Hacker News new | ask | show | jobs
by stavros 216 days ago
I didn't say anything about the data the government has or doesn't have. I'm talking about perfect enforcement. Try faking a digital ID.
5 comments

And, specifically, frictionless perfect enforcement. Kind of like CCTV you can pull on request after a crime, vs proactive permanent ubiquitous surveillance (looking at you, Flock Safety).

It feels healthier for the enforcement apparatus to have a budget, in terms of material personnel or time, that requires some degree of priority-setting. That priority-setting is by its nature a politically responsive process. And it’s compatible with the kind of situation that allows Really Quite Good enforcement, but not of absolutely everything absolutely all the time.

Otherwise ossification feels like exactly the word, as you said, stavros: if it costs nothing for the system to enforce stuff that was important in the hazy past but is no longer relevant, nobody wants to be the one blamed for formally easing restrictions just in case something new bad happens; 20 years later you’re still taking off your shoes at the airport. (I know, I know, they finally quit that. Still took decades. And the part that was cost-free—imaging your genitalia—continues unabated.)

This is based off of a biometric passport, which have been digitally signed for a very long time now.
We have this issue already with biometric passports and ID cards.
> Try faking a digital ID.

Since most of that "digital ID" manifestations are just pixels on a screen, these are not a problem to fake pixel-perfect.

I did some limited travel during the COVID era, including areas that did not want to recognise my country's digital vaccination certificate. I presented them with a pixel-perfect picture of their own country's digital vaccination certificate. It's easy to copy from a screen of a friend, and it's not complicated to create your own Apple Wallet pass that looks like the one you want.

How did you fake the cryptographic signature QR code?
I was showing a real QR code -- that was issued to a person who wasn't me. As soon as that produced a big green checkmark on anyone's QR scanner, I was in.
Then you're hoping they won't try to match the info on the screen with the info on the paper, which is very easy to foil (just don't skip the check).
If they need to match with the info on paper it's not clear what the case for "digital id" is? If one needs to present "digital id + paper id" one can simply present the paper id as they do today.
They won't. They'll just check the digital ID. I said you can't fake a digital ID, you said you've faked a physical ID, which isn't really relevant.

Digital IDs can't be faked. The only way to fake them would be to convert them to physical (what you did) and hope that the physical ID gets accepted.

I know a guy who went to jail for that. He was in the news and everything. Banned from this country for life. Warned him that what he was doing was a stupid idea, he was even doing it for others who also got arrested...
I don't know what "that" was, and again, I had both the vaccination and the digital certificate to prove it; the system in place would not accept the real documents, so I fed it with other documents that it did accept.
Showing a QR code that belonged to someone else, like you know, the thing you said you did

Eventually in a system like that they may refine their procedures and then you get dinged essentially...

Yeah, perfect enforcement is dystopian. I don't think most people understand this, but your point is very well taken.