zlacker

[parent] [thread] 0 comments
1. shorts+(OP)[view] [source] 2025-09-28 20:31:57
The current reference design is not compatible with existing law. eIDAS regulation that is the legal basis for digital wallet mandates unlinkability. GDPR has a general requirement for technical controls to be state of the art. Inherent reliance on American monopolies is incompatible with Digital Markets Act.

The current design and usage of cryptographic primitives does not allow for unlikability (it is actually quite easy to for verifiers and relying parties to collude) and it certainly is not state-of-the-art. BBS signatures would achieve actual unlinkability, but those have been outright rejected by the designers.

Current implementation is poised to not comply with the regulation that established the mandate for the wallet and it violates GDPR. The best one could hope for is for CJEU to strike down the whole project.

The GitHub organization of the OP's post has various issues that discuss these ills. Here is a position of several cryptographers against the current design: https://github.com/eu-digital-identity-wallet/eudi-doc-archi...

[go to top]