Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some of the current EU ID cards are actually smartcards, so in terms of privacy guarantees and separation of concerns, we are moving backwards. I am also more comfortable with a low-tech solution that is not linked to my personal devices. Something like a FIDO passkey would be ideal as those are also able to verify the identity of the other side, but are relatively low-tech and won't serve to track me.




ICAO biometric travel documents, the underlying standard which almost all EU ID cards implement these days, aren't suitable for remote identity verification though, as they don't have any way of verifying whether the legitimate holder or a thief/fraudster is using them.

Selfie or video face verification is susceptible to deepfakes, and remote fingerprint reads would also require trusted reader hardware.

Some countries have domestic schemes implemented on the same cards (e.g. Germany), but these are not interoperable across the EU, and many countries just don't have any non-ICAO scheme on their cards to begin with, and are instead implementing eIDAS (the current EU digital signature scheme) using some alternate scheme.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: