‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. KingMachiavelli · · focus · HN ↗
    All of this is nearly pointless unless the photo itself is in the barcode and also signed. You only need a leak of a few hundred real IDs to cover all of the identifiable characteristics (hair, eye, skin color, approx height and weight). Leak a few hundred thousand a year and now you can’t even flag leaked IDs without some false positives.

    A fake photo plus a valid barcode will pass any current check right? Unless you still do a secondary proprietary photo lookup that I don’t think exists.

    1. lxgr · · focus · HN ↗
      The Austrian ID card does that. It’s a really blurry black-and-white photo only, but it’s still recognizable and I find it quite impressive that any type of photo (in addition to its public key signature) can fit into a QR code at all.
      1. miki123211 · · focus · HN ↗
        This is a radical idea, but we should remove photos from ids entirely.

        Having the photo there just encourages sloppy ID checks by human eye, and it's much easier to mislead the human eye than it is to forge an NFC chip.

        If the photo was in the chip only, we'd force ID verifiers to do their job properly, and make forgeries structurally impossible. With basically everybody having an NFC-enabled phone now, you wouldn't even need people to get extra hardware for this.

        1. lxgr · · focus · HN ↗
          I have to say that I really don't love the idea of having my ID scanned (and definitely not stored, wink wink) every time I buy a drink etc. Having both paths available, depending on the "severity" and expected anonymity of the situation, seems nice to have.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.