usnistgov / 800-63-3

Home to public development of NIST Special Publication 800-63-3: Digital Authentication Guidelines
https://pages.nist.gov/800-63-3/
Other
701 stars 102 forks source link

Proofing Issues #1912

Open paul-grassi opened 6 years ago

paul-grassi commented 6 years ago

Effectively have kept valid KBV out of IAl2, which is not what we intended, at least when it comes to financial validation. Need to look into this.

In addition, verification requirements are silent on backend database template or picture on evidence. I think we want more credit for backend vs just the license since that is easier to forge.

RGalluzzo commented 6 years ago

Two thoughts here:

  1. To get KBV in at IAL2 you could create an option for agencies to only require 1 piece of "fair" evidence and 1 piece of "strong" so long as both are verified appropriately. So instead of requiring two fair and one strong where only the strong is being verified, you could open it up so that, for example, you could have someone achieve the same level with financial evidence that has been validated and verified through micro deposit, plus a driver's license that has been validated and had the image verified.

  2. For extra credit, would it be too much of a stretch to consider the back-end check as "superior" verification? Selfie to picture = physical comparison; Selfie to DMV template = biometric?