Inside NZ's Digital Identity Stack (And How Do You Even Test This Thing?)
by Nick von Dadelszen | - 5:00pm
Digital Identity is taking off worldwide with multiple implementations completed and in progress, including Digital Driver Licences, Digital Passports, the EU Digital Identity project, and many more. New Zealand is working on its own Digital Identity projects and legislation has now been passed that enables digital credentials for use in transport law and sale and supply of alcohol. The first credentials are due to go live shortly, and will likely be in people’s hands by the time I give this talk.
The technology is new, the standards behind it are still evolving, and there are significant security implications. This talk covers where the technology sits in New Zealand, how that compares internationally, and what you need to know about it as security people.
One thing I ran into is that nobody has built any security testing tooling for this yet, so I’ve had to write my own from scratch. This talk is about the standards and my methodology, not about any particular implementation I have worked on.
Some of the topics to be covered include:
- The Digital Identity ecosystem being implemented in New Zealand, and how it compares internationally
- How Digital Identity improves security, including selective disclosure and cryptographic issuer authentication, and not having to hand your full licence or a photocopy of your passport to a stranger
- Protocol privacy issues like linkability, issuer visibility and status list leakage. Some of this is mitigated in the standards, some of it just gets moved somewhere else, and some of it is still open
- Hardware attestation and device requirements, and what happens if your phone doesn’t qualify
- Attacks against the protocols as specified, and what the standards do about them
- Test tooling limitations and how I approached them. I’ll show what I built, and expect to put some of the simpler pieces out for people to play with
Hopefully by the end of the talk you’ll have a decent understanding of why Digital Identity is important and where it’s going. I will also hopefully have removed some of the tinfoil hats from the room, or at least shrunk them. The tech is new and interesting and directly relevant to everyone in the room, as it’s likely you or someone close to you will be using it in the very near future.
About Nick von Dadelszen
Nick is now an oldie in the security industry, having started his penetration testing career in the late 90s. After managing several security teams, he co-founded Lateral Security in 2008 and ran that for 15 years. Since leaving Lateral a couple of years ago, Nick now spends his time as a security contractor taking on projects that interest him, and spends his spare time doing other research. Nick has spent the last year in the bowels of Digital Identity and AI.