Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is not a problem with GDPR. This is a problem with organizations (companies and governments) treating publicly data as private keys.


Not private keys, secret keys. "A Secret is something you tell one other person [So I'm telling you]".

But yes, that's exactly the problem, the Credit Reference Agencies actually sell this as a service. They think it's a big improvement, and if they're right that ought to be terrifying - what was being done before this crap? "Nothing" is likely to be the depressing answer.

"Hey, we can tell if this is really Dave Smith, because we'll ask "How much did you spend on your credit card in May?" and the real Dave knows the answer, and so do we. Well yes, and so does anybody who saw Dave's card statement, and people at Dave's bank, and the card company, and... also when Dave answers $849.28 that won't match and gets a bad user experience. Oh you mean the _other_ credit card. Yeah, Dave only spent $30.26 on that, he mostly uses it to buy fuel for his jet ski... So you try to solve this "How much did you spent on the VISA ending 4282 in May?" now you've given away a useful fact to an adversary. Idiots.


Moreover, it's a problem with the current state of "identity" as a whole. Most of the data received in the article - passports, addresses, phone numbers, credit cards - does not change very often. Some documents expire, but even then it could be valid for another 3 - 10 years.

We need to move to a system that allows rapid expiry of PII data. Then it will not matter if someone is able to social engineer this data from all these companies. By the time the data leaves the companies HQ, it is already out of date and therefore impossible to use with new services.


I had a thought awhile back. In the vast majority of uses, identity is exactly the issue. Yet in the vast majority of compromises or problems, the problem is correlation and combination of data. By this I mean it seems to me that, say, the Social Security Administration needs to be able to identify a citizen in order to know whether and how much they need to pay a person of a certain identity to avoid paying the wrong amount, the wrong person, double-paying, etc. There does not need to exist an identity which spreads beyond that. Your credit card company does not need to use the same identity and a unique identity which functions solely within the context of the credit card account is all that is needed. Instead, we have identities that get spread across multiple services even though there is never any actual need to relate or correlate the activity across those services. This seems like the sort of situation that cryptography can solve, although obviously there would be a lot of usability work to be done. But it seems to me that cryptographically unrelatable distinct identities which has only 1 possible point of aggregation (you) is what is needed.


I've heard that in Japan, stamping with your personal stamp is accepted (and perhaps sometimes even required?). They have made electronic gadgets that store their stamps as images so that they can directly sign (stamp) an electronic document (using a specific input device).

I think we should have something like this, but with a personal certificate instead of an image. Of course I guess it requires some logistics (lost/stolen stamps, expiration dates, perhaps the stamp should be activated with fingerprints...).


Isn’t this equivalent to stamping PDFs with your signature like we do elsewhere ?

Also the stamp has to be registered to have legal value, which makes it tough to change.

But your idea of signing with the result of some personal certificate is very nice. It can be checked by crypto, different everytime, and wouldn’t matter how it is signed, if it’s easy to reproduce the content etc..


> Also the stamp has to be registered to have legal value, which makes it tough to change.

This is not actually true. Some stamps need to be registered (for example the stamp for corporation), but personal stamps for most applications don't need to be registered -- even for bank accounts. I have several and I'm always forgetting which one I used for my different bank accounts :-P.

One of the strange things about Japanese stamps is that if you let someone have your stamp, then it is considered that you have given them permission to do whatever they want with that stamp. The very fact that they have the stamp means that they are authorised. I got very angry at my previous employer (the government, no less) when my contract was over. They demanded that I give them my stamp I had used for stamping my time card. It happened to be the one I used for my bank account too (because I was clueless at the time!) It took me a couple of months to work around that. If you are ever working in Japan, treat your hanko (stamps) exactly the same way you would treat your encryption keys: use a different one for each application if possible.


As far as I know the registering part is mandatory for legal use but lets the accepting party decide to check it or not.

For instance as you point out for banks you can open an account without any check (you’re giving them money) but you won’t get a mortgage without proof of registration (they’re taking the risk)

At a previous company my boss had his company stamp (a shachihata) in a drawer for us to use when he’s not there. It’s interesting because by the rule of law we would be the one in fault for using someone’s stamp, so it better be for stuff he approved verbally or other ways.


Too bad anyone can access your stamp if you simply lose it. When I first saw the stamp thing for myself, I couldn't fathom how anyone would consider that secure. Better than a signature? Maybe. But easily reproducible and too tangible to consider safe.


See the examples below in discussion with personal certificates and signing keys embedded in gov't ID chipcards of certain European countries, Estonia has this for more than a decade already and now many more countries have something like this.


If GDPR created new vectors of attack which didn't exist before - there's a problem with GDPR even if there are also problems with organizations. Otherwise, you have just created a perfect excuse for any lawmaker: "my law written with good intentions, so not my problem if there are unintended consequences".


Uhm, the corporations handing out private data to the wrong person, are definitely violating the GDPR or probably some earlier privacy law, because you also weren't supposed to give out people's personal data like that before the GDPR either.


The only shocking thing to me is this is the first time I’ve seen any story about this hole in the GDPR. This was one of the top reasons we blocked and deleted all EU users. How do I verify that a request is legitimately from a user, short of them arriving in person and providing some biometrics, which presumably we would need to collect from them in the beginning?

I have no idea. Any system with a high false negative rate is breaking the law, and one with a high false positive rate seems even worse.


That is true. But it is the current state of the world and GDPR enables people to more effectively weaponize that.


How is that not a problem with GDPR? They passed a law which relies on technology which does not exist. There is no way to safely and reliably identify an individual electronically.


Unless you live in Estonia, where each citizen has a private key (on a smart card) and can electronically sign things to prove identity.

Governments could work with big tech players to confirm that certain Gmail/Facebook accounts are linked to one, and only one, national identity. Then through OAuth, you could use that to login anywhere else, proving you are a real person with exactly one ID (which needen't be revealed, just confirming you have exactly one account)


Too bad the rest of the EU doesn't live in Estonia, it would have made GDPR much better.


In my country (Oz) we had a referendum a few decades back about a national ID card, which failed to pass. I for one am against any form of centralised ID system. The basic premise (of the time) was, "if you want to know me, here I am". The government department of Birth, Deaths and Marriages goes to some lengths to ensure that these 3 things are not tied to any one number. Ironically, the government got what it wanted when it introduced a Tax File Number and has bled into some other systems like banking, but thankfully it's not as bad as the U.S's SSN.

I seem to recall reading here on HN a few weeks back how surnames came into existence: it was because the (? Italian) government wanted to track taxes. Before that everyone had several ways of naming themselves: John, John son of Joe, John of someplace, John the carpenter, etc. Personally, I really like that because I'm not just "one thing", but am a person who has different aspects.


You reap what you sow unfortunately. The fact is that the government still keeps track of you but you just have a boatload of downsides by not having a proper system citizens can use.


Any centralized identity system solves a problem we don't have. It doesn't simply serve to identify a person. It serves to aggregate an identity and tie together extremely disparate and unrelated data. It enables a data leak or abuse to not just compromise one service, but all of them at once. If there is a leak of data from, say, a dating site that involves dumping the public keys of the users alongside the user activity associated with it, then the credit card company and electric company and water company and the gaming forum you signed up for and multitudes of other utterly unrelated organizations now have the ability to correlate your dating activity with your activity on their service. The identities on all of those separate systems being the same identity is the problem a centralized system solves. And it's a problem we have never had.


> Any centralized identity system solves a problem we don't have.

You already have one, SSN and similar absolutely count and allow aggregate different data. Not to mention that you're absolutely forgetting about the fact that humans don't have a lot of entropy, k-anonymous data is not what we have by-default. You are wrong about a centralized system "providing a way to aggregate data" it just makes it easier. I live in a country that actually gives citizens access to a centralized identity system and I'd say it has solved much more than you're giving credit for.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: