Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In EU (Italy) there is eIDAS (SPID) that could allow this. It is essentially a national SSO.

Today it requires almost always a Android/iOS phone AFAIK, but it could easily be massaged to solve this problem.

The system is set up so that your account is owned by the state, and you can register with documents to providers; then after certification they run the actual SSO process.

A library provider could set up a computer that automatically passes the SSO login for your national account after certificating your identity.

Honestly this feels a bit too open to social engineering attacks, but probably there is a good middle ground.

Edit: Maybe in the US this is already almost possible by extending something like https://en.m.wikipedia.org/wiki/FIPS_201



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: