• 0 Posts
  • 20 Comments
Joined 2 days ago
cake
Cake day: August 28th, 2026

help-circle
  • 1 & 2: it would work the same as all other EU specific things. You don’t need to comply with GDPR for people outside EU, you wouldn’t need to verify users outside the EU.

    3: I don’t know what you mean. It could be easy to modify spec of those certs to include names.

    4 You don’t know how this proposition is supposed to work.

    In short:

    There’re officially approved apps (you can’t just create you implementation arbitrary, but if you implementation meets all standards, you can work to have it approved). Using those apps, your credentials are secured with one (or many, I don’t understand that part) of:

    • Hardware secure element
    • Software secure element
    • External device
    • Server HSM operated by the provider

    Those apps must also use some defined encryption standards.

    When you create your app, it needs to be approved by one of the member states.

    The app can store all kinds of personal governmental things such as your ID, bank account number, drivers license, etc.

    When a service wants to know whether you are 18 or more, you can give them your wallet. The wallet app will show who demands what informations and a reason they put in the request. You can approve or reject the request.

    It doesn’t have to be tied to google or anyone other.

    Yes, those apps won’t be libre, but (and you don’t need to agree with me) in my opinion this is better than letting people create any implementation they want.

    GrapheneOS can create thier implementation, that relies on hardware security chip. Linux distros can create a joint implementation reliant on yubikeys and alternatives.

    Also, alternatives must remain.