Hacker News new | past | comments | ask | show | jobs | submit login

Truthfully estonia's id looks weak too. Stealing an ID is easier than stealing and impersonating biometrics.



Biometrics are highly problematic in this context. IF someone steals your private key, you can jump through some hoops and get a new one issued, and regain control over your identity.

If someone steals your biometric data (and that is a thing that can happen through a variety of methods), there's no form you can fill out be issued new retinas. Your identity is permanently compromised.

A moderate increase in security[1] in the average case in exchange for catastrophic failure modes isn't good tradeoff.

(And given the very, very troubled history of biometric security, I'm being charitable assuming it's even an increase.)


Stealing an ID and two PIN codes without the user revoking them all. That's quite hard, isn't it?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: