logoalt Hacker News

fc417fc802yesterday at 11:29 AM1 replyview on HN

If you can't implement it securely then perhaps such an undertaking wasn't a good idea? In the vast majority of cases I don't see why PII ever needs to be available over the network for remote queries. For the purpose of verification isn't it sufficient to verify hashes or better yet to attest via smartcard?


Replies

dijityesterday at 11:31 AM

You can, they didn't; big difference.

show 1 reply