‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. yencabulator · · focus · HN ↗
    > how to use the DMV's public key to check whether a California ID is real.

    That's not what the signature guarantees, though. It says the combination of textual information on the card is *someone's* valid driver's license. The signature doesn't even cover the photo! It just limits the forgeries to using identities of real people.

    Compare to <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Biometric_passport" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Biometric_passport that actually contains a digital photo, with a signature.

    1. returningfory2 · · focus · HN ↗
      IIUC, the forgery path then involves getting any legitimate California license and changing the photo only? I guess that works.
      1. yencabulator · · focus · HN ↗
        The forgery path is downloading the leaked database of 153 million driver&#x27;s license images, picking one with the right gender, rough age, weight and height, and printing a card with that text+barcode and your photo.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.