ShareID wants to verify your ID without storing personal data

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
A new startup from France is entering the market with a solution that, in theory, should protect people’s privacy.

ShareID spokesperson Eliana Daboul described the company in an email as “an Authentication-as-a-Service solution tied to government-issued IDs.”

The twist is that, unlike other similar companies, ShareID claims it doesn’t store any personal data. Instead, according to ShareID’s CEO Sara Sebti, the company asks users to submit a video to prove their “liveness” — a fancy word that means the user has to prove they are a real person in front of their phone’s camera and it’s not a pre-recorded video — and a picture of their government ID. But ShareID says it doesn’t store this data, it keeps it in memory on its servers and creates a hash — a unique ID — and then wipes the data, which effectively was never stored on the servers.

Other companies use a different approach.
[...]
ShareID, on the other hand, wants to retain as little information as possible, and for as short a time as possible.

“We issue reusable identities to our users, we get rid of all the personal data that we captured. We only generate this homomorphic hash and we use it to re-authenticate the person when they come back,” Sebti told TechCrunch, referring to an encryption technique that allows the creation of a unique value from a set of data, and makes it impossible to reverse it to get the original data.

In practice, Sebti explained, ShareID customers have access to an SDK and an API that allows them to embed the company’s technology on their website, as well as their Android or iOS app. Sebti said that the person who is trying to authenticate will have to submit a video showing the front of the document for three seconds, and the back of the document for another three seconds. Then, the website or app will capture a video of the person’s face, asking it to fulfill challenges to prove they are really recording it live, such as smiling, tilting their face to the left or right, and following a point on the screen, whose position is randomly generated.

“You have a random point that is run on your screen and you have to follow it with your eyes, and you have no clue where it will be. So you cannot prepare the video to get into it,” Sebti said.

At that point the service processes this data and creates a homomorphic hash that can be used to re-authenticate the user when they come back.

At least, that’s what ShareID claims. Sebti said France’s military police audited the company’s security, and that they monitor their own security by running penetration tests, or pentests, and “other live security monitorings.”

 
F

ForgottenSeer 103564

[...]


That's cool except, what happens when the information is intercepted in real time and still used for identity theft on other platforms. The safest way to navigate the net is to not use real identification, much like users do in this forum.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top