logoalt Hacker News

tuwtuwtuwtuw • today at 10:56 AM • 3 replies • view on HN

There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.


Replies

nylonstrung • today at 11:23 AM

Personal numbers and social security numbers in US are horrible idea, essentially a password and username simultaneously

olau • today at 11:04 AM

Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.

I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.

➕ show 1 reply
Symbiote • today at 1:18 PM

Authentication in Denmark also uses cryptographic signatures etc.

The CPR alone is used for casual identification.