‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. bzmrgonz · · focus · HN ↗
    It baffles that people think it's a bad thing to disclose a public key. That's their purpose actually. Sure we now have the post quantum computer threat, and some state actors are harvesting keys, but quantum computer is going to disrupt so much, that Id verification won't even matter really.
    1. remix2000 · · focus · HN ↗
      I think it depends on the context? It's in an ID card's design goals to be provably valid, so it's pointless to not publish its public keys, but something like SSH pubkeys, uhh, should I really be so eager to just publicly dump all of mine…?
      1. miki123211 · · focus · HN ↗
        github.com/your-username.keys; they're already there.
        1. remix2000 · · focus · HN ↗
          The signing key? Sure, but it's not an SSH access key.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.