Skip to content

Root of Trust in Verification #12

@toreini

Description

@toreini

Adding the points in the issue #5 raised by @torgo:
It is unclear where the root of trust in the digital credentials is. I can infer the trust is coming from the integrity and proofs provided by the Digital Wallet, under the assumption that it has already verified the physical credentials and government records. This approach is not bullet-proof. An old example is the traceability attacks to e-passports, and a newer attack to digital wallets.

Wallets identity verification pipeline is also vulnerable to new forms of attack, some examples:

I believe root of trust (and acknowledging its complications) needs to be clarified somewhere in the document.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions