[Openid-specs-ab] OpenID for Verifiable Presentations over BLE - draft 00 ready for review
Tom Jones
thomasclinganjones at gmail.com
Sat Jul 29 18:25:38 UTC 2023
i should have added - that is easy to fix, just include the subject id with
the qr code (or whatever).
Be the change you want to see in the world ..tom
On Sat, Jul 29, 2023 at 8:59 AM Tom Jones <thomasclinganjones at gmail.com>
wrote:
> thanks for the response - I remain unconvinced that the privacy of the
> user can be protected with what i have seen. No PII can be released before
> the holder is aware of the entity receiving the pII and consented to the
> release. ANY ID, including the ID of the wallet, is PII as it can be used
> to track the user.
>
> ..tom
>
>
> On Sat, Jul 29, 2023 at 2:53 AM <torsten at lodderstedt.net> wrote:
>
>> Hi Tom,
>> Am 28. Juli 2023, 20:51 +0200 schrieb Tom Jones <
>> thomasclinganjones at gmail.com>:
>>
>> I have a fundamental problem with OpenID for Verifiable Presentations
>> over BLE flow diagrams.It seems that the user wallet identifies itself
>> to the verifier before the user knows the identifier of the verifier.
>> There is a statement about the advertisement "5.2 The QR Code contains
>> the name and the ephemeral public key of the Verifier."Is the
>> presumption that the physical context of the QR code is sufficient?.