2FA using a postcard
shkspr.mobi
shkspr.mobi
I think it is a very smart & less cumbersome way to verify physical address.
As a side note, I really like the way the author of this blog has constructed his "Contact Me" bit at the bottom, it's very intuitive, clever, and uses URI schemes where appropriate, nice job!
It also is, quite literally, lying to people. I personally hate when businesses do that.
It's also an invalid way to verify where someone lives. It's possible to "verify" any address at which you can have mail sent to your name and receive, for example, a previous address, an office, a co-working space, an abandoned building or vacant apartment, etc.
This is why it's such a big deal that Nextdoor makes each user's address public inside their neighborhood group by default — there are trivial ways to get into a neighborhood group.
Picture of a card: http://2.bp.blogspot.com/-bhasaP2UfVA/T-itxSP6-uI/AAAAAAAAAF...
Site: http://NemID.nu
For some reason Germans love these cards as well
When they Swedish post office started their online portal back in the mid-to-late 90's they would mail your initial password home when you signed up. I guess because postal mail is all they knew?
This approach has the interesting property that, in order to cheat this unofficial system, you've have to commit either mail fraud (interception) or vote fraud (fake entry in election registry).
Canadian proof-of-concept here: https://github.com/patcon/id.c4nada.ca
Ping me on Twitter if you're interested in working on this in Canada or any other jurisdiction. Would be rad to create an auth system for citizen projects to validate identity/ward/district/state with high assurance. That way, user desires can be passed to reps with reasonable certainty that numbers reflect real voters.
And could start doing fun stuff with encryption keys or keybase integration or things like that ;)
There has been a national identity register here since 400 years, so I might be a bit biased, but I never really saw a problem in everyone knowing where other people live.
The most common problem is you have an abusive ex-husband, and some similar things like that, but then the national identity database is just a very minor side-problem compared to the actual problems...
But yeah, I get parts of it. I remember that my granddad was always a bit miffed over the identity number he got, since he lived half his life without it. Before that the name and address was considered unique enough.
But it's such a nifty system - we get all updated addresses automatically, and it improves the credit scoring processes so it's very easy to buy things online, etc.
I live in Denmark, so I have a Danish "personnummer".
e.g. http://www.experian.co.uk/business-express/identity-solution...
Last year I had a number of cases of identify fraud. In one case somebody went into a phone shop, gave just my name and address, and walked out with a iPhone 7 and a £60/mo contract. As the director of a limited company my name, address and date of birth are public record, so it seems really stupid that this is how identity is usually 'verified' in the U.K.
As there is no way to remove yourself from these databases (short of committing credit score suicide), I now pay £10/year to be on another database:
There was an option to verify by phone number - but it didn't work on my mobile. I assume that they use landline numbers to see if you are in the right geographic area.
It is also easy to lose your privacy.