| ▲ | shireboy 3 days ago |
| When this first landed I asked what the fix could even be. Everyone needs a new ID at a minimum. But then I got to thinking: 1) is that the point? Conspiratorial thinking I know but “hey all
Our ids got hacked I guess we need a national id”. And related 2) the current id system from a security standpoint was a band aid fix for outdated world to be shoehorned into a modern one. IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN” but bottom line, at least in US there is no cryptographically secure identity system that proves you are the citizen you say. And that fact bleeds into all sorts of patchwork solutions, fraud, etc. Moreover there are serious philosophical hurdles to getting to one. I’m not even positive I want one. But unless there is some zero-trust way to do this, I’m not sure what the fix would be. |
|
| ▲ | iugtmkbdfil834 3 days ago | parent | next [-] |
| And then, in real life, one discovers that institutions route around in creative ways for all sorts of different reasons ( recently had to 2fa a transaction at a god damn teller window; you just took my DL ). |
| |
| ▲ | AnimalMuppet 3 days ago | parent [-] | | Isn't the DL (which has a picture) and your face the two factors? Isn't that the whole point of having a picture on a DL? | | |
| ▲ | lotsofpulp 3 days ago | parent | next [-] | | No, the teller is not sufficiently qualified to be liable enough to match the picture on the ID to the person in front. The 2nd factor is the phone number on file, which offloads liability for errors in that mechanism to the phone company. The goal is to reduce the amount of decisions the teller makes, so as to reduce the amount of errors they can make, which also reduces the amount of training they need, all of which reduces costs. It’s really interesting how the lack of US federal government stepping in to provide an official electronic identity verification API has resulted in the mobile phone networks becoming the de facto arbiters of identity. Even for government services. I don’t even think I could trust having my phone number on someone else’s mobile phone plan, as I would want to ensure I have as much control over it as possible. | |
| ▲ | iugtmkbdfil834 3 days ago | parent | prev [-] | | Yes, but it is rather pointless to argue with teller who can't even begin to understand policy dictating it, much less, apparently, make exceptions. Machine told me to do it. |
|
|
|
| ▲ | Terr_ 3 days ago | parent | prev | next [-] |
| > IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN” With the benefit of hindsight, we'd have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor. |
| |
| ▲ | AngryData 3 days ago | parent | next [-] | | To be fair many SS cards were printed stating right on them they aren't for ID usage. | | |
| ▲ | simoncion 3 days ago | parent | next [-] | | Yep. Social Security numbers are not guaranteed to be unique, and for a very long time, were pretty easy to figure out if you knew roughly when a person was born and where. "I know! We'll use this number that its issuing agency says is most definitely not to be used for identification purposes for identification purposes!" is real PHB thinking. | |
| ▲ | Terr_ 3 days ago | parent | prev [-] | | Right, I don't blame the SS administration, they knew what people shouldn't do and warned everyone about it... the problem was private companies were desperate for security-theater and were never punished as they built an entire grand opera-house of insecurity. | | |
| ▲ | mahboi a day ago | parent [-] | | What should the companies have used instead? Even the government identifies you by SSN, eg taxes or voter registration. They combine that with state ID often, but the only national ID is passport which not everyone has. |
|
| |
| ▲ | fortran77 3 days ago | parent | prev [-] | | But they were! My college student ID from 1980 has my SS number right on it. I have here an employee badge from the Walt Disney Company from 2000 and my SS number is in a bar code right on the bottom. Even in 2000, it would be trivial to take a photo of someone wearing the ID badge and decode the 1D bar code on it. | | |
| ▲ | Terr_ 3 days ago | parent | next [-] | | Right, but somehow a bunch of companies still made them into a "prove who you are" factor, and (if we assume incompetence instead of malice) that means a bunch of decision makers still considered the a trust factor. | |
| ▲ | 3 days ago | parent | prev | next [-] | | [deleted] | |
| ▲ | quesera 3 days ago | parent | prev [-] | | In some states, until the early 1990s, SSNs were also used as drivers license numbers. |
|
|
|
| ▲ | mahboi 3 days ago | parent | prev [-] |
| Passports seem a lot better. You scan it with NFC, and the chip inside proves authenticity via asymmetric crypto. |