Hacker News new | ask | show | jobs
by akira2501 662 days ago
> It would be quite straightforward to make your biometric identity a public private key kind of setup.

There is no repudiation, attestation or key rotation in this setup, with all the attendant problems that creates.

2 comments

All of those things can be part of it. You're totally forgetting where we're coming from right now which is your identification or attestation is a little plastic card that is issued by the government based upon some other pieces of paper. There is no rotation of that either. The primary thing people use to identify you is your social security number in the United States which was never even envisioned as a way to identify someone it was simply an account number.

What I'm proposing puts the private key in your hands and requires you to locally do some sort of second Factor authentication to release it so it can be validated against the public key that the government or another entity has.

To issue or reissue or key rotate as you say can support the same methods we have now for determining identity and it also provides a better more secure method for determining identity.

You have to keep in mind perfect is the enemy of good and any solution that puts your identity in your own hands is massively better than what we have now and what any country has now.

you can always save up for plastic surgery!
"In response to this data breach we are offering you free Experian plastic surgery services for the next year."