DenRaf's Blog

  • Contact

Contact
View Raf Nijskens's profile on LinkedIn
OpenSource
Linux
Powered by Drupal, an open source content management system
Get Firefox
Fosdem
Visit Inuits Technical home

Locations of visitors to this page

Tags in TagCloud

5 6 ADP1 Android apache automaticmenu caching cardreader cats Centos closed source cron Debian dell Dell R200 deploy Dream driver drupal drupalcron eclair Fosdem funambol mysql node_page O2Micro old openfire OpenID OSD otrs password trigger password_trigger plutado Ports presentation recover response header rpm script svn sync syncml tagadelic taxonomy terminal logging theme ubuntu update upgrade user filter user_import virt-manager wordpress wordpress 2.3 wp2drupal xmlsitemap zabbix zimbra Zimbra LDAP
more tags
Home ยป Some thoughts about eID

Reply to comment

Some thoughts about eID

Submitted by DenRaf on Tue, 02/05/2008 - 21:22
  • [View]

It's been a year since the first implementations around eID started showing up. Yeah indeed, just before FOSDEM or maybe that's just coincidence, but my thoughts are still the same.

I think, and I'm not alone in this case, there is a security flaw. And not just one that's quickly solvable, but a flaw in design. The thing is, you get your card with a private key and you just don't know who else has your key. Ain't it the goal of keys, that you create a private key and you distribute your public key?

And now some other really nice thing about it. It's not writable. Of course not you say, but listen up.

Say, you move to an other place. Wouldn't it be nice, to just be able to change that? I can understand you need to go to the city hall of your new place, and prove you come to live there, but that it is at least a quick write over. But no, it's not. You need to go back home, cause they have to order a new eID for you. After 2 weeks, you get your new card, with your new address, but also with a new private/public key pair. Now you can warn all your friends, who have signed your key, you have a new one, again.

So, instead of using an eID, use a smart-card with your own keys, this way you at least can control them.

  • DenRaf's blog
  • Add new comment
Tags:
  • Uncategorized
  • eID

Reply

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Guided search

Click a term to initiate a search.

Categories

  • drupal (26)
  • Linux (6)
  • SysAdmin (6)
  • Uncategorized (5)
  • Linux-tools (3)

Date authored

  • 2010 (5)
  • 2009 (10)
  • 2008 (27)
  • 2007 (11)

TagCloud

  • drupal (26)
  • Ports (7)
  • cron (6)
  • drupalcron (6)
  • 6 (3)
  • OSD (3)
  • zimbra (3)
  • cats (2)
  • Fosdem (2)
  • funambol (2)
  • more...

Recent blog posts

  • OSD2010: Day 2
  • OSD2010: Day 1
  • OSD2010: Pre notes
  • Howto: Android 2.1 on G1/ADP1/Dream
  • Updated look
  • Zimbra monitoring with zabbix
  • New module: Node Page Template
  • AutomaticMenu module for drupal 6
  • Drupal synchronisation
  • Imagefield_gallery module for drupal 6
more

Recent comments

  • Please help me
    3 weeks 4 days ago
  • This is so dumb
    4 weeks 3 days ago
  • I've installed it on my
    7 weeks 2 days ago
  • I am also having the same
    9 weeks 1 day ago
  • No Video
    9 weeks 5 days ago
  • Good, just finished the
    10 weeks 6 days ago
  • Screenshot Item Trigger
    11 weeks 1 day ago
  • You don't need 2 because
    16 weeks 14 hours ago
  • Oracle plugin
    16 weeks 2 days ago
  • Thanks much for providing
    16 weeks 4 days ago

Syndicate

Syndicate content
I love Smashing Magazine!
Fervens Drupal theme by Leow Kah Thong. Designed by Design Disease and brought to you by Smashing Magazine.