论文标题
免疫护照和W3C分散标识符的批评
A Critique of Immunity Passports and W3C Decentralized Identifiers
论文作者
论文摘要
由于广泛的共同证明了19日大流行,因此一直在推动“免疫护照”甚至技术建议。尽管有关免疫护照的医学和道德问题的辩论已经普遍存在,但对免疫护照计划的技术基础的检查较少。这些方案被设想用于共享COVID-19测试和疫苗接种结果。最突出的免疫力护照计划涉及一系列鲜为人知的标准,例如分散的标识符(DIDS)和可验证的凭据(VC)(W3C)。我们的分析表明,这组技术身份标准基于具有重大安全性和隐私问题的未指定且通常是非标准化的文件,部分原因是对区块链技术的可疑使用。关于免疫护照的一项具体提议甚至容易受到字典攻击的影响。在标准化中应劝阻“密码剧院”在诸如免疫护照之类的努力中使用“加密护照”来减轻用户的隐私问题。在诸如免疫护照等用例中的“自我主张身份”的这些W3C标准的部署也可能导致危险形式的身份极权主义。
Due to the widespread COVID-19 pandemic, there has been a push for `immunity passports' and even technical proposals. Although the debate about the medical and ethical problems of immunity passports has been widespread, there has been less inspection of the technical foundations of immunity passport schemes. These schemes are envisaged to be used for sharing COVID-19 test and vaccination results in general. The most prominent immunity passport schemes have involved a stack of little-known standards, such as Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) from the World Wide Web Consortium (W3C). Our analysis shows that this group of technical identity standards are based on under-specified and often non-standardized documents that have substantial security and privacy issues, due in part to the questionable use of blockchain technology. One concrete proposal for immunity passports is even susceptible to dictionary attacks. The use of `cryptography theater' in efforts like immunity passports, where cryptography is used to allay the privacy concerns of users, should be discouraged in standardization. Deployment of these W3C standards for `self-sovereign identity' in use-cases like immunity passports could just as well lead to a dangerous form identity totalitarianism.