Another huge shitstorm thread from British security researchers on Twitter[^1] about how the reference implementation of #EUDigitalWallet #AgeCheck published on https://ageverification.dev is “insecure”, while ignoring the tiny details it’s a REFERENCE implementation whose documentation literally say:
Pre-configured hosted services that allow you to test the Age Verification App and its core components without the need for complex local setup.
A production version would be hooked up to a respective national id database and therefore require no selfies etc.[^2]
The funny part is that a national id database is something that we don’t have in the UK[^3] because we instead made a choice to use commercial services from a private company Experian for the same purpose 😁
Also, you can clearly see that #Brexit did not only happen thanks to some red necks, as it’s often portrayed - British elites are also have a strong knee jerk response to anything that comes from the EU and violated “established truths” of their generation, for example the axiom that anything designed by a shitty private company is 100x better than anything designed by the “government”. I would honestly expect better from the generation of people who had actually lots of interesting things to say about cryptography and computer security in the past.
[^1]: https://xcancel.com/Paul_Reviews/status/2044436001611801072?s=20
[^2]: https://ageverification.dev
[^3]: https://krvtz.net/en/posts/in-defense-of-the-national-id-and-digital-id.html