djlink,
@djlink@mastodon.gamedev.place avatar

deleted_by_author

  • Loading...
    AngryAnt,
    @AngryAnt@mastodon.gamedev.place avatar

    @djlink Identity systems in the US and other places with ancient infrastructure have been embarrassingly insecure for the non-privileged class for decades.

    Trying to do identity proof via a photo in fx. Scandinavia or China will just get you an "ok, ha ha, but for real this time".

    Critically important topic to draw attention to, but it does boil down to another "here's a broken thing - now with a dash of AI!" headline.

    yacc143,
    @yacc143@mastodon.social avatar

    @AngryAnt @djlink
    Exactly. Although there are some EU MS like Germany that have gone crazy with photo ident, which is idiotic, as their national ID cards contain all that is required for biometric digitial IDs.

    (they stopped using it for health care purposes after it has been proven to be totally unsecure, but somehow other industries in Germany still use it.)

    AngryAnt,
    @AngryAnt@mastodon.gamedev.place avatar

    @yacc143 @djlink That is absolutely maddening. I wonder if it is a service problem? Like maybe the national ID system is unnecessarily difficult to implement support for?

    yacc143,
    @yacc143@mastodon.social avatar

    @AngryAnt @djlink
    Good question, might be more a combination of:

    • legal issues (for the national id you need a legal reason why you are checking the ID of your users)

    • no business case for the ID providers (photo ID might be trivial to hack, but it is much work to verify)

    • hardware (reading the national IDs require AFAIK smart card readers, which few users by default have, but nearly everybody has a webcam)

    AngryAnt,
    @AngryAnt@mastodon.gamedev.place avatar

    @yacc143 @djlink Ah ok that does sound like a hazzle. The IDs I mention are selectively digital and the integrated experience is like a commercial SSO.

    So say you're signing a document or logging into your web bank in DK, they redirect you to a portal where you enter your manually selected ID (user name) and then confirm on your mobile app (default) or using a code generator dongle (optional) or key pair paper (optional).

    Integrator side can request legal accept or confirmation of known data.

    AngryAnt,
    @AngryAnt@mastodon.gamedev.place avatar

    @yacc143 @djlink So there's a lot less legal worry connected to the ID process itself - as no sensitive data is provided by the process. It's just public/private key interaction, with the private key held by gov.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • InstantRegret
  • slotface
  • osvaldo12
  • kavyap
  • khanakhh
  • Durango
  • megavids
  • everett
  • tacticalgear
  • modclub
  • normalnudes
  • ngwrru68w68
  • cisconetworking
  • tester
  • GTA5RPClips
  • Leos
  • anitta
  • provamag3
  • JUstTest
  • lostlight
  • All magazines