‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. bzmrgonz · · focus · HN ↗
    It baffles that people think it's a bad thing to disclose a public key. That's their purpose actually. Sure we now have the post quantum computer threat, and some state actors are harvesting keys, but quantum computer is going to disrupt so much, that Id verification won't even matter really.
    1. morsch · · focus · HN ↗
      Think about it, the key analogy is just terrible. In the origin domain, losing a key is always bad, and making a key available to all is a non sequitur.

      It's not like non-technical people understand asymmetric cryptography. Or even technical people, for that matter.

      Maybe we should refer to the public key as an address, and the private key is just a password again. You can send stuff, securely, to an address. And you can verify the sender when you have their address (ie check the signature).

      1. SilasX · · focus · HN ↗
        Yeah, that always bothered me about the terminology. My fix would be to call it a lock -- everyone understands that you can share those and it doesn't make them any easier to open.
        1. morsch · · focus · HN ↗
          That analogy works for encryption but doesn't really work for signature verification
          1. snmx999 · · focus · HN ↗
            Maybe we should not use analogies? Just call them secret-text and public-text.
            1. gowld · · focus · HN ↗
              "public-text" doesn't describe the purpose of a public key.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.