‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. bzmrgonz · · focus · HN ↗
    It baffles that people think it's a bad thing to disclose a public key. That's their purpose actually. Sure we now have the post quantum computer threat, and some state actors are harvesting keys, but quantum computer is going to disrupt so much, that Id verification won't even matter really.
    1. jrochkind1 · · focus · HN ↗
      The OP itself and the title given here uses confusing language that isn't helping.

      "Recovering the signing key", the title suggested by HN submitter -- I would not call the public key a "signing key". I might call it a "verification key". You can not recover the "signing key".

      The author of the OP: "ECDSA has a specific cryptographic property that given a signature and the message it signed, you can mathematically recover the public key that produced it" -- no, the "public key" did not produce the signature!! If you could actually recover the private key that was used to produce the signature, that would mean that ECDSA was fundamentally flawed in it's very fundamental design, and it is not, in this way anyway. You could say "public key that can be used to verify it", or "verification key that goes with the private key used to sign it", or anything different from what they said.

      This stuff is confusing for people who didn't learn it long ago, and people who should know better using incorrect and/or misleading language does not help here! Just say "public" and "private", the actual standard terminology. if you aren't sure how to decribe them more transparently, these already at least describe which key is intended to be secret and which isn't! -- calling the public key a "signing key" or "a key used to produce the signature" is just wrong.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.