1. Single Point of Failure
While concentration of function and data onto just 2 mobile platforms is great for controlling citizen behaviours and selling their data, it is very poor for the citizen's privacy and security.
Putting the EUDI Wallet on the citizen's phones as a mobile app creates a single point of failure.
1.1. Non-Stop Security Bugs
Putting all your most valuable data (EUDI intent to store almost everything from your health records to education results) on platforms which have proved to have been hacked and have still NEW security bugs appearing EVERY single month does not make any sense.
1.2. No Safe State
Mobile phones are normally exposed online for most parts of the day, interacting constantly in the background with internet sites that the phone owner have no idea of.
To make things worse, thousands of new mobile apps are download and installed everyday by EU citizens on thousands of different phone hardware and operating system version combinations.
With the constant changes, there is no steady state to be analysed and established as safe. It is IMPOSSIBLE to perform security assurance testing to any credible level.
And we have not even mentioned possible bugs with the EUDI Wallets themselves (which are being developed independently with different quality by different countries).
1.3. Physical Risk
As more and more data is put on the phone, it become more valuable target for attack, not just through the internet but also physically.
With the phone being use for everything (including EUID Wallet), having physical control of the phone, means having control of all the application and data on it.
-
Unlocking a phone by just pointing it at a victim's face is easy and less violent that trying to force out a password that might be forgotten.
-
Sending a SMS code to the SAME device that has just supplied a password, is poor multi-factor authentication.
The improvement in physical security of mobile phones and their owners have NOT catch up with the increasingly important roles it play and concentration of data it has stored on it.
2. Fundamental Flaw 2 - Ancient Design
1. Centralisation of Power
European Digital Identity Wallet (EDIW) intents to transfer the control of personal identities from 440+ million EU citizens to just 2 US companies.
Both are companies with proven to act against the interest of the
The damage to the 27 EU governments by putting their identity systems under the control of Apple and Google, so much less than the damage their poor citizens have to endure.
All the identity system of all s have to follow app store rules from Apple and Google.
The EU is pushing their citizens on the advertisement platform
There are limitation that stufles COVID
Encur
European Digital Identity transfers control of their citizen's identity from 27 EU countries to just 2 US companies.
The app stores that EBoth Apple Ads and Google Ads
(2) Centralisation of Device
Previously
European Digital Identity is NOT increase EU citizen privacy,
it actually INCREASES the Centralisation of Power
As a mobile app
transfer more substantial MORE power (e.g. ability cr
oss EU states) into the
bases itself on
App Store Vulnerability
Mobile Phone Vulnerability
Stealing vs Robbing
Instead of just stealing your digital wallet (you phone), now the bad people have to take control of both your phone and YOU
then they can use you face or whatever to unlock it and have FULL access to your wallet.