Estonia's e-residency program expands abroad
e-estonia.com
e-estonia.com
The first thing to know is that you have to physically be there to apply. I went to Estonia and applied at the local police station. I know that sounds weird but thats how you do it. In Estonia, this is where you go to renew driver's licenses and a lot of governmental things.
It was relatively painless. I didn't need to make an appointment. It's just like a DMV. You take a ticket and wait. The woman behind the counter asks some questions, for your passport, biometrics (photo and finger prints) and 50 euros. You then you wait to hear a response within two weeks.
An annoying part is that you have to show up again in two weeks to pick it up in person. Mine is still waiting for me in Estonia as I've not been back yet and I can't have a friend pick it up for me (it has to be me!).
Be prepared to spend two weeks in Tallinn, therefore, which isn't bad as the prices are quite reasonable and the food is good.
Out of curiosity, what was your motivation for applying? It seems to me that the only obvious use-case for e-residency is to run a company registered in Estonia while living elsewhere.
My motivation is eventual real residency. This just makes it easier.
Step 2: NSA, GCHQ, Russia and China steal the whole fingerprint database, which includes your fingerprint
Step 3: Now your iPhone/Android phone that uses fingerprint reader is vulnerable to hacking
I'd recommend everyone visit Tallinn.
On a quick walk you can see a medieval castle, renaissance architecture, soviet architecture, and postmodern examples from the sprint west after Baltic independence. It's like a walking through a timeline of European history.
I'd strongly advise against January though. :)
Not anymore, according to the article.
Some references: https://jhalderm.com/pub/papers/ivoting-ccs14.pdf ( Lookup the ID-card part. ) http://www.wassenaar.org/ ( Crypto is defined as a "dual use" weapon. )
The worst aspect of the estonian ID-card is simply the fact that your private key is not private, and stored in the card itself. You as a user, can not revoke or resign it. At the same time however, it holds full legal status and dominion over your identity.
- When voting, each voter receive a receipt with a random number assigned to his vote
- All the votes are published with the random numbers alongside them
- Each voter can verify that his vote was correctly saved by looking at his assigned number in the list
It's not perfect but relying on a central server is far worse I think (like the paper said)
Otherwise the server can lump together several voters who voted for the same option.
I don't know offhand how Debian is doing it, but they've got some mechanism like that for their ballots. Since it's been around forever I'd guess it's solid.
Here's a rather long but very interesting tech talk about electronic voting schemes which maintain the secret ballot property: https://www.youtube.com/watch?v=ZDnShu5V99s
The important point for me was that getting e-voting right is so incredibly important to a democracy that it should be treated as a national security issue. The Estonian E-voting system was clearly treated as a government IT project as procedures like "don't plug in a personal USB stick into the master counting server" are violated if its more convenient than replacing the broken DVD drive. Worse, politics gets mixed in which means that security concerns are dismissed with complacent and technically questionable statements like "nice people who care about computer hygiene have no viruses".
Why?
Even without getting into complex election fraud, parties in many countries already know how to buy votes in a paper-ballot system: you simply offer a bottle of vodka for a cell-phone photo of the ballot marked the way you want.
And even without that, there's a much simpler calculation in play in Estonia. Keskerakond (the party closely allied with Putin's party), only got 7.7% of the e-votes in the most recent election: the demographics of online voters has very little overlap with their supporters. If only the paper-based votes were counted, Keskerakond would have won the election.
Sure, they'd still have the complication of actually forming a government; but it's much more likely they'd be able to do that with a first-place showing (and possibly without Savisaar).
With those sorts of numbers, if I were a Keskerakond strategist, I'd be doing everything I possibly could to discredit e-voting too. And the more "useful idiots" I could find, who'll merrily interfere in the elections a country they know very little about because it suits their own ideals, the better.
you have to keep tens of thousands of people quiet for that to work without any suspicion at all. with e-voting you can commit major fraud without anyone noticing and with much much less evidence trail.
This certainly doesn't protect against all attacks (and it's only one part of the security system) — but it _does_ help against the threat of a virus that invisibly intercepts your vote to turn it into something different. If people started reporting that their phone showed a different vote to what they thought they'd cast via their laptop, then the election would be in trouble.
The fact that it only shows you this for a short time period also gets around the problem of you being able to show to a third party how you voted (in cases of vote-buying or coercion), because under the Estonian system you can also vote as many times as you like (with only the final vote being counted). So you could use this verification to 'prove' to someone that you voted the way they wanted you to — and then log in again an hour later and vote for someone different.
However, I'm much less concerned with this threat than with the much simpler virus that simply changes your vote in real time.
Most people I know don't leave their ID card connected at all time; so the virus would need to wait for the next opportune moment, rather than silently casting this vote whilst you're not at my computer — thus significantly increasing the chances that at least some people would notice it. If it also had to load the voting software again to send the vote (I don't know enough about the protocols around this to know if it would have to or not), then it would be even more likely that some people would notice.
And on top of that, don't forget that the ID-card software shows on launch how many times you've digitally signed things. Most people almost certainly don't pay much attention to that number, but I'm sure some people would notice it rising unexpectedly from the virus, and an investigation could happen.
That's the theory anyway. We'll see if it pans out.
Personally, it's an important step for me in getting a real residency beyond one tied to a company that isn't my own in the EU.
http://www.theguardian.com/technology/2012/apr/15/estonia-us...
However, there is some discussion about whether its a completely new legal status which would do things like make you liable for double taxation. Personally I find that highly unlikely, but IANAL, YMMV etc.
Yeah, that was the type of obligation I was referring to.
Why one should? yes, access to EU market, access to good services (google, paypal, soon stripe etc), access to e-banking, and generally digital signature gives hassle-free business environment (signing contracts with partners, filling e-tax declarations, administrating business on a business portal).
Why Estonia is doing it - to increase its economic reach / gain more customers / PR