← Back to post

Edit history

Most recent

I’ll start off by saying I’m not super familiar with the EU proposal for digital IDs (other than looking at a few articles here and there), but

  1. I’m not in the EU. The EU proposal is tied specifically to the EU. And without documents that establish physical presence in the EU it makes it hard to interact with EU services. A cert with an email doesn’t have this problem.

  2. There are more problematic cases than “non-EU citizen outside of the EU want to access EU services”. There are always edge cases where there’s a piece of document that establishes the person is legally allowed to be here but is glossed over as an “ID”. Usually, you can present these in person and a human would be able to check it. It’s much harder to convince an automated machine to do so, especially when it isn’t in a drop down list. Which means no digital ID for this person (since the system can’t verify). This is not hypothetical. I have actually encountered this myself outside of the EU. Impossible to submit rental applications, trade-ins at Best buy, rent cloud servers, etc. A verification system backed by multiple non-government entities can alleviate this by 1) only verifying age and 2) verifying age through different methods, sometimes even through human vetting.

  3. Data protection is governed by policy in the EU proposal. Policy can change. It’s a lot harder when something is technically impossible by design. A cert with only an email cannot produce a name in it, even if storage was implemented incorrectly.

  4. My understanding is that while the digital id wallet is supposed to be open source, currently it depends on Google attestation framework and can’t even work on GraphineOS. You don’t run into this problem with a file.

Edited

I’ll start off by saying I’m not super familiar with the EU proposal for digital IDs (other than looking at a few articles here and there), but

  1. I’m not in the EU. The EU proposal is tied specifically to the EU. And without documents that establish physical presence in the EU it makes it hard to interact with EU services. A cert with an email doesn’t have this problem.

  2. There are more problematic cases than “non-EU citizen outside of the EU want to access EU services”. There are always edge cases where there’s a piece of document that establishes the person is legally allowed to be here but is glossed over as an “ID”. Usually, you can present these in person and a human would be able to check it. It’s much harder to convince an automated machine to do so, especially when it isn’t in a drop down list. This is not hypothetical. I have actually encountered this myself somewhere outside of the EU. Impossible to submit rental applications, trade-ins at Best buy, rent cloud servers, etc. A verification system backed by multiple non-government entities can alleviate this by 1) only verifying age and 2) verifying age through different methods, sometimes even through human vetting.

  3. Data protection is governed by policy in the EU proposal. Policy can change. It’s a lot harder when something is technically impossible by design. A cert with only an email cannot produce a name in it, even if storage was implemented incorrectly.

  4. My understanding is that while the digital id wallet is supposed to be open source, currently it depends on Google attestation framework and can’t even work on GraphineOS. You don’t run into this problem with a file.

Original

I’ll start off by saying I’m not super familiar with the EU proposal for digital IDs (other than looking at a few articles here and there), but

  1. I’m not in the EU. The EU proposal is tied specifically to the EU. And without documents that establish physical presence in the EU it makes it hard to interact with EU services.

  2. There are more problematic cases than “non-EU citizen outside of the EU want to access EU services”. There are always edge cases where there’s a piece of document that establishes the person is legally allowed to be here but is glossed over as an “ID”. Usually, you can present these in person and a human would be able to check it. It’s much harder to convince an automated machine to do so, especially when it isn’t in a drop down list. This is not hypothetical. I have actually encountered this myself somewhere outside of the EU. Impossible to submit rental applications, trade-ins at Best buy, rent cloud servers, etc.

  3. Data protection is governed by policy in the EU proposal. Policy can change. It’s a lot harder when something is technically impossible by design. A cert with only an email cannot produce a name in it, even if storage was implemented incorrectly.

  4. My understanding is that while the digital id wallet is supposed to be open source, currently it depends on Google attestation framework and can’t even work on GraphineOS. You don’t run into this problem with a file.