Hacker News new | past | comments | ask | show | jobs | submit login

Isn’t there a PIN to protect these? Also, I’m assuming GP meant “not visually displaying as ID”, not “trying to swipe the PIV at a random computer”?



The PIN is required to get the card to perform cryptographic operations, not list certificates -- although the certificates aren't a secret, within DOD there's sites like DOD411 to get anyone's certificate, though I haven't checked for an FPKI equivalent.

The real reason not to use your PIV for ID in random places is that it's meant to be used as an ID for you acting as your official capacity. This can also be seen in the case where people have multiple PIVs to represent their multiple identities, like National Guard who may have a PIV as a contractor and a PIV as a National Guard -- they would use the correct one depending on what capacity they are acting, or none if it's not part of their official duties.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: