year was the earliest
| time I needed to submit said paperwork.
|
| Handling stuff online is not easy and sometimes goes very wrong.
| That being said, for most general company admin things you need
| to do here you can buy a hardware cert and avoid this entire risk
| and they're supposed to be rolling out IDs with similar features
| and a similar promise in August. Though as to how that will
| function, I have no idea as I couldn't find any info on it.
| rrrrrrrrrrrryan wrote:
| This is sad.
|
| Estonia's government is exceptionally forward-thinking when it
| comes to embracing technology (they've had internet voting since
| 2005, for example), but ultimately they're still a smaller nation
| and it sucks to see them get burned.
|
| Some more info:
| https://www.newyorker.com/magazine/2017/12/18/estonia-the-di...
| Proven wrote:
| If they were forward thinking they wouldn't have collected that
| PII
| systemvoltage wrote:
| Appearance of forward-thinking and actual boots-on-the-ground
| situation can vary widely. Especially with governments - you
| might be suprised how many things are just held on stilts
| behind the scenes. When it comes to security, I have zero trust
| in the government ID programs.
| codedokode wrote:
| Internet voting that cannot be independently verified and
| monitored is just a fraud.
| roddux wrote:
| So when can we expect ThisEstonianDoesNotExist?
| DocG wrote:
| It was a oversight in picture program. Basically you can always
| request your own photo and the hacker already had names and ID
| codes and was able to use legimate access to download photos. He
| did use botnet, with many computers so it seemed legimate
| traffic. And was apprehended literally the next day.
|
| Stolen pictures were not forwarded, so they even got the leaked
| data back.
|
| Dunno, not a big deal.
|
| Only thing was he was downloading pictures en masse. Names and ID
| codes got from elsewhere beforehand. ID code is not a secret here
| either, you can reconstruct it with high accuracy just by knowing
| persons birthday and city he lives.
|
| Tho I think this triggered a fast lane for upgrading some legacy
| stuff that was to be updated soon. So good scare I think.
| thih9 wrote:
| > Stolen pictures were not forwarded, so they even got the
| leaked data back.
|
| Can we be certain that the hacker didn't make any copies?
| codedokode wrote:
| Does truly democratic society need identity card and databases?
| Do people need to be tracked since their birth as if they were
| someone's property?
|
| Also, such leaks can be dangerous. If someone is hiding from
| authoritarian government then the stolen data can be used to
| track and assasinate them.
| flemhans wrote:
| Why were they storing them in the first place?
| Dma54rhs wrote:
| Very few governments don't store data like that, America and it
| lack of standardized documentation is an outliner in the
| developed world.
| drstewart wrote:
| Do you have a source for this? I'm curious to see a chart of
| "centralization of standardized documentation" by country to
| validate your claims.
| Dma54rhs wrote:
| Source for what, it's so common knowledge that you should
| list countries that don't do centralized id besides USA in
| the developed world. Search for voting id laws is probably
| a good start.
|
| https://www.consilium.europa.eu/en/press/press-
| releases/2019...
|
| These are from 2019,but the documents have always existed.
| And each country is using this guideline for their
| countries.
| johannes1234321 wrote:
| having a givernment issued ID neither means all data is
| being stored, nor that itnis stored centralized.
|
| In Germany for instance most data is held by the
| municipality and centralization happens slowly and
| centralizing pictures is only a recent proposal.
| croes wrote:
| Because it's not necessary. Since 2017 police and secret
| agencies can access all photos 24/7 per web access.
| est31 wrote:
| The centralization proposal the person you are replying
| to was done because that API access you are talking about
| apparently hasn't been implemented in a wide spread
| manner. So now each Bundesland can create their own
| database.
|
| https://www.golem.de/news/trotz-kritik-smartphone-
| ausweis-un...
| wil421 wrote:
| Not according to comments on this post. Lots of governments
| in Europe keep records at the city and state level. Unless
| they are passports.
| sofixa wrote:
| Like which ones? I can't see the comments you're referring
| to.
| wil421 wrote:
| Look at johannes1234321 comment below.
