https://www.youtube.com/@elecblush Musician, Gamer, IT specialist

  • 0 Posts
  • 8 Comments
Joined 3 years ago
cake
Cake day: July 12th, 2023

help-circle

  • Eu is working on a digital wallet that would (among other things) help with this.

    Afaik It has a tiered information/identity structure, where the lowest level is: “is this a human being” (as an alternative to captcha)

    Then you could have age. (Just “is this person above %age”) Response would be just yes/no

    Then spesific age, nationality etc etc.

    You get the prompt, where it says what data they are asking for and you can concent or decline.

    The source of authority would be the nation you are a citizen of, the origin of data would be obscured through EU proxies, and data would only be transferred if you approve the transaction from your app.

    It’s a pretty big and ambitious project and could eventually lead to a lot easier transfer of sensitive data, where you are in control of who gets what and less need to store local copies of sensitive data. (An example usecase is for instance confirming a prescription to a drug for a pharmacy while traveling abroad).

    Biggest risk as i see is people confirming data request without scrutiny. There needs to be mechanisms to aggressively revoke the ability to ask for data if abused. And I would assume the requirements to what org can ask for high tier data are really strict.

    Going to be interesting to see what comes of it.



  • Lastly if you are asking how you would deal with getting new credentials. There would be a mechanism similar to when you first get the electronic id where your previous device gets deauthorized and you authorize a new one.

    All of these are allready solved problems at this point. We do this all the time with other credentials like online banking etc.

    This varies by country, but in Norway for instance all of these things are already solved and online/phone banking is both safe and the most common way of doing things.

    Loss/theft of phone is at worse a few phone calls and security questions to get it deauthorized (a properly secured phone would not be any significant hazard as mentioned in other responses) and authorizing a new device can be done with mail/SMS combo identification pr by showing up to a local office if you wanna do it that way.