HNHacker News
TopNewBestAskShowJobs

Ryan5453

701 karma · joined December 19, 2024

CS student @ Northeastern

email me: ryan@ryan.science

submissionscomments
Ryan5453··on Keys Not Included: recovering the signing keys for US driver's license barcodes
Generally it's configurable. The one that comes to mind first is TokenWorks's Anti-Passback feature which says "Set your custom timeframe (1 hour to 7 days)"

https://www.idscanner.com/product-features/anti-passback/

Ryan5453··on Keys Not Included: recovering the signing keys for US driver's license barcodes
The ICAO standard for passport chips is really well done. Especially since you can read the photo from the chip itself.
Ryan5453··on Keys Not Included: recovering the signing keys for US driver's license barcodes
Thank you! Just updated it to use the the browser default monospace for inline text.
Ryan5453··on Keys Not Included: recovering the signing keys for US driver's license barcodes
You can only store ~1100 bytes in a PDF417 barcode so storing the image itself it unfeasible. And storing a signature of an image you don't have access to is useless. Passports are able to do this because the smartcard chips they use can store at least 32 KB of data (usually more).
Ryan5453··on Keys Not Included: recovering the signing keys for US driver's license barcodes
> Seems doubtful! I expect the forgers used a real signature from another card instead, so it has the right key but the wrong data. Reverse engineering the process as the author did and making up their own key wouldn't be of any value to the forgers.

This was just bad wording. I meant to say "someone else's key" in the context that it was a key generated by the forgers rather than the state DMV, will update to make it more clear!

> This is not wrong, but should come with a little warning. A real verifier needs to additionally check the encoded data matches the human-readable data on the front of the card.

Correct, but simply checking that it matches the front is likely not enough to deter fraud. You could extract the barcode data from a real ID and put it on a physically different (fake) ID with a different photo and it would still return as valid. To detect this you generally would need a higher end solution (IDScan.net/VeriScan's ID authentication solution (yes... the one that just leaked everyone's data), TokenWorks' IdentiFake, IDScience, amongst others) that does the same high resolution UV/IR checks TSA does. But the forgers are good enough now to be able to sometimes pass those scanners too.

Ryan5453··on Project Glasswing: Securing critical software for the AI era
Pricing for Mythos Preview is $25/$125, so cheaper than GPT 4.5 ($75/$150) and GPT 5.4 Pro ($30/$180)
Ryan5453··on Google restricting Google AI Pro/Ultra subscribers for using OpenClaw
Antigravity gives access to Sonnet and Opus 4.6, I would presume most people are using those models rather than Gemini
Ryan5453··on Developing Developers (2015)
There is a decently large amount of TAs for the freshman first semester course (aka Fundies 1) — this semester has 77 TAs