| Dma54rhs wrote:
| Its all centrally forced, the security, the implementation.
| They are printed the same place, same way, a lot of
| directives straight from Brussels.
| sp332 wrote:
| And the passports have photos, right?
| onion2k wrote:
| The UK isn't technically in Europe any more (except
| geographically), but there are no city or state (county)
| level photo IDs here. Everything is national and managed by
| the central government.
| ithinkso wrote:
| It's in Europe the same way it has always been. UK is no
| longer in the EU
| alibarber wrote:
| And even within the EU I'd still wager that there are
| many different systems in different countries. Almost
| like it's a block of diverse individual nations and not
| just a single entity that you can make lazy comparisons
| with.
| djbebs wrote:
| Are you asking why the estonian government was storying
| identity information?
| wutwutwutwut wrote:
| Yes, he was. Many people in US specifically does not seem to
| have knowledge about how other countries are governed.
| vletal wrote:
| Well, is not it simply because the rest of us living
| outside of the US are frequently exposed to US politics via
| mainstream media? Since there is 160+ countries in the
| world, this exposure can be hardly symmetrical.
| wutwutwutwut wrote:
| I'm sure, but even as a person living in the US, having
| knowledge on how your own country differs from all others
| make sense.
| Symbiote wrote:
| Presumably the US government stores passport photographs,
| and the state governments store driving license
| photographs.
|
| (Estonia has a similar population to Maine or New
| Hampshire, 1.3 million people.)
| runako wrote:
| Only ~30% of Americans have a passport, so the passport
| database is nothing like comprehensive.
| yostrovs wrote:
| They do now. There was a time when you could go to the
| DMV and switch places with your friend right before the
| photo for the ID was taken. If you were under 21 and your
| friend was older, you had a real fake ID made for you by
| the state. At least in Illinois that was the case when I
| was still underage. Now they do see the older photo come
| up when renewing a license, presumably to prevent
| swapping.
| code_duck wrote:
| Someone I know did this with his brothers documents
| without his brother being involved. He took the documents
| to the DMV and said he lost his license. Pretty much all
| they had to go on was basic appearance metrics and
| questions like where you got your license last time. This
| was in the 90s so it's possible it might not be as easy
| now.
| ghaff wrote:
| In my state, and I assume most/all(?) others, it's all
| electronic. When I had to replace a lost license a few
| years back, it was very easy. Go to a website and pay $25
| or whatever. But there's no new photo involved.
| adolph wrote:
| A distant acquaintance did that in the early 90s, only
| that person asked for a new drivers license. The clerk
| attempted to offer a duplicate instead of a new license
| and the nervous license getter refused until the clerk
| said, "look I'm trying to save you some money, we still
| take your picture and give you the license today!"
| Aaargh20318 wrote:
| > There was a time when you could go to the DMV and
| switch places with your friend right before the photo for
| the ID was taken.
|
| But wouldn't that mean your friend no longer had a valid
| drivers license ?
| code_duck wrote:
| The old license is not effectively invalidated in any
| way. Almost nobody you presented the license to would
| know that another one has been issued, besides possibly a
| police officer. It would be fairly easy to tell them that
| you got a replacement and then found the old one.
| Aaargh20318 wrote:
| > The old license is not effectively invalidated in any
| way. Almost nobody you presented the license to would
| know that another one has been issued
|
| That's strange. Where I live, if you get a new ID you
| have to turn in your old one. You can keep a passport if
| you want (some people like to if they have a ot of stamps
| from their travels) but in that case they punch a couple
| of big holes through the entire booklet before returning
| it to you (basically, it removes the chip and some other
| security measures).
| code_duck wrote:
| They do ask you to do that, but what if you lost it?
| Aaargh20318 wrote:
| If you lost it you have to go to the police and report it
| lost. Then you need to hand over the police report when
| you request a new one. Reporting it lost or stolen also
| invalidates your drivers license meaning you can't drive
| while you wait for your new license.
| code_duck wrote:
| I see. In what region are you referring to? I have never
| lived in a state with any sort of concept of rendering
| your license invalid because you lost a physical license,
| nor have I been told to file a police report.
