Hacker News new | ask | show | jobs
by Gigachad 1370 days ago
We will literally never teach the whole world to use current crypto tech safely. It needs better UI.

At the root of the problem, people will forget passwords and lose physical tokens and will need some other way to restore access.

2 comments

If this were being used for SSNs, you'd have a central authority to restore access. If you lose your passport, they can issue you another one and mark the old one as lost/stolen. You can do the same thing for key pairs.

The main problem it solves is giving a sketchy client your SSN on your I9 without allowing them to use it/leak it to scam groups to spin up a credit card on your behalf.

The main problem with the “key escrow” scenario is that the government can access your private key, so this solution is still not meaningfully secure. What do you think is more likely: that this new institution will be magically invulnerable? Or perhaps you will have just created an irresistibly valuable target for social engineers and hackers that inevitably will fall?
Not magically invulnerable, just a lot less vulnerable than a plain text 9 digit number that you hand out to hundreds of people over your lifetime.
Good news. A good chunk of the world already uses crypto for identification. My eID card is just that, i can auth with a chip and pin. This is normal in a lot of the EU.
I don’t want my identity to be linked to many of those accounts. So I’ll take a yubikey. Second, I’m glad I don’t live in a country where I’m required to carry id.
Just because a country has IDs doesn't mean you have to carry it all the time. Where I'm from (Germany) you don't have to.
You don’t have to but in situations where you are unable or unwilling to show your ID and a peace officer wants to check your identity, they’re entitled to take you to the precinct.