Comment by e12e

1 hour ago

The article is a little one sided, as it doesn't touch upon MinID which is a government ID service, and Idporten which is an authentication service that allows use of different EIDs, like MinID and BankID.

MinID is only considered "secure" while BankID is considered "highly secure"; as the linked pdf report (on Norwegian) states - in Norway, due to the popularity/market dominance of BankID - a lot of the logins are "highly secure" - while in Sweden their (different, but with same name) BankID is only "secure" - and most services require only "secure" login.

In Norway there are AFAIK public services that require "highly secure" login - and there the public issued MinID isn't enough.

If 2fa for MinID is improved - I think it would easily be upgraded to "highly secure" (most other details are similar to BankID). That should take care of public services.

Private services that do not cater to the public good - would still need a portal similar to (or be granted use of) Idporten.

So I think catastrophe is a little hyperbolic - but the current path of BankID dominance isn't good.

Ed: I see the hn title is editorialized - TFA has a more balanced title.

Ed2: From the podcast - BankID might get downgraded to "secure" because of how 2fa is handled - so it's not only MinID that might need some adjustments.