|
| I looked it up for my state and they said you only must
| file a police report if you believe your license has been
| stolen, not lost, and you desire a new number. I'm sure
| policies differ among states.
|
| I picked Michigan at random. Their website merely warns
| that the old license will be invalidated electronically
| and cannot be used for border crossing while encouraging
| use of online replacement services.
|
| https://www.michigan.gov/sos/0,4670,7-127-1627_8669_53328
| ---...
| nly wrote:
| Seems like a dumb thing for your friend to do for you
| when that photo will be part of a permanent database.
| Talanes wrote:
| The purpose of that anecdote was to demonstrate that
| there was no database at that time.
| sneak wrote:
| State governments have to turn over all of the DL/ID data
| to the feds these days under the new backdoor federal ID
| law ("Real ID").
| code_duck wrote:
| From what I recall, in a fairly recent traffic stop in my
| home state the police officer had access to all of my
| license information including the photo.
| flemhans wrote:
| I'm from Denmark, not the US, and they don't store my
| picture by default. The passport picture is stored in the
| chip and then supposedly discarded.
| chrismeller wrote:
| Multiple reasons, just like CBP in the US can pull up your
| photo to make sure the one on the ID and standing in front of
| them is actually the person the system says it is.
|
| They also compared my old ID photo with the new photo I was
| submitting when I renewed it recently for the same reason.
|
| Though I've never had this particular problem, I believe the
| police will also do the same thing to verify they're arresting
| or ticketing the right person.
|
| Also keep in mind that Estonia is the size of a (quite) small
| state in the US, so they're storing things like a driver's
| license photo just like your state would. You actually don't
| need a physical driver's license with you in Estonia as long as
| it's linked to your ID card, so it's really an "all your eggs
| in one basket" kind of system.
| TekMol wrote:
| IDs have become a joke. People have been handing them out for
| copying to hotels, websites and apps like candy.
|
| We need to replace IDs with chips that do not give away their
| secret key but only sign stuff you throw at them.
|
| So when a website or hotel wants to know "Hey, are you really Joe
| Doe?" it sends this message to the "ID" and the "ID" sends it
| back with "yes" and signed.
|
| This way we can identify ourselfes without giving the other party
| the ability to identify as us from now on.
| Taylor_OD wrote:
| Wait till you hear about SSN. Which were created specifically
| not to be used for identification.
| jaanjalgratas wrote:
| Why are you scared of sharing SSN? In Estonia it's called
| Personal Code and it doesn't have any special status, just
| your unique digital name. We have left these days behind
| dozen years ago when banks used asking Personal Code as a
| security measure.
| labster wrote:
| SSN is not a Personal Code. It's just a number. Add or
| subtract one, and you get the a valid number for the people
| in your home town who were born nearest to your birthdate.
| There are no checks and it's very difficult to change. Some
| people in the USA would like a better system, but we can't
| have it because national IDs and vaccines are tyranny.
| rtuulik wrote:
| Estionian Personal Code number works just as a unique
| identifying number. American Social Security Number work
| both as an unique identifying number AND as a verification
| of identity. Basically its similar to estonian ID number,
| but instead of PIN1 and PIN2 you have just the SSN.
| lazide wrote:
| SSN is used by many, many entities as a 'secret security
| code' essentially. Including (still) many banks, government
| offices, etc.
|
| It's also used for things like tracking of tax liabilities
| - so if someone has your SSN, with some minor fudging of
| other data there have been historic issues like claiming
| tax overpayments and getting checks from the government.
|
| It's incredibly dumb, but it is what it is (mostly still).
|
| At least most of the big players aren't quite as dumb about
| it as they used to be.
| 2Gkashmiri wrote:
| You know, that was the original idea with indian "Aadhar". I am
| talking about keeping up with its news on tech magazines back
| in 2007 when it was lauded as a FOSS achievement. The idea from
| what I can recall now was "yinput your id, you put your finger
| on.the reader and the backend sends a "yes/no" with a hash of
| the authentication. Thats it"
|
| Over subsequent years, politics fucked it up bad. They made it
| "compulsory". Then people started asking for photocopies. Then
| scans. Then people would keep and then buy and sell these scans
| in bulk. Then people started putting phones with multiple
| cards, like entire villages would be one computer operator who
| would keep his own phone for "otp". That operator would then
| sell access which would be bought for buying Sim cards, shit
| and frauds.
|
| Then you have the political appiontees who run this Aadhar
| system, those pompous assholes claim they are unhackable. Come
| on.
|
| Sadly they built a Pandoras box now with 1.3 billion almost
| demographic data, biometric data and that is scary.
| IfOnlyYouKnew wrote:
| I don't know how copies of my ID being made turns it into a
| joke? There isn't anything secret on my ID, and just knowing
| the information and having a picture is to impersonating me as
| putting on running shoes is to drawing an owl.
| w3ll_w3ll_w3ll wrote:
| Most newly issued identity cards in Europe work that way. They
| have a private key stored in the chip, that can be used to
| prove identity, without giving the ability to the other party
| to impersonate the citizen.
|
| Unfortunately most places still check these type of cards
| visually, but I hope that electronic verification will become
| more common in a few years.
|
| For example these cards can be checked very easily simply using
| an NFC Android phone and the right app.
|
| In US for something similar you can look at ICAO passports and
| Enhanced driver's license,
| rjzzleep wrote:
| For a lot of things I have to send photos of passports
| around, in wechat, whatsapp, line and whatever other BS other
| people request. The other day I was requested to give a new
| copy of my updated passport to a local telco with abysmal
| security, just to be able to return a SIM card to get my
| security deposit back. WHY?
|
| It's infuriating. Governments still use a 100 year old system
| of stamping each others documents in overseas missions to
| confirm the authenticity of a document that is based in an
| era where there was neither telephone nor internet. The whole
| world runs on a bad joke.
|
| The thing that's different about the three baltics is that
| their crypto is open source and has had many iterations. They
| even sued Gemalto for an insecure revision IIRC. All of the
| signing code is open source on top of that.
|
| The way Germany works is that they design something in a
| committee for 20 years in private, then they push it out to
| public. Then the CCC finds security issues in there, then the
| government ignores it and changes the law to force you to use
| it anyway. One thing I will give the Germans is that in legal
| interaction with their official institutions they will allow
| you to blacken out PII from the identity card. But no private
| institution does that so it's kinda pointless.
| w3ll_w3ll_w3ll wrote:
| Yes it will be a long time until we are able to change this
| old habits.
|
| But you can put it another way: if someone commit am
| identity fraud using a picture of your ID, you can defend
| yourself showing that you were required by many different
| entities to send a copy of your ID. So there are many
| parties that could have leaked your ID and a picture of you
| ID cannot be considered a prove that you authorized or
| allowed anything.
|
| Case dismissed :)
| rjzzleep wrote:
| Unfortunately no, when people commit identity fraud using
| your ID, you're the one that needs to prove your
| innocence. In the US for example it's so easy to commit
| identity fraud, but really hard to get out of the damage
| someone else may have done to you.
| mikem170 wrote:
| You mentioned the burden of proof being on the victim of
| identity theft. Is that applicable to anything besides
| ones credit report?
|
| If creditors want to get a judgement to garnish wages or
| seize assets they have to go to court. I wonder if the
| burden of proof is any different there, or if the
| parent's defence (everybody has a copy of my
| identification!) could work at that point?
| lazide wrote:
| The damage of identify theft is the damaged credit
| report, and the fact you now have to explain to every
| entity you do business with what happened - and hope they
| believe you. Many won't because it isn't worth the risk
| to them.
|
| Garnished wages are pretty rare from what I've heard, and
| yes it rarely gets to that point. It's still a nightmare
| for many people with real world consequences if it
| happens to you.
| mikem170 wrote:
| I understand the impact a problem on a credit report can
| have for most people.
|
| Over the years I've been trying to minimize my dependence
| on credit reports. It's been frozen for most of a couple
| decades, and I'd like to keep it that way. I've paid cash
| for vehicles, use secured credit cards, put down a
| deposit for my utility service, have a pay as you go
| phone, rent from people I know, and hope to remain self-
| employed, or work for people who know me enough to know
| that I can be trusted. I'd rather not deal with BigCorp.
| I realize that not everyone wants to or can do these
| things.
|
| But that left me wondering about what would happen in a
| trial to get a judgement if someone was able to
| fraudulently open a line of credit in my name. I'm hoping
| that a judge would require more than a forged signature
| to seize my wages/assets. Personally this is what I worry
| about, not so much my credit report.
| lazide wrote:
| It has happened, it is rare though. Also know of a few
| cases of folks selling peoples houses out from under them
| by fooling the title company when they were on a long
| vacation. Realistically, most thieves are far too lazy,
| and it's real (and risky) work doing that compared to
| doing a bunch of credit card fraud.
| skeeter2020 wrote:
| "Identity fraud" or worse, "identity theft" are BS terms
| made up by the organizations responsible for the actual
| underlying crime. Example: a criminal gets credit cards
| issued in your name and your bank screams "Identity
| Theft!" when this is just good ol' fashioned fraud
| enabled by their crappy process and antiquated security.
| The difference is the former is your problem while the
| latter is all theirs. Plus they get the chance to sell
| you another service to protect you from their mess.
| $PROFIT !!!
| flotzam wrote:
| "I seem to have my identity, whereas you seem to have
| lost several thousands of pounds."
| https://www.youtube.com/watch?v=CS9ptA3Ya9E
| Spooky23 wrote:
| The old stuff is still around because it works.
|
| New fancy integration, digital signatures, etc are still
| protecting a process that's unreliable fundamentally. It's
| all anchored to your birth certificate, and in the US
| that's controlled by thousands of jurisdictions with
| varying competence.
|
| The most secure scenarios (cleared employees), tie your
| credentials to biometrics, and vet your origin as a control
| for fraud. Everything else increases the risk of fraud as a
| trade off for convenience or privacy. (Your cellphone
| carrier doesn't need to vet where you went to elementary
| school)
| LeifCarrotson wrote:
| It works for the requirements of the people who are
| running it, not necessarily those who use it.
|
| The differentiator is that when an incompetent
| jurisdiction gives away your ID, it's your loss, not
| theirs. When hackers spoof a business with your
| credentials to perform industrial espionage or plant
| ransomware, it's the business that loses, not you. An
| incompetent jurisdiction can continue operation
| indefinitely, they just have unhappy, powerless citizens.
| An incompetent business will suffer financial losses and
| fail.
| Spooky23 wrote:
| It's more nuanced than that.
|
| The village clerk in some Indian reservation in South
| Dakota probably doesn't have a process that looks like
| the NYC department of Health for vital records. But
| people live for a long time, and errors and omissions do
| too.
|
| The point is, you can establish identity, but it's a pain
| in the ass. I need to provide a drivers license to open a
| savings account, but anyone with my SSN can open a credit
| card.
| RaptorJ wrote:
| Any day now Equifax is going down. The real difference is
| that humans have some institutional power over political
| jurisdictions and how they are run and exactly none over
| how (large enough) businesses are.
| ectopod wrote:
| They add friction to any outgoing payment because some
| proportion of customers will walk away and then they will
| have more money.
|
| Other organisations (especially banks) will collect far
| more information than is legally required for KYC because
| they can use it for marketing.
|
| But why does a 50 cent SIM card need a security deposit?
| 0xffff2 wrote:
| >In US for something similar you can look at ICAO passports
| and Enhanced driver's license,
|
| I'm not sure what you mean be "Enhanced driver's license",
| but my RealId driver's license doesn't seem to have a chip in
| it, just an excess of holographic overlays.
| rrrrrrrrrrrryan wrote:
| Enhanced driver's licenses are different: they have a chip,
| and right now they are only available in 4 states near the
| Canadian border.
|
| https://blog.americansafetycouncil.com/enhanced-drivers-
| lice...
| gumby wrote:
| Unfortunately Germany deliberately borked the encryption
| ecosystem so it's useless there. And many of the the smaller
| countries have trouble building out the infrastructure with
| everything else on their plate (Estonia being a significant
| exception).
| w3ll_w3ll_w3ll wrote:
| Do you have more information on how Germany deliberately
| borked the encryption ecosystem?
| gumby wrote:
| Sure. The key is "ecosystem". A technical flaw
| notwithstanding, the PKI itself seems fine (Estonia also
| had a technical problem in this regard).
|
| However the cards were simply rolled out: essentially the
| only practical difference for anyone between the old
| cards and the new was that there was a chip in it. But
| there was no surrounding infrastructure: government
| didn't take it, banks didn't take it -- there was no
| practical benefit. There were no mandates for use, no
| examples or or incentives. The country made greater
| provision for spelling reform than they did for the E-ID.
| There was a lot of unease about the idea of all that
| tracking...yet the card itself already leaks lots of
| unnecessary personal info (e.g. address) to anyone who
| glances at it.
|
| Compare this to countries like Estonia who made a point
| of using the card as the easiest way to unlock government
| services and made it easy for companies to do the same.
|
| This is touched on in English in this recent article:
| https://www.theguardian.com/world/2021/may/22/new-id-law-
| aim...
| rjzzleep wrote:
| Don't know what he means, but there were a couple of
| security vulnerabilities in the past. The German gvt.
| didn't really address how it was improved, but gave a
| security certification award to it.
|
| https://www.ccc.de/de/updates/2010/sicherheitsprobleme-
| bei-s...
| zeeZ wrote:
| Their problem with the German ID was that cheap readers
| did not have a keypad, so you'd have to enter your PIN on
| the PC, which could be infected with a trojan.
|
| It's sad that this myth that "eID is insecure" has stuck
| around, because it's just not true. Their problems have
| all been with auxiliary devices or software, not the eID
| itself.
| tinus_hn wrote:
| I'm pretty sure you can read people's birthdays using NFC
| where the N for near is up to the attacker.
| disabled wrote:
| Yep. All European Union countries are eventually going to use
| electronic IDs (eID) with Smartchips that can be read by a
| Smart Card reader.
|
| A number of governments already use eIDs, and have elaborate
| databases for citizens, such as Croatia. See:
| https://gov.hr/en
|
| There are also other forms of government facilitated
| authentication (e.g. electronic signatures or citizen
| services), and depending on the level of security needed.
|
| It's amazing that the United States does not have this
| functionality, which would be useful moving from state to
| state.
|
| I guess the US passport card is the closest example, but it
| is useless except as identification.
| cromka wrote:
| >All European Union countries are eventually going to use
| electronic IDs (eID) with Smartchips that can be read by a
| Smart Card reader.
|
| As far as I know there's a deadline for it and we just
| passed it.
| dragonwriter wrote:
| > It's amazing that the United States does not have this
| functionality, which would be useful moving from state to
| state.
|
| The US does have it, used in both passports and "Enhanced
| Driver's Licenses" meeting the federal requirements for
| that label. I think only a couple states currently issue
| EDLs.
|
| > I guess the US passport card is the closest example, but
| it is useless except as identification.
|
| Almost any place that requires government ID, IME, accepts
| passports; they aren't at all useless as ID.
| disabled wrote:
| The point I was trying to make is that in many countries
| in Europe, we can use our electronic IDs to do a lot of
| things in everyday life that cannot be done online in the
| US. You can see all of the services we can access in
| Croatia here: https://gov.hr/en/catalogue-of-services/10
|
| The eIDs also require a biometric picture of your face
| and 2 fingerprints, which are encoded into the card, as
| required by European Union regulation.
|
| When I am ready to I can even apply for my European
| Engineer license online on that portal, with my eID using
| a Smartcard reader on PC (highest level of security for
| authentication of credentials).
| jjcc wrote:
| Most of the ID verification systems use "What you know"(PIN
| or password), "What you have"(ID Card or Phone),"Who you
| are"(biometrics, i.e. finger print hash), using 1 factor or
| combination of 2 factors. For verification, storing hash on
| server is good enough.
|
| If we use safely stored finger print hash in ID
| cards/Passports/Phones (Iris is better but expensive), the
| stolen IDs from server have less value to hackers. ICAO
| standard already includes secure storage of the biometrics
| data long time ago but not many countries implement yet.
| Finger print sensor is widely adopted in mobile phones.
| Anyway the technology exists. Maybe some identity theft
| incidents will push the government and the industry to
| implement the solutions
| SavantIdiot wrote:
| So I just steal your ID. You still need a PIN and/or biometric
| authentication.
| GoblinSlayer wrote:
| What if the website sends "Hey, do you want to take a large
| credit?"?
| w3ll_w3ll_w3ll wrote:
| Authentication and digital signatures (like for signing
| contracts) are usually kept separate on electronic cards.
| There are already standards for that.
| megous wrote:
| I don't think I have many ID cards without chips anymore. Maybe
| EU health care insurance card doesn't have one. Everything else
| has wireless chips.
| foepys wrote:
| This is already possible with the German ID card (nPA). It can
| also verify if you are over a certain age without giving out
| your data. You also cannot read the nPA without a PIN code. It
| even includes a pseudonymity function where every service you
| authenticate with receives a different pseudonym so tracking
| isn't (easily) possible.
| codebeaker wrote:
| I'm a recently naturalized German citizen, could you say more
| about how I can use my Perso this way. It seems nobody uses
| the "smart" features.
|
| So far, it seems like a "mini passport" and an enormous risk
| to carry around literally everything someone needs to know to
| rob and/or impersonate me, but yet we're legally required to
| do so.
| MilaM wrote:
| Adoption of the online ID function has been incredibly
| slow. I haven't had a need for it yet. Some online banks
| allow you to open an account using it. You can also file
| taxes with it. Most applications require a NFC reader of
| some kind. But there is also an official app for iOS and
| Android which can be used to read the ID with your
| smartphone.
|
| There is an online portal where you can read more about it:
|
| https://www.ausweisapp.bund.de/en/ausweisapp2-home/
| gumby wrote:
| Germany deliberately set up the authentication ecosystem
| around private actors it appears pretty much to ensure this
| would not ever happen. I use my Estonian ID to sign certs
| from time to time, but my kid has never even bothered to
| open the envelope with the codes (PUK etc) for his German
| Ausweis.
| IfOnlyYouKnew wrote:
| You're not legally require to carry your ID around, only to
| have an ID. You can leave it at home without worry,
| although there may be situations where that is
| inconvenient.
|
| As to how to use the smart features: not knowing how to use
| them is really what makes you German. Welcome onboard!
| zeeZ wrote:
| This is not entirely correct. The eID can be read without the
| PIN. There is a six digit CAN (card access number) printed on
| the front that can be used to read the card online, but
| legally only for cases where an agent checks your identity
| instead. It's more of an easy way to copy most of the data
| that is printed on the card (some information such as sex,
| eye color, height is not digitally available to online
| services). It's mostly a way to prevent mistakes from copying
| and to check validity.
| walshemj wrote:
| No we need to do away with the European "papers please" concept
| of mandatory ID cards.
| aloisklink wrote:
| The funny thing is, Estonia already has this feature in their
| ID cards (although, as I'm not Estonian, I'm not sure how often
| people actually use this feature).
|
| https://learn.e-resident.gov.ee/hc/en-us/articles/3600006244...
|
| Their ID cards can cryptographically sign documents/anything
| using a PIN that only the user should know, so even if the ID
| card is stolen, it still can't be used to sign
| documents/messages.
|
| The problem is, the certificate (public key) purposely contains
| the full-name/public personal ID code, so that people can prove
| who (and which ID card) signed the message.
|
| I'm unsure if making the photograph public was purposeful;, the
| Wikipedia article is quite vague (it says that "personal data"
| is publicly associated with your certificate, but I can't find
| whether photos are included under "personal data" on the
| English language government site).
| Zanfa wrote:
| Since the Estonian ID-card infrastructure has been around
| almost 20 years (didn't even realize it's been this long
| already), it's used literally everywhere. Every time you
| interact with the government or a bank, utilities or even
| loyalty programs at stores, you'll use your digital ID.
|
| These days, you also have the option of signing with Mobile-
| ID (using a secure SIM application provided by your phone
| carrier) or SmartID (a regular Android/iPhone app) are
| probably more convenient since you don't need the smart card
| reader.
|
| I can't remember the last time I had to physically sign
| something in Estonia, only when dealing with foreign
| companies, where you need to pretend to print, sign & scan
| the document. They don't seem to mind copy-pasted PDF
| signatures though...
| chrismeller wrote:
| Oddly enough both of my leases in Estonia have wanted a
| hand-signed copy (though both times I also did the digital
| PDF signature). No clue why, but I can't remember anything
| else that ever has...
| jnsaff2 wrote:
| AFAICT the photo service is a convenience feature for the
| user itself. When I use the ID-card desktop utility or the
| national web service it offers to show me my own photo. It
| may be used by govt agencies internally (and obv for issuing
| it) but I have yet to see an actual use case beyond showing
| it to myself.
| jaanjalgratas wrote:
| Estonian ID-cards contain 2 key pairs: authentication and
| signature. Certificates' DN contain both: owner's full name
| and Personal Code. Personal Code contains your sex and birth
| date. Also, there's data file on chip containing all textual
| data seen on the card, no image. So it's easy to use ID-card
| in both, physical stores (reads data file for Personal Code)
| and e-shops (reads certificate after auth). This document
| image service was just a convenience service to download your
| document image. Problem causing the issue was that auth
| certificate path was not verified during authentication, so
| you could impersonate by generating fake auth certificates.
| tiku wrote:
| I'm an e-resident and we also get a digital ID. It uses 2 pin
| numbers, a normal pin and a second pin to sign stuff. Works
| great.
| sneak wrote:
| It will still have your name and face on it, and they will
| still stick it in an optical scanner when you hand it over to
| them for use, and the scan will still get stolen from an
| unprotected S3 bucket with millions of others.
| vesinisa wrote:
| Ironically enough, Estonia is the global forerunner of exactly
| the type of tech you just described.
|
| However, having a smart chip on your ID card does not do away
| with requirements for good operational security.
| EE84M3i wrote:
| >hotels
|
| Fwiw some countries, including Japan, require the hotel to keep
| a record of a copy of your passport/residence card (for non
| citizens at least) to meet regulatory requirements. It's not up
| to the hotel to choose to collect it or not.
| lobochrome wrote:
| Travelled a lot in Japan. Happens rarely tbh but happens.
| Used to happen in hotels everywhere around the globe though.
| EE84M3i wrote:
| https://www.japantimes.co.jp/community/2020/02/17/issues/ho
| t... says copies of passports have been required since at
| least 2014.
|
| I seem to recall I had a similar experience in Canada.
| deanclatworthy wrote:
| I literally just went to a well known department store in my
| city and in order to get an advertised discount, I was asked to
| become a member. This required a SSN rather than just email. I
| don't trust them with this info and with the SSN alone you can
| call the bank and identify yourself, the police, and the tax
| authorities. You can even identify yourself over the phone to
| healthcare authorites
| ARandomerDude wrote:
| Wow. What store?
| deanclatworthy wrote:
| Stadium, Finland.
| walshemj wrote:
| Damm - In the UK I remember being read the riot act that
| any misuse of NI numbers out side of a small number tiny
| permitted uses was a disciplinary offence.
| raunometsa wrote:
| They have my photo now
| saurik wrote:
| Is that not a photo of yourself in your Twitter bio (as if so
| that would mean we all had your photo already)?
| draugadrotten wrote:
| Having the photo AND the connection to the true identity is
| the important part. Photos are everywhere. The identities are
| everywhere. The link between is worth a lot.
| SavantIdiot wrote:
| However, this person uses their real name and even provides
| a personal website with lots of information about
| themselves.
| raunometsa wrote:
| Not exactly the same photo, but yes - same face!
| [deleted]
___________________________________________________________________
(page generated 2021-07-29 23:01 UTC)