Nice writeup. As a belgian, I do not think I know anyone or any apllication that uses you eID pin. I know you have to create one at the municipality when you collect your id card, but I doubt anyone would ever remember it. ItsMe has universally replaced all scenarios that would have needed an eID with pin, and booting the ItsMe account, while I think you in theory could do it with an eID and reader, I do not think anyone does. I know I have such a reader from a developer conference decades ago from when eID was lauched. Not sure it would even work on 2026 OS'es.
Thanks! ItsMe actually uses the connective signing ext system to sign users up so it's likely lots of people signed up for itsme with this flow and just never uninstalled the extension and native host.
Not sure. Do you have numbers? AFAIK having the eID reader was mostly an IT crowd thing. 'Normies' never had them, and even if they did they would have borked on the install.
The only numbers I've got right now are the 2M+ weekly active users on the chrome web store listing - I've not got exact numbers for how many people use the card readers but I get the impression it's more common in the legacy enterprise/government world.
The 2M+ WAUs would still be vulnerable to the RCE (assuming the native host is setup) independent of whether or not they have a card reader.
Comments
Nice writeup. As a belgian, I do not think I know anyone or any apllication that uses you eID pin. I know you have to create one at the municipality when you collect your id card, but I doubt anyone would ever remember it. ItsMe has universally replaced all scenarios that would have needed an eID with pin, and booting the ItsMe account, while I think you in theory could do it with an eID and reader, I do not think anyone does. I know I have such a reader from a developer conference decades ago from when eID was lauched. Not sure it would even work on 2026 OS'es.
Thanks! ItsMe actually uses the connective signing ext system to sign users up so it's likely lots of people signed up for itsme with this flow and just never uninstalled the extension and native host.
Not sure. Do you have numbers? AFAIK having the eID reader was mostly an IT crowd thing. 'Normies' never had them, and even if they did they would have borked on the install.
The only numbers I've got right now are the 2M+ weekly active users on the chrome web store listing - I've not got exact numbers for how many people use the card readers but I get the impression it's more common in the legacy enterprise/government world.
The 2M+ WAUs would still be vulnerable to the RCE (assuming the native host is setup) independent of whether or not they have a card reader.