In my (European) country now we can have a digital copy of the driving license on the phone. It specifically says that it’s valid to be presented to law enforcement officers during a check.

I saw amazed in the beginning. They went from limited beta testing to full scale nationwide launch in just two months. Unbelievable. And I even thought “wow this is so convenient I won’t need to take the wallet with me anymore”. I installed the government app and signed up with my government id and I got my digital driving license.

Then yesterday I got stopped by a random roadblock check and police asked me my id card. I was eager to immediately try the new app and show them the digital version, but then because music was playing via Bluetooth and I didn’t want to pause it, i just gave the real one.

They took it and went back to their patrol for a full five minutes while they were doing background checks on me.

That means if I used the digital version, they would had unlimited access to all my digital life. Photos, emails, chats, from decades ago.

What are you are going to do, you expect that they just scan the qr code on the window, but they take the phone from your hand. Are you going to complain raising doubts? Or even say “wait I pin the app with a lock so you can’t see the content?”

“I have nothing to hide” but surely when searching for some keywords something is going to pop-up. Maybe you did some ironic statement and now they want to know more about that.

And this is a godsend for the secret services. They no longer need to buy zero day exploits for infecting their targets, they can just cosplay as a patrol and have the victim hand the unlocked phone, for easy malware installation

Immediately uninstalled the government app, went back to traditional documents.

2 points
*

This is the biggest issue I have with them. The only way this will work in modern society where the police can’t be trusted, is if the ID is accessible while the rest of the device is locked down.

And that’s really only possible if Apple and Google integrate that directly into the OS.

permalink
report
reply
4 points
*

It is.

Apple has “guided access”, android has “pin app”.

I only have experience with the latter, it works by opening the task management view, and selecting “pin application” on a running app.

That then locks the device to that app. To access anything else, it has to be unlocked as if the screen were locked.

permalink
report
parent
reply
2 points

App Pinning DOES NOT lockdown the device, even if you have it set to require a PIN to unpin, biometrics still work to unlock the device.

It also gives you a warning that personal data may still be accessible and the pinned app can open other apps. It specifically says “Only use app pinning with people you trust”… which is the exact opposite of the use case here. And app pinning is turned off by default, you have go go searching in the settings to enable the ability.

permalink
report
parent
reply
3 points

Was definitely on by default on my device.

Personal data is still accessible, if the app you choose to pin is something like the dialer, or your mail app, then yes, you can obviously access contacts and emails. The feature doesn’t block the pinned app from accessing everything it normally accesses.

As for opening other apps, this applies to stuff like links or launchers. If the app has links somewhere, you could open your default browser app. It does not allow you to “escape” the pinned app to anywhere else in the system, unless the pinned app has a way to launch other apps the way launchers do.

The feature could certainly use improvement, but if it were only useful with people you trust, it would be pointless.

It’s obviously intended for situations where you have to let someone use your phone, and don’t want to give them free reign. With people you trust, you wouldn’t need something like that.

It’s far better than nothing, and is in fact part of android.

permalink
report
parent
reply
54 points
*

They went as far here in Ukraine as making some services exclusive to those who have the app. The official government app for digital documents and services, Diia, also has stupid integrity check, which makes it unable to be installed from Aurora Store, which makes me cut out from such services, because I don’t have Google Services installed. By the way, there are Google trackers in the app.

permalink
report
reply
2 points

The IRS (tax authority) in the US has Google trackers loaded into the DOM including pages listing your Social Security number too, yikes.

permalink
report
parent
reply
1 point

Don’t get me wrong, it’s great that you figured this out. But why did you not consider this sooner? Wouldn’t it have been obvious that you would have to have the phone unlocked and that having a police person have any access to an unlocked device would be a real problem?

permalink
report
reply

What’s obvious to you may not be obvious to other people?

Likewise, what’s obvious to you at one moment may not be obvious to you at another, simply because you’re thinking about the situation from a different angle.

permalink
report
parent
reply
7 points
*

To add to this, a lot of what keeps us safe is the friction of bureaucracy. Authoritarians cannot micromanage every decision you make or round up every person they want because those actions take time and resources that aren’t infinite. But you can reduce the time and resources required if you make identification more convenient and therefore enforcement more targeted. Maybe now they can justify making you present ID every time you pay cash at Starbucks, buy a backpack, get on a bus, use a bike share, watch hot snuff porn, you name it.

permalink
report
reply
3 points

Every country in Europe that has vastly better privacy laws than the US, also already has national ID since forever.

Now they even became electronic biometric IDs, and I still don’t need to show it whenever I buy a loaf of bread.

Even if, why would anyone ever want to bother when they could just track your payment cards?

permalink
report
parent
reply
31 points

On iOS you can enable Guided Access and restrict what one can do, for example disable touch and lock it to an app, until you enter a Code. I imagine Android will have something similar.

This obviously doesn’t protect against electronic forensics, but it does protect against just opening different apps and searching through the phone manually.

permalink
report
reply
15 points

Yes, Android has app pinning. But they still have access to anything the app gives them.

They can see my ID on the phone. But if they want to take it, then no, I don’t have that ID on me. But then, I live in the US where digital ID isn’t valid.

permalink
report
parent
reply
13 points

It is valid in some states. OP raises an excellent point. I live in the U.S. and have the digital ID on my phone, but I won’t be handling it to law enforcement. I’ll make sure I have the physical copy when I’m driving.

permalink
report
parent
reply
2 points

You can block off certain sections of the screen, or disable touch completely. If all the info they need is on the screen just make it so they can’t tap anything.

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 5.5K

    Monthly active users

  • 1.8K

    Posts

  • 27K

    Comments