Why this specification of age verification is so mobile-centric? Like, there are no options like these:
- OTP via SM flow,
- FIDO2 webauthn flows with TPM, Yubikey and other USB dongles with keystores and data signing capabilities
- dedicated device with monochrome display, specialized EUID/Age Verification software preinstalled, and USB, NFC and Bluetooth interfaces, without any touch of Google or Apple
The whole spec rotates only about just 2 flows:
- mobile device of quite specifc kind, with stock Android or iOS onboard, with age verification app installed.
- device from (1) used to scan via camera a QR code appearing on screen of the other device.
I asked a related question to this spec here: https://github.com/eu-digital-identity-wallet/av-doc-technical-specification/discussions/62
If find this relevant, and have GitHub account – boost that question please.
(PS: already seen question there from people asking why ever GitHub used to store that spec)
Leave a Reply