Skip to content

Comment on EU Digital Identity Reform: The Good, Bad and Ugly in the EIDAS Regulation

Comments

I’ve been using one of these id wallets since a few years (itsme) and it’s been a huge quality of life improvement. I don’t have to create accounts, passwords, etc; I just login to the websites, it’s like a global single sign on.

While the fact that it’s done under my verified real name and address could be a privacy issue in some cases, it’s also a big security improvement for all the cases where the third party need that info anyway.

it’s also a big security improvement for all the cases where the third party need that info anyway

Security there (in the cases I am guessing) is determined not by Alice being able to prove that she is Alice, but by Trudy not having secondary ways allowing her to claim that she is Alice.

So, it would be «a big security improvement» only when login were restricted to needing a certificate.

Indeed, but if the majority of users uses the wallet, then business can now afford to do stricter identity verification for the users that don't.

third party need that info anyway.

See, a noteworthy news in the Epicenter.Works' take was that Big Tech is also required to implement the thing. They do not "need" to know anything, but I am sure they're quite trilled about this requirement.

It is illegal in the EU to ask for unnecessary personal information and the wallet app can authenticate you without giving your name and address. So I don’t think it’s as bad as it’s made out to be

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.