Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • no one launch Doom yet?
  • The amount of human effort, labor, and heartache put into squabbling over where someone was born or was naturalized is absolutely mind blowing.
  • Go to South Sudan and tell me if you still feel the same way.
  • It's because generations/families are a thing. Even the countries taking the most immigrants like USA aren't expecting an immediate benefit, they're thinking 1-2 gens later.
  • I was going to respond, but when I looked in my bag of trollfeed I saw it contained fuck all.
  • Do you treat your immediate family better than an absolute stranger?

    If so, why? Aren't they all just people?

  • The native Americans tolerated immigration, and we all know what happened to them.

    On the topic of the article, every hotel outside the US I've used has asked for my passport; I didn't know that a copy of the details exposed weaknesses on the electronic side.

    by axus
  • How do you offer entitlements and quality healthcare to the entire population of the world without money?

    Who should be allowed to participate in the decision-making process that allocates these finite resources?

  • A democracy cannot function if the electorate is not well defined. They are vulnerable to Sybil attacks, same as the distributed ledgers and hash tables.
  • It is one of the core concepts of sovereignty--defining a territory and then deciding who or what gets to be inside. Along with a government with a monopoly on violence used inwards, and some foreign relations directed outwards, you have the recipe for a modern country.
    by z2
  • > The filesystem architecture is straightforward, comprising three file types: master files (MFs) serving as the root directory; dedicated files (DFs) functioning as subdirectories or applications; and elementary files (EFs) containing actual binary data.

    AFAIK, this is the exact same protocol used in all other kinds of smart cards, including credit / debit (EMV) chip cards, both standard and contactless, as well as SIM cards.

    Not sure whether public transit, employee ID and TV cards use it too, but I wouldn't be surprised.

  • I have a very practical question with big political implications: Can electronic passports be used to make large-scale elections without government involvement?

    I am thinking of authoritarian countries that issue modern e-passports but do not allow free elections. Can activists organize an election for all citizens of that country in some online form, asking the voters to scan their passports using their phones, so that

    - only legitimate citizens (who have passports) can vote - votes remain anonymous - everybody can vote only once - the whole election can be audited

  • The authoritarian govt controls who gets passports and can create fake people if it wants.
  • >Can activists organize an election for all citizens of that country in some online form, asking the voters to scan their passports using their phones, so that

    By the point said activists reach organizational capacity to do so, they have already won and can hold the vote basically with scanning a qr code with a simple app.

    >only legitimate citizens (who have passports) can vote

    this makes no sense as a requirement in a situation you described.

  • Yes, as long as the passports implement a signing scheme, and the set of valid public keys (the electorate) can be agreed upon. If you can sign arbitrary data, then you can sign other public keys, including whatever the voting system requires.

    Vitalik has a great blog post about blockchain voting.

    https://vitalik.eth.limo/general/2021/05/25/voting2.html

    You probably wouldn't want to use the cryptography on the passports themselves to implement the voting system. You probably want to use one of the general purpose zkSTARKs or multi-party-computation systems.

  • > authoritarian countries that issue modern e-passports but do not allow free elections

    You are trying to solve a political problem with a technological solution.

    1. Many authoritarian countries don't allow freedom of travel (i.e. it is not easy to get a passport)

    2. If they don't care free election, what's stopping them issuing more passport just for voting?

    3. What's stopping them confiscating or revoking your passport?

  • > authoritarian countries that issue modern e-passports but do not allow free elections

    Those tend to not issue passports (of any kind) to many citizens.

    Then there's access. In America for example only half the adults in the country even have a passport, and I suspect that skews quite heavily towards one demographic. Do you think that India, Nigeria, or Russia have more equitable access?

    And even if they did, what stops the state issuing extra fake passports to citizens they want to vote.

    of course then there's key elements of a free election, freedom of access to the ballot paper, freedom to campaign the same as others, freedom from imprisonment because you are running against the incumbent leader, having each vote being worth the same. Many countries prevent people in jail from voting, or even people who used to be in jail. Many countries give more power to one constituency than another, almost all have some level of unequal access to campaigning.

    It's not a "Free election" or "no election".

    The actual casting of the vote is only part of the story.

  • I had heard something about some sort of counter being incremented in the passport when it's read, which was meant to dissuade you from messing with it, since the next check-in at a border crossing would report this information...

    This article doesn't really give much useful information beyond what is mostly well-known.

  • i went through border control twice at an airport after going to the wrong gate and when i returned to the uk the e-gates immediately declined to process it (the camera etc. didn't move and e.g. reject the facial recognition, it just immediately said go to the desks). i've always wondered what that was about, how do they know i didn't just go to a third country?
    by 4rt
  • I never realized how much complexity goes into a passport, the cryptography, authentication layers, and others are mind blowing.

    It’s impressive that something so small carries so many trust anchors. I’m wondering how they will manage to upgrade them - for future algorithms without breaking compatibility.

  • What's even more impressive is that this technology has been around for decades!

    > I’m wondering how they will manage to upgrade them - for future algorithms without breaking compatibility.

    Just like all other smartcard systems: Very, very slowly. Credit and debit payment cards with a smartcard (EMV) chip have similar issues – even small patches take multiple years due to the relatively long average card validity.

    by lxgr
  • Passports and money are quote complex to be forgery-resistant. With internet existing it turns out, it's easier to discard the physical form altogether and only leave pure chain of trust digital form.

    It already happened to money, it is slowly happening to passports and ids too.

    > I’m wondering how they will manage to upgrade them - for future algorithms without breaking compatibility.

    The same way as always -- introduce a new version of the passport, which can as well be verified through a completely different system altogether.

  • But what kind of cryptography makes it mathematically impossible for bribed officials to issue perfecly legal and cryptographically protected fake passports, and if none, then what problem do electronic passports actually solve other than creating even more opportunities to surveil common people?
  • That's an overly cynical take. Obviously it means that a criminal organization would need to recruit officials before they could issue fake passports. Which is already pretty hard.

    And maybe they would need to recruit multiple officials across multiple agencies. And if these agencies has internal policing, then even if they manage to do that, they now have another vulnerability where the criminal operation can be discovered and sabotaged.

  • Electronic passports are about faster processing. The nerd drama is mostly irrelevant.
  • The history of passports has always been surveillance and control of movement of, and enforcing quotas on, the proles.

    In their earliest form, they were documents from your lord that permitted you to travel, and specified where you belonged and where you were allowed to travel to, most often used for internal travel. Later and in general, they were used to keep the poor from moving, for example, to find work elsewhere.

    Later Americans used them to limit European immigration based on country of origin, Europeans used them in WWII to do some not good things, Soviets used them to exile or keep undesirables where they wanted them, etc

  • 1. It's easier to centralize cryptographic cert issuance than passport issuance.

    You may allow embassy personnel to issue passports, while still requiring a computer system in the homeland to verify that the person actually exists in some government register (and that photos match) before the certificate can be issued.

    If you give embassy personnel blank passport templates, they can issue passports with completely fake identification details, for people who have never existed. The moment computers get into the mix, that may no longer be possible, or at least leave an audit trail.

    2. There's no risk of surveillance. Reading data from the chip still requires you to read the MRZ, so you can't do that remotely.

    There's nothing a chip gives you that you wouldn't get from a normal passport (beyond a very easy and hard-to-fake way to verify that the passport is authentic).

  • Cryptography is a tool that turns arbitrary problems into key management problems. It doesn't solve problems, but it constrains them in useful ways.
  • Usually some state's passports grant the holder more privileges than those issued by another state precisley because of the perceived risk of them being (not) obtained by fraud. Your genuine Sealand passport is less practically useful than a genuine Finnish one for use in the context of international travel.

    The cryptography aspect is basically preventing the corrupt Sealand government official from stamping out ones that might be confused for, for example, a Finnish one.

    Sealand[1] being used as an example least likely to cause offense - but you can understand that most governments around the world really do want to ensure that they are the only ones issuing their passports, and hence what that means for their citizens.

    [1] https://en.wikipedia.org/wiki/Principality_of_Sealand

  • For one thing, with printed passports border officials have to recognise all the anti-fraud features on all the passports issued worldwide in the past 10 years.

    Quick, what security image on a valid UK passport - a thistle, a daffodil, a rose, a clover, a coat of arms (but not the same coat of arms as on the front cover), a map of the UK, a harlequin pattern, a crown, a lighthouse, a pair of bird wings, William Shakespeare, an oak leaf, a compass, a marine chronometer, the letters UK, the words United Kingdom, a Bermuda-rigged boat, a square-rigged boat, a steamship, or the holder's birth date?

    It's a trick question, you'll find all of them; they changed the passport once for brexit, and again after the queen's death. And that's just one document from one country. Far simpler to just hold it to the reader and get a beep.

    For another thing, if you're worried about bribed officials - it's much harder to bribe airport border officials if they're required to scan every passport into a computer, and match it against the airline's passenger list.