Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×

Comment Re:cryptobracelet (Score 2) 116

We'll see.

It's absolutely wrong that I am proposing a 'stealable' ID. No, it's not that at all. Like NFC (ApplePay and others) you don't send out your ID, your bracelet will engage in a two-way conversation that uses generates unique identifiers every time that prove that it's you without giving the system communicating with you the ability to impersonate you. It's not hard at all; we should have been doing this years ago. This is described in Bruce Schneier's Applied Cryptography twenty-fucking-years ago. Chapter 21(Identification Schemes) describes "zero-knowledge proof of identity". Curiously, researchers Feige, Fiat, and Shamir submitted a patent application in 1986 for this, but the Patent Office responded "the disclosure or publication of the subject matter ... would be detrimental to the national security..." The authors were ordered to notify all Americans to whom the research had been disclosed that unauthorized disclosure could lead to two years' imprisonment, a $10,000 fine, or both. Somewhat hilarious, as the work was all done at Weizmann Institute in Israel.

That said, I do think that groups like the NSA and FBI have been quite successful in keeping people (like Jeff4747) remarkably uneducated. Banks, credit card companies, and groups like Google that make gigabucks tracking people have held back from doing things right as well -- and they're paying for it today.

To say again. It is easy to build a system that would securely verify that you have authority to do something, without giving the ability for somebody else to impersonate you. It's somewhat more challenging than printing number in plastic on a credit card, but only a tiny bit more challenging.

This will happen. Once it does people will wonder why it took so long.

Comment Re:cryptobracelet (Score 1) 116

The problem with phones is that you can lose them or break them or have them stolen. I agree that it's a good place to start, though.

I believe that the RFID tag that Coren22 suggests don't have, and can't have, the processing power required to do this right. You don't want to say "Yes, I'm 132132123123", that would be *way* too easy to fake. You want to have a back-and-forth communication that shows that you are who you are, without giving away your ID.

I think the bracelet would become a status symbol -- the status being "yeah, I care about security." I'm actually not kidding.

Comment cryptobracelet (Score 1) 116

At some point, and my guess is pretty darn soon, reasonable people are going to have a very secure cryptobracelet that they never take off, or if you take it off it will never work again.

The bracelet would work like the NFC chip in current phones, it would create unique identifiers for each transaction, so you can be verified that you are who you are without ever broadcasting your identity.

Then, all email and every other communication can easily be encrypted, securely, and without adding complication. You won't have to worry about remembering a hundred passwords, or about what happens when the store you bought things from is hacked, or that a library of 100 millions passwords will find yours.

I grant that some will protest that this is not natural (I don't want to wear something on my wrist!) but people do a hundred other unnatural things every day (brush their teeth, use deodorant, wear glasses, live longer than fifty years...) The benefits will be enormous, the changes minimal, and this will be led, I believe, by thought leaders.

Comment Re:If you don't control it it's compromised. (Score 1) 86

Even a simulation of the inputs won't prevent all cheating. What if someone has an x-ray hack in place, and maybe even a bot attached that can play a perfect game? The best solution is to just not give a crap and not have online leaderboards or IAP so the only people affected by the hacking are the hackers themselves.

PvP is a problem though. There's not a lot you can do to prevent some forms of cheating in PvP, but on the mobile space PvP isn't nearly as important anyway. Usually it boils down to "user A submits an army list to the server, user B submits an army list to the server, the server simulates a battle, and then returns the results to both players". As long as your game isn't structured like a CCG with overpowered "rare" units that are supposed to be balanced by being difficult to get (or requiring real money) then it's not so bad. The cheater can submit an optimal army without having to grind, but otherwise they aren't ruining the game for other people too much.

Comment Re:Lets encrypt (Score 2) 104

I always find it amazing that these huge companies with enormous public domains don't have a person who's job description includes managing all of their certs and making sure they don't expire. You could even assign the job to two people just to make sure one of them doesn't get sick or something and miss one.

Comment Next step -- VMT (Score 3, Insightful) 114

The problem with license plate readers is that there are only so many cameras out there. How can they know where everybody was all the time?

The answer is the Vehicles Miles Traveled tax. Many states and the federal gov't have proposed over and over that all cars have GPS trackers in them that tax them on how many miles they drive. They say "the problem is cars are more efficient, so we don't make as much money." (Can't you just raise the rate then? wtf?) or that this is "more fair", everybody is charged the same amount for how far they drive; as opposed to how much gas they use and how much carbon they emit.

But, come on, the real reason is almost certainly to track where everybody went, all the time. If there is anything the Snowden revelations have demonstrated, it's that if there is any possible way to capture data on people, the government is going to do it. Anything you can imagine, and many things that you could never have imagined, are being done. If you want to believe that a GPS tracker that hooks up to a gas pump only sends one bit of information, well, I suppose you deserve what you get.

Comment Re:Governments way to admit that bitcoins are... (Score 1) 144

They were caught because the investigator was on a $150,000/year salary with a homemaker wife and deposited $750,000 in his bank account one year. Then logs from DPR's laptop confirmed it was him. Basically, he was totally and completely brazen about stealing the bitcoins both from DPR and from the government.

Comment Re:OSX (Score 1) 196

If that was installed by default and reasonably discoverable I wouldn't complain nearly as much about this, but your average person has virtually no chance of just discovering this without some deep Googling.

Slashdot Top Deals

If all else fails, lower your standards.

Working...