‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. bzmrgonz · · focus · HN ↗
    It baffles that people think it's a bad thing to disclose a public key. That's their purpose actually. Sure we now have the post quantum computer threat, and some state actors are harvesting keys, but quantum computer is going to disrupt so much, that Id verification won't even matter really.
    1. morsch · · focus · HN ↗
      Think about it, the key analogy is just terrible. In the origin domain, losing a key is always bad, and making a key available to all is a non sequitur.

      It's not like non-technical people understand asymmetric cryptography. Or even technical people, for that matter.

      Maybe we should refer to the public key as an address, and the private key is just a password again. You can send stuff, securely, to an address. And you can verify the sender when you have their address (ie check the signature).

      1. fragmede · · focus · HN ↗
        Or how about we call it the lock. There's the (private) key, and it fits the lock (public key). You can pass the lock around, but you need the (private) key to be useful.
        1. danw1979 · · focus · HN ↗
          I dunno if that works or is any less confusing, to be honest.

          I don’t think there’s any process or entity in the physical world that is reasonably familiar to most people that is even remotely suitable as an analogy to public key cryptography.

          1. tialaramex · · focus · HN ↗
            I think this is worth highlighting. Public Key Cryptography is a surprising idea. Like Computation, if you'd told a 19th century mathematician about this, they might buy it as a concept but deem it unlikely to ever happen in practice or be of any significance, in the 20th century these were both realised and caused a massive change to our society.

            These are not analogs to things ordinary people had already seen. For Computation we just got used to it being everywhere and so we don't need to explain it so much.

          2. raddan · · focus · HN ↗
            For what it’s worth, it’s the analogy I use, and for the twenty or so college sophomores I taught on Tuesday, the analogy is sufficiently understandable that they were able to generate and use SSH key pairs to do their homework.

            I think the reason we (the HN crowd) don’t like it is that the analogy starts to break down when you start thinking through all of the operations you can do with public keys. But this does not matter much for somebody learning to use them for the first time. I’ve had to grow comfortable with the idea of giving people imperfect explanations so that they can build an intuition. Once that happens I can return with the mathematics so that they can really understand what is going on.

            1. faxmeyourcode · · focus · HN ↗
              This analogy is exactly what made it click when I was a teenager.
        2. Reubachi · · focus · HN ↗
          More people being exposed to asymetric keys probably leads to some confusion when imagining the public keys roll as lock in a symetric system.

          IE; the existence of the asymetry allows for the public key to function more than just a "lock", but a much more easy to rationalize "signer attestation.

        3. TeMPOraL · · focus · HN ↗
          Except it makes no sense if you look at the thing, because then you realize that the "lock" and "key" are literally the same thing. In the real world, the lock and the key are completely different objects - there's no way to confuse which is which (and there's no way for one to act as the other if you use them in opposite order, either).

          The analogy doesn't make sense because it's skipping the existence of the third thing that's the actual (pad)lock - the encryption/decryption software. And it does that because it wants to talk about data as having the property of being "locked", which makes no sense in the first place, but that one isn't immediately obvious.

          The whole analogy of locks and keys fundamentally makes no sense when talking about data, because locks are external devices, attached to or directly containing the protected thing, while encryption is the process of scrambling the very thing being protected.

          All confusion stems from this bad choice of analogy, trying to "make it simple" for the normies.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.