4 ms·
As I understand it the validation happens online to avoid tracking. Nowadays banks and telcos share a lot of information on their clients. So instead of giving
by krab 3y ago
As I understand it the validation happens online to avoid tracking. Nowadays banks and telcos share a lot of information on their clients. So instead of giving out the unchanging personal ID number (containing the date of birth), you're supposed to give out the number of your ID card that changes every five or ten years. Or, in the online world, the bank gets a unique token.
I don't think it will fulfill that purpose in practice. The name plus date of birth is a very good tracking identifier and people will be still giving DOB to these companies.
- rekoil 3y agoThere are even cooler ways of doing this, look up eIDAS and/or Zero-Knowledge Proofs. Basically, with the right cryptography, my app can prove my license is valid without revealing any PII. Or in the case of eIDAS, binary questions like "is rekoil 18 years or older?".