* Posts by Cappendell

1 publicly visible post • joined 28 Jan 2008

IPS leak suggests ID card fingerprint chop

Cappendell

@Why a card

I am aware that this point has already, at least partially, been made, but, a card/document based system is infinitely preferable to a central database because it is much harder to abuse.

Anyone discovering a way of manipulating/abusing a central database, or being in a position to manipulate/abuse it, can cause far more damage for far less effort than someone able to create counterfeit cards.

Experience here in Germany has shown that, with a little personnel training, only a vanishingly small percentage of counterfeit ID Cards cannot be identified as counterfeit.

Public Key Cryptography does allow the "Signing" of digital documents in such a way that it can be verified that the signing party was in fact the government and this requires no direct "online" access.

I do not think that ID Systems are useless, indeed having a reliable way of identifying people for important transactions is very useful indeed, for all parties in a transaction. What is needed is a decentralized system that allows no third party to track what is being done - as would be the case with a central database.

I agree that it is very silly indeed to have two systems that should prove identity - a single system is really the only way to go.

A decentralized card based system, with no central database, where biometric data, cryptographically signed at time of issue as correct, is only available on the card, would be the way to go, in my opinion.

As not all transactions require the biometric data, and humans can't read the data without an electronic reader anyway, I would plead for a document that is as difficult to forge physically as it is electronically.