Skip to content

Comment on Estonia blocks electronic ID cards over identity-theft riskparent

Comments

You can request your service to be whitelisted: https://www.sk.ee/en/services/validity-confirmation-services...

Pricing is here: https://www.sk.ee/en/services/pricelist/certificate-validati...

So it's not quite as simple as Google or Facebook oAuth. But the government does support the idea that if you want then add this as a login option to your forum for dogs or an e-store for sweaters.

The main value is still in the fact that the authentication gives you the ability to create legally binding contracts that get signed online.

To be precise: the system offers both identification and authentication (by using two different certificates, with two different pin codes.)

Even if you don't sign-up and whitelist your service you can sign documents or verify other people documents signatures (both online or with a desktop client). There are usage quotas, though.

This is paying for revoke checking, right?

Validating the certificate the same way servers validate client certificates should be enough to verify it as a date/time-valid Estonian ID.

Yes, this is to use OCSP. You do not have to pay if you download revocation lists manually. Ofcourse lists become stale rather quickly.

Very basic - hello world level - implementation is as simple as enabling client certificate authentication in Apache config.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.