There's actually nothing new here: digital IDs were already a thing, corruption has always been a thing, and the referendum process worked correctly to remind the politicians who is in charge.
No they don't but I can see why you might think that.
ePassports (the ones with the stylised "chip" image on the cover) do have X.509 certificates baked into them. And ePassports do say "We are the government, and this is Jeff" (if you are Jeff) but that's not what the X.509 certificate says.
Each X.509 certificate is one of a relatively small number minted by your government which says "We are the government of country X and this is a public document signing key".
Then the passports all contain raw data (such as a photograph and summary information about their subject) with this certificate and a signature over the raw passport data that can be authenticated with the public signing key.
So there's an X.509 certificate but it isn't for Jeff, and there's data about Jeff, but it isn't in an X.509 certificate.
No.
https://www.reuters.com/article/estonia-gemalto-idUSL8N1WD5J...
> Estonia's Police and Border Guard Board (PPA) said in a statement Gemalto had created private key codes for individual cards, leaving the government IDs vulnerable to external cyber attack, rather than embedding it on the card's chip as promised.
"Much cheaper" here means we might expect criminals to break the RSA key for an individual Estonian ID card for less than a million bucks, whereas by design this ought to be impractical at any plausible price. It doesn't mean your bored teenager can make a fake ID on his laptop on a Friday evening. As a practical matter it seems likely key officials & police could be bribed for less than a million bucks, but forging RSA signatures might still be desirable in some circumstances, and anyway of course the mere possibility of this happening ruins public trust in the scheme.
Estonia switched to P-384 keys on the same platform. Unlike choosing random RSA keys (which involve finding large primes) choosing a good P-384 key is trivial so there's no temptation to come up with clever but insecure algorithms to mint keys.
What's interesting about this flaw is that it only happens because the keys are minted on the Infineon device you own. But we know Estonia has historically had some weird incidents which are best explained by keys not being minted on device but instead burned into the ID card after being made (and potentially recorded) elsewhere. Estonia's laws establishing these cards are clear that mustn't happen (if it did the government can seamlessly impersonate any ID, including ID issued to citizens, non-citizen residents and diplomatic staff) but evidence suggests it did, at least a few times and at least on some older platforms.
Estonia's IDs are all public using a very different scheme to Certificate Transparency, since it assumes you trust the Estonian government to decide which IDs exist - but with similar effect, if anybody is minting bogus IDs there would be a smoking gun in the official public records of Estonia.
On the other hand if the government (or a government agency perhaps without wider knowledge) has copies of some or all keys, they would be able to decrypt messages sent to citizens/ residents using the embedded PKI. We would not necessarily have any public evidence that this was happening if indeed it was happening.
You should probably be confident in Estonian IDs as proof of someone's identity in the usual course of things, but it may be prudent not to rely on this to keep secrets from the Estonian government or its allies.
This is in part because no score is ever released related to prior delivery (ie, no central assessment record), and attempts to include it get tied up in process issues (ie, rights to respond, litigation) or claims it is subjective. It also overlaps with govt agency disfunction around scope and requirements and no govt manager wants a failed project, so everyone just sweeps them under the rug and keeps moving. It is crazy though, you are literally hiring the same HORRIBLE firms over and over.
What is PARAMOUNT is that you be willing spend absolute metric tons of UNPAID time responding to RFP's, have enough money in bank to lose 4 out of 5, be willing to go through 2 year RFP processes, be willing to agree to every item on the requirements lists filled with further buzzwords and "standards". This does NOT attract high performing companies, no competent engineer would even put up with this / sit through this. So you get body shop type consulting firms, using giant java framework and other solutions, and everything is insanely siloed.
The crazy pricing is often justified because the hassle in dealing with these contracts from a contract admin overhead can absolutely DWARF actual deliverables, and nothing has to be logical (and sometimes is not).
My recommendations here would be either:
a) just pay to bring stuff in house so you get cooperation, develop open source apps and prohibit any scope creep outside of absolute minimum needed until project is in operation. EVERY freaking agency hangs 100's of new requirements they never even used before onto these projects - solutions can be undeliverable and unusable as a result, for example 40 questions PER VACINNE SHOT here in California is the height of stupidity to make these idiots feel important.
b) pay for actual use / adoption, and let there be a somewhat free market. A lot of time the users of any govt system have ZERO input. Oddly, if they let agencies find their own solutions on a smaller scale, whatever you lose in "efficiency" by not having the megaproject (hint nothing - mega projects = disaster in govt land) you would see some natural winning solutions start to bubble up. I worked with an agency with a totally fantastic contract management / invoicing system, and I kept on wondering, holy hell, they actually got it right. I started to see other agencies use it in neighboring govts - it was great - people really liked it (super easy use, allowed users to do the google, Microsoft etc login even which is unheard of) and it was fast which is also rare.
But then someone convinced the head tech folks they should stomp on everything with the new and improved people. They actually had to roll back the mega project for another year (after years of dev) because it didn't even cover a fraction of what old systems easily did.
The reality is that you only hear about failed projects. When was the last time that you heard about taxes not being collected or welfare payments not being paid or SNAP cards not being refilled?
It’s all background activity, and those awful contractor companies are often responsible for material aspects of delivery.
And they're usually pretty competent, especially the few ones that work for the federal government.
for every single job you have to answer 30+ questions. no getting around it. my friend who is a vet just thinks this is normal. lol
I think you may underestimate the system needed. Identity management is the tip of the iceberg: this needs to tie into any future digital currency, income taxes, property ownership, government benefits, and who knows what else. Any off-the-shelf product will need customization. I’m not saying it can’t be done.... it SHOULD be done. But not in 6 months.
> Identity management is the tip of the iceberg: this needs to tie into any future digital currency, income taxes, property ownership, government benefits, and who knows what else.
I'll put my shoe on my head if you can find me a private company that can do this in six months. Previously on HN: CDC website built by Deloitte at a cost of $44M is abandoned due to bugs (technologyreview.com)
https://news.ycombinator.com/item?id=25975110
1167 points by donsupreme 35 days ago
664 comments
And we're talking about Italy, not some first rated technological paradise.
also, the government already owns all my data, from birth onward. the authentication system makes it so forgery is much harder from the officials themselves, so this protects me from that as well.
For how it is designed, there are a dozen companies that offer this service. The citizen can choose the one they trust more (there are some small differences between them; some require to pay a small fee; others require you to physically go to an office to be recognized; others offer you an app to login through a QR code...) BUT they are all required to implement industry-standard security. At one of my past jobs, many years ago, I had to implement this login system in a public portal. It was a mess (the technical specification was on a PDF written in bureocratic language) but shortly after a new team overtook the project and created a proper website with SDKs etc. To this day, the only known attacks to SPID were Phishing attacks, that require the user to do some dumb action on their side.
... I mean, as a French citizen who kind of wants my government to keep existing, I also agree with the statement you quote?
Our government's public-facing IT systems have gotten better over the last few years, but my default expectations for any new projects would still be for them to mess it up.
Of course, the problem is I'd also expect the average contractor to mess it up in very similar ways, for similar reasons.
That 1% though, is going to have all the weird edge cases.
There is no way it could be done in 6 months given any reasonable parameters you care to throw at it.
So, like the US?