Comment by uyzstvqs
2 days ago
Important to note: Their anonymous solution is reported to be temporary until their digital ID system is released[1], which does not offer that same anonymity, but rather functions as a server-side OpenID-based authentication system.[2] While you can share only your age with an online service, it still creates an authorization token, which appears to remain persistent until manually removed by the user in the eID app. This would give the host of that authentication system (EU and/or governments) the ability to see which services you have shared data with, as well as a token linked to your account/session at that service. There is also no guarantee that removing an authorization will actually delete all that data in a non-recoverable way from the authentication system's servers.
[1] https://itdaily.com/news/security/eu-temporary-app-age-verif...
[2] https://openid.net/specs/openid-4-verifiable-presentations-1...
Good catch, that does seem a lot worse. :/