Iowa to launch smartphone driver's license
desmoinesregister.com
desmoinesregister.com
A simple hack utilizing this vulnerability that would be hard to fix is getting someones phone and then replacing their image with yours (e.g. by running the real program in the background and an overlay to cover their image and replace it with yours, you could get fancier and find the distortions in the image below and apply them to yours as well). In any case, the key here is that a human looks at the image, not a machine.
In reality, if you know your license number you don't even really NEED to carry the card. The app just just an easier way to carry that number around. I've known people that have been stopped without a license on-hand but able to recite their number, resulting in no trouble at all.
Well that's one way to facilitate a warrantless search. Even without the obvious privacy element, "Sorry officer, my ID ran out of batteries" seems like a pretty common problem.
And oh, the convenience. It's already unlocked for me.
[1] http://www.cnet.com/au/how-to/ho-to-pin-apps-in-android-5-lo...
So here, the government steps in and says "here's some closed-source software that you now will trust your life, security, property and government with. You're not allowed to know how it works, if you try to find out we'll throw you in prison."
Yes, HN tends to be wayyyy on the side of disbelief in the official words of the government on topics of software & trust. But isn't that healthy? Isn't that the way it should be? When the governments come at us with secret software and threatens us against learning about it, we should absolutely assume that it is intended for evil. Otherwise, how will we know when it "actually" is?
Not that the number of voting machines has any influence on the ease with which electronic voting can be manipulated, but less than 130M votes (http://en.m.wikipedia.org/wiki/Voter_turnout_in_the_United_S...), distributed over 10M+ machines? That's less than 13 votes per machine, on average. if that is true, someone has been overspending seriously on hardware.
Yet republicans have lost 5 of the last 6 presidential votes.
Anyway, partisan politics is a distraction here: the integrity of our elections is increasingly in the hands of a few voting machine manufacturers who sell hackable, un-auditable black box systems. Here are some starting points in case you're interested in this beyond the typical R/D sniping:
</tinfoilhat>
I would imagine that verification of said license should happen wirelessly.
I bet we'd see a comment just like this at #1.
Let me tell you about the state tracking you, since you're worried about your ID being tracked. You know those signs on the freeway that say "15 minutes to Taylor Street" or "25 minutes to I-94"? Nice and handy, you know if it says 20 minutes when it normally says 5, there's a traffic jam. You know how they get that info? I learned this recently while working for a client that was involved in those signs being installed in that area. They scan the Bluetooth on drivers phones, and time how long it takes for a unique phone to get from one sign to the next. The average of that is the time that gets displayed on the sign.
So don't worry about your ID being scanned. They already know where you are. But obviously they're not sharing the information real widely, since the police took three days to find the person who hit my car and drove off even though I told them the description of the car, the driver, and the license plate number. So there's a little comfort I guess.
One of the really neat things about the modern radar units is that they feed into some software processing that can automatically detect accidents and other types of unusual events and alert authorities.
I'm not saying that there aren't people using bluetooth, but I suspect it's a small minority. I would think that if a municipality wanted to track individual vehicles through an entire section they would be more likely to use LPR, because it's a well established technology and there's a lot of inertia in government purchasing (read: unwillingness to try new tech/manufacturers).
Edit: there's also the confusing issue of vehicles that are tracked by radio transponders - these are going to be voluntary participants though, the obvious groups being people with EZPass type toll transponders and semi trucks with weigh station prepass devices (which are rather similar to the toll system). I wouldn't be surprised if municipalities use this data for traffic observation because it's already being collected for other purposes.
MADISON, WI October 18, 2010 - TrafficCast announced it has now finalized agreements with nine leading distributors of traffic signal and control equipment, enabling localized sales services and product support in forty-one states plus the District of Columbia for its innovative BlueTOADTM technologies.
MADISON, WI March 1, 2011 - TrafficCast International, Inc. today announced that Econolite Canada, Inc. will distribute its BlueTOADTM line of products, enabling localized sales services and technical support in the ten provinces and three territories of Canada.
For techies. For other people making the computer work is magic.
This will save so much time imo, and more secure than you're standard hard card which is way to easy to replicate.
But the nice thing (from a law-enforcement perspective) about plastic IDs is that they can be made expensive to forge/alter, and (forgeries aside) it's fairly easy to restrict the number of copies.
Drop your driver's license onto concrete. It's fine, isn't it? Care to drop your phone from the same height?
Verification method must include authentication and authorization by means other than human eye reading some text off a card (digital or physical).
Since I'm handing you the device I am in complete control of the output and can clone the output of another card or any signing cert/key embedded in the app. The incentive to do this is to: a) Get into a bar or b) Avoid being arrested on an open warrant. Either of which I can see someone paying and risk breaking the law to accomplish.
Or for police specifically, it could look up the token in the state's database to access a photo and have a human verify that the photos match (and match the person presenting the id).
The structured information is easy to sign; the photo is more difficult. I'd be curious if they had anything intended for this.