The FIDO alliance, in charge of authentication standards such as the FIDO2 standard widely used in hardware keys, has announced a new digital credentials initiative aimed at standardizing and streamlining the adoption of “verifiable digital credentials and identity wallets.”
Unless I’m mistaken I’d like to think this as a way for those to get standardized so whenever you have a Linux phone, GrapheneOS, Android or whatever it is at least a form of secure digital ID and without it being at risk of a breached server which is what I’ve been asking for a while, Passkeys FIDO or not are pretty secure as is and having one of the most sensitive information secured like this is important.
Hopefully, this will become a standard that is used widely around the world. It now seems very likely that age verification will be required everywhere. However, this is certainly the best of the bad options I have heard about.
On a positive note, this also gets people and services used to using Passkeys. Hopefully, that will lead to them being adopted very widely.
If this could be used as a way to verify age requirement, without revealing nessesary the holder name, this could be awesome. These wallet/identity will need to be signed with an authorities to prevent fakes. It could be used to read some information, but not all, and still have guaranteed of valid values with the cryptographic Signature.
Let’s stay realistic, these verification measure are bad, but it’s better if we have good technologies around it than not.
I don’t think an authority signature would necessarily be needed; you could do this with what is effectively a Parental Controls setting that states “This user is a minor,” similar to settings that have existed on devices/accounts for a while, but instead of having to make a whitelist/blacklist that contains all the notable sites, it’s a limited number of generalized settings that sites would have to comply with.
A FIDO-like standard would still be needed to have a cross-platform means of allowing apps/websites to query this data in order to act accordingly. Then put the responsibility on the manufacturers to allow setting this, on the parents to set appropriately, and on the services to respect the settings. Clearly not perfect, but IMO better than any of the doxxing “verification” that’s been done so far.