Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"... almost no government has the IT capacity and resources to single-handedly develop an eID quickly and to the appropriate standards." Bullshit. We're talking identity management here. Any government that can't handle that internally doesn't deserve to exist. What that's really about is feathering the nests of tech industry donors (and/or the non-tech middlemen or middlewomen who seem to grow like weeds around the tech sector). A handful of IdM SMEs with serious field experience could set it up in six months: assuming they had sufficient backing from their government employer to overcome static at Layer 8 of the OSI Model, you know,"politics".


I don't think you could do it in six months, but the good news is you wouldn't need to. Passports already have an x509 certificate in them saying, "we are the government, and this is Jeff". So the government already know how to do this, they just were trying to give a gift to their buddies in private industry and they got caught and got their hand slapped by the citizens.

There's actually nothing new here: digital IDs were already a thing, corruption has always been a thing, and the referendum process worked correctly to remind the politicians who is in charge.


> Passports already have an x509 certificate in them saying, "we are the government, and this is Jeff"

No they don't but I can see why you might think that.

ePassports (the ones with the stylised "chip" image on the cover) do have X.509 certificates baked into them. And ePassports do say "We are the government, and this is Jeff" (if you are Jeff) but that's not what the X.509 certificate says.

Each X.509 certificate is one of a relatively small number minted by your government which says "We are the government of country X and this is a public document signing key".

Then the passports all contain raw data (such as a photograph and summary information about their subject) with this certificate and a signature over the raw passport data that can be authenticated with the public signing key.

So there's an X.509 certificate but it isn't for Jeff, and there's data about Jeff, but it isn't in an X.509 certificate.


Nifty, where are the specs that explain that? I got as far as the ldif files from ICAO with all the signing keys in then, but couldn't find examples of the part you are talking about.


Belgium has been doing digital identities for years now, we had our first identity cards with chip and digital signature I think 15 years ago? I frequently use it to sign documents and login to some government stuff. So if Belgium, which didn't have a government 3 out of the last 10 years, can do it, surely Switzerland can do it too.


Except Belgium didn't build it. They contracted it out to Zetes. https://peopleid.zetes.com/en/reference/eid-belgium


And Estonia too!


and Sweden. But these are largely outsourced to private companies iirc. There was a scandal in Estonia where they had to recall all the ID's because the main private key which signed them all got leaked (and that key was held by a private company)


To be more specific than the existing "No" reply, what famously happened is that Estonia's IDs used Infineon-based chips for a period of time with 2048-bit RSA keys and Infineon's RSA implementation mints RSA keys with a peculiar property that, once you know about it, makes breaking them much cheaper than it should be. CVE-2017-15361 - for HN readers it's more likely you were impacted by this defect in a Yubikey.

"Much cheaper" here means we might expect criminals to break the RSA key for an individual Estonian ID card for less than a million bucks, whereas by design this ought to be impractical at any plausible price. It doesn't mean your bored teenager can make a fake ID on his laptop on a Friday evening. As a practical matter it seems likely key officials & police could be bribed for less than a million bucks, but forging RSA signatures might still be desirable in some circumstances, and anyway of course the mere possibility of this happening ruins public trust in the scheme.

Estonia switched to P-384 keys on the same platform. Unlike choosing random RSA keys (which involve finding large primes) choosing a good P-384 key is trivial so there's no temptation to come up with clever but insecure algorithms to mint keys.

What's interesting about this flaw is that it only happens because the keys are minted on the Infineon device you own. But we know Estonia has historically had some weird incidents which are best explained by keys not being minted on device but instead burned into the ID card after being made (and potentially recorded) elsewhere. Estonia's laws establishing these cards are clear that mustn't happen (if it did the government can seamlessly impersonate any ID, including ID issued to citizens, non-citizen residents and diplomatic staff) but evidence suggests it did, at least a few times and at least on some older platforms.

Estonia's IDs are all public using a very different scheme to Certificate Transparency, since it assumes you trust the Estonian government to decide which IDs exist - but with similar effect, if anybody is minting bogus IDs there would be a smoking gun in the official public records of Estonia.

On the other hand if the government (or a government agency perhaps without wider knowledge) has copies of some or all keys, they would be able to decrypt messages sent to citizens/ residents using the embedded PKI. We would not necessarily have any public evidence that this was happening if indeed it was happening.

You should probably be confident in Estonian IDs as proof of someone's identity in the usual course of things, but it may be prudent not to rely on this to keep secrets from the Estonian government or its allies.


> There was a scandal in Estonia where they had to recall all the ID's because the main private key which signed them all got leaked (and that key was held by a private company)

No.


Helpful comment.

https://www.reuters.com/article/estonia-gemalto-idUSL8N1WD5J...

> Estonia's Police and Border Guard Board (PPA) said in a statement Gemalto had created private key codes for individual cards, leaving the government IDs vulnerable to external cyber attack, rather than embedding it on the card's chip as promised.


It was helpful, you saw that what you wrote was technically VERY incorrect and without any proof.


It's not an issue of whether it's technically feasible do it, but whether it's feasible to do it with appropriate safeguards that protect privacy and anonymity online while authenticating in a targetted way to those end points that need it.


This. In Europe you'll find the likes of Capgemini, Accenture, Cognizant, etc. hovering like flies around government IT projects.


And they keep getting awarded contracts despite their continued poor delivery. I really don't understand how their terrible track record never seems to impact their ability to win more business. I can only assume corruption, but I have no evidence of this.


Their ability to win business is based on their expertise at writing responses to RFPs in a successful way, not in their ability to deliver. Also, they do have a few successful projects, to some standard of success, which they point to in the RFP responses as a "successful" track record. Often the ability to point to an almost perfectly analogous project and writing the responses in the "correct" way is all it takes.


This reminds me of how much universities value the ability of staff and students that can write grant applications that get awarded.


"writing responses to RFPs in a successful way" really means "successfully identifying decision-makers at top levels and brib-- 'charm' them into compliance", often even "dictating how RFPs should be written so that they will be the only ones who know exactly how to reply to them in the only acceptable way".


Prior delivery is not generally a major consideration in a govt RFP award.

This is in part because no score is ever released related to prior delivery (ie, no central assessment record), and attempts to include it get tied up in process issues (ie, rights to respond, litigation) or claims it is subjective. It also overlaps with govt agency disfunction around scope and requirements and no govt manager wants a failed project, so everyone just sweeps them under the rug and keeps moving. It is crazy though, you are literally hiring the same HORRIBLE firms over and over.

What is PARAMOUNT is that you be willing spend absolute metric tons of UNPAID time responding to RFP's, have enough money in bank to lose 4 out of 5, be willing to go through 2 year RFP processes, be willing to agree to every item on the requirements lists filled with further buzzwords and "standards". This does NOT attract high performing companies, no competent engineer would even put up with this / sit through this. So you get body shop type consulting firms, using giant java framework and other solutions, and everything is insanely siloed.

The crazy pricing is often justified because the hassle in dealing with these contracts from a contract admin overhead can absolutely DWARF actual deliverables, and nothing has to be logical (and sometimes is not).

My recommendations here would be either:

a) just pay to bring stuff in house so you get cooperation, develop open source apps and prohibit any scope creep outside of absolute minimum needed until project is in operation. EVERY freaking agency hangs 100's of new requirements they never even used before onto these projects - solutions can be undeliverable and unusable as a result, for example 40 questions PER VACINNE SHOT here in California is the height of stupidity to make these idiots feel important.

b) pay for actual use / adoption, and let there be a somewhat free market. A lot of time the users of any govt system have ZERO input. Oddly, if they let agencies find their own solutions on a smaller scale, whatever you lose in "efficiency" by not having the megaproject (hint nothing - mega projects = disaster in govt land) you would see some natural winning solutions start to bubble up. I worked with an agency with a totally fantastic contract management / invoicing system, and I kept on wondering, holy hell, they actually got it right. I started to see other agencies use it in neighboring govts - it was great - people really liked it (super easy use, allowed users to do the google, Microsoft etc login even which is unheard of) and it was fast which is also rare.

But then someone convinced the head tech folks they should stomp on everything with the new and improved people. They actually had to roll back the mega project for another year (after years of dev) because it didn't even cover a fraction of what old systems easily did.


RFPs frequently reference past activity. That’s just not accurate.

The reality is that you only hear about failed projects. When was the last time that you heard about taxes not being collected or welfare payments not being paid or SNAP cards not being refilled?

It’s all background activity, and those awful contractor companies are often responsible for material aspects of delivery.


But there is rarely a determination that past activity resulted in a failure or success. You usually just have to show that you have had contracts for past activity (and yes, have not been disbarred etc- which happens very very rarely). In many cases big is good here, lots of contracts so looks "safe".


IT services companies that work on government contracts in Switzerland are much smaller.

And they're usually pretty competent, especially the few ones that work for the federal government.


oh man i just tried to use our site: https://usajobs.gov

for every single job you have to answer 30+ questions. no getting around it. my friend who is a vet just thinks this is normal. lol


> six months

I think you may underestimate the system needed. Identity management is the tip of the iceberg: this needs to tie into any future digital currency, income taxes, property ownership, government benefits, and who knows what else. Any off-the-shelf product will need customization. I’m not saying it can’t be done.... it SHOULD be done. But not in 6 months.


>> six months

> Identity management is the tip of the iceberg: this needs to tie into any future digital currency, income taxes, property ownership, government benefits, and who knows what else.

I'll put my shoe on my head if you can find me a private company that can do this in six months. Previously on HN: CDC website built by Deloitte at a cost of $44M is abandoned due to bugs (technologyreview.com)

https://news.ycombinator.com/item?id=25975110

1167 points by donsupreme 35 days ago

664 comments


Vendors with years of time to build can't even track Cannabis properly. Human are much harder than trees to keep track of.


Indeed. Someone’s making excuses to support a privatized deployment.


Our country rolled out two certification based systems (Carta Nazionale Servizi which then got rolled into the Carta di Identità Elettronica), plus a federation based system built around SAML (Sistema Pubblico di Identità Digitale) where you can access to most italian bureoucracy.

And we're talking about Italy, not some first rated technological paradise.


Yes and now your picture, a picture of your id card, your email and telephone are in the hands of the same people who store banking passwords in plaintext..


The goal of SPID (the authentication system) is to let more citizens access to government services without going physically going to a place, and this goal is kinda working right now. During Covid, many italians asked for social welfare from their mobile phones, among other bonuses.

For how it is designed, there are a dozen companies that offer this service. The citizen can choose the one they trust more (there are some small differences between them; some require to pay a small fee; others require you to physically go to an office to be recognized; others offer you an app to login through a QR code...) BUT they are all required to implement industry-standard security. At one of my past jobs, many years ago, I had to implement this login system in a public portal. It was a mess (the technical specification was on a PDF written in bureocratic language) but shortly after a new team overtook the project and created a proper website with SDKs etc. To this day, the only known attacks to SPID were Phishing attacks, that require the user to do some dumb action on their side.


because of the certificate inside, the id card without the pin is worthless; having the identity split from authorization is an absolute win. compare and contrast with the SSN number.

also, the government already owns all my data, from birth onward. the authentication system makes it so forgery is much harder from the officials themselves, so this protects me from that as well.


Your picture, e-mail and telephone is mostly public (social media, etc), and the government would have your ID card information anyway - I don't see how this is worse?


> We're talking identity management here. Any government that can't handle that internally doesn't deserve to exist.

... I mean, as a French citizen who kind of wants my government to keep existing, I also agree with the statement you quote?

Our government's public-facing IT systems have gotten better over the last few years, but my default expectations for any new projects would still be for them to mess it up.

Of course, the problem is I'd also expect the average contractor to mess it up in very similar ways, for similar reasons.


Building a system which works for 99% of the population, 99% of the times they want to use it, sure.

That 1% though, is going to have all the weird edge cases.


> set it up in six months

There is no way it could be done in 6 months given any reasonable parameters you care to throw at it.


Seriously. I suppose Santa’s elves issue drivers licenses.


"Any government that can't handle that internally doesn't deserve to exist."

So, like the US?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: