3 ms·
> Not true. The device's public key is also sent, which functions as a stable device identifier. This is covered by allowing for single-use credentials. IIRC t
by Aaargh20318 3mo ago
> Not true. The device's public key is also sent, which functions as a stable device identifier.
This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one request and then deleted. The wallet will automatically request new credentials in batches when they run out. The old key-pairs are deleted along with the credential so you don’t run out of space in the secure enclave.
> Another reason why these proposals aren't getting much uptake
I’m not sure what you mean by not much uptake, EU countries are required to issue and accept them for official business by the end of 2026
- jcgl 3mo ago> This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one request and then deleted. But this then means that the issuers and the verifiers can trivially collude to deanonymize holders/users.
- pseudalopex 3mo ago> This is covered by allowing for single-use credentials. They said There are proposed mitigations like issuing multiple sets of credentials or rotating them, but we're not going to get an infinite number of keypairs for every website or session in the secure enclave in practice. > Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. The comments you replied to omitted mass surveillance. But the article and 1st comment included it. The government would know what wallet requested each single use identifier.
- tremon 3mo ago> The government would know what wallet requested each single use identifier Which only means that the government knows how many tokens each citizen consumes on average. They don't know where each identifier was used nor the exact timestamp unless each website communicates this to the government, and such a backchannel does not exist in the spec.
- pseudalopex 3mo agoYou did not know governments demanded records? Or infiltrated networks? And governments investigated high electricity users as suspected marijuana growers. Would governments ignore high identifier use?
- tremon 3mo agoCan you make an actual argument rather than spouting insinuations? It's rather tiresome to have to construct my own straw man from your drivel.
- donmcronald 3mo ago> The wallet will automatically request new credentials in batches when they run out. Is that an ongoing cost that I’ll pay for via taxes? It doesn’t matter how anonymized all the schemes are. The government needs to give permission by signing attributes. It will be abused to gate everything we can do. I wouldn’t be surprised if everything is gated behind attestation fairly quickly. Then our “secure” devices will attest against us if we do anything that isn’t a government approved activity. Hopefully they never manage to hijack our network protocols. Imagine something like SNI, but it’s an attestation that traffic originated from a secure device that’ll participate in the scheme you described. Then your ISP can drop non-compliant traffic and you can only engage in government approved activity. The answer to these proposals should be “no”.
- inigyou 3mo agoWhatever the system is taxes will pay for it and the inherent cost will not be very high, but it'll be contracted to a greedy money-wasting government contracting firm like Oracle, as always happens.
- inigyou 3mo agoThe government will, of course, log all issued public keys and who they belong to.