‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. bzmrgonz · · focus · HN ↗
    It baffles that people think it's a bad thing to disclose a public key. That's their purpose actually. Sure we now have the post quantum computer threat, and some state actors are harvesting keys, but quantum computer is going to disrupt so much, that Id verification won't even matter really.
    1. what · · focus · HN ↗
      Where did you get the impression the author thinks it’s a bad thing? From the article:

      > These are public keys, which are meant to be published - recovering one lets anyone check a signature, not forge one.

      1. isomorphic · · focus · HN ↗
        I think GP and TFA mean that some of the states are afraid of public-key disclosure.
        1. prophesi · · focus · HN ↗
          TFA is a bit obtuse about it, and assumes you've read their previous article on the topic, but from what I gathered, it's about whether the AAMVA would standardize cryptographically signing the barcodes of driver licenses to mitigate creating fakes in the US/CA. Cali showed it's entirely possible, but there's still no pressure for the standard to change across the board.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.