There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.
There is a reason why numerous security features are embedded in physical documents like watermarks, holograms and NFC. That's so the authenticity can be inspected in person. A picture has none of those, so it should not be treated as a credential.
This is how biometric "authentication" works - you slide a picture (of a face, or maybe a fingerprint or hand geometry) under a door, and the guard on the other side of the door looks at the picture, maybe compares it to some database somewhere and then says PASS/FAIL. Maybe the device taking the picture has some sort of cryptography to prevent yourself from shoving a picture of some authorized person. Usually not.
People keep trying to find the correct magic spell to make biometrics "foolproof". That's a waste of time. Blackhat/DEFCON type conferences were showing people how to make fingerprints out of (the gelatin that makes) gummy bears back in the late 90s. Make them thin enough and you can fool pulse detection (carjackers in some Asian countries were chopping fingers off to bypass theft deterrent systems that used fingerprints).
Because there is no other universal method that works online, and because companies don’t really care about identity verification – they just need something “good enough” so that they can say “hey, we’ve followed industry standard protocols, how could we have known this passport scan was photoshopped?”
And to be honest I think it’s for the best. I really don’t want to be scrutinized even more online (and give even more personal data so it gets leaked a couple years later).
I don't think you should be able to do anything with your passport online. That's a document that should only have value if you're actively holding it in your hand.