logoalt Hacker News

lxgrtoday at 11:27 AM2 repliesview on HN

How would you use a paper ID online? (Securely, i.e. not the insane thing of taking a selfie holding it or something similarly bizarre in an age of powerful GenAI.)


Replies

simongraytoday at 11:32 AM

NemID, the previous national 2-factor solution, used a small card with rows of pre-printed single-use codes. When you logged in to a bank or a public sector website, it would ask for a random code at a specific row and column number. Once the system registered that you had just a handful of codes left, a new card would be sent to you via snailmail. It worked fine for the time.

The current system, MitID, depends on smartphones, though you can get an an external key generator as a backup too.

show 2 replies
LeonidasXIVtoday at 11:37 AM

The way it worked before was that you had basically a piece of paper with OTP codes and the website would prompt you for a very specific one.

How that would've prevented this issue: not at all. If the login service is down, having the piece of paper with OTP codes is worthless as the problem is not getting the codes (I can still get MitID codes with the OTP dongle) but the authentication website. The previous system was just as centralized.