Apache Struts Statement on Equifax Security Breach
Apache Struts Statement on Equifax Security Breach
Posted Sep 13, 2017 14:26 UTC (Wed) by nybble41 (subscriber, #55106)In reply to: Apache Struts Statement on Equifax Security Breach by ssmith32
Parent article: Apache Struts Statement on Equifax Security Breach
In this case you don't need secure key distribution. You aren't actually trying to associate a particular public key with a real-world identity. You just need to show that the person applying for this loan is the same person who has a history of on-time payments on previous loans, utility bills, etc. The key itself is all the identity you need. When you first start out you just generate a fresh key and are treated as someone with no prior credit history; perhaps others with established credit who trust you (or institutions which know your real-life identity and are willing to back you) co-sign your key to give you a head start. Over time you build up a history of payments associated with your key. When you need a loan you sign the application with your private key to prove to the lender that the person submitting the application has an established credit history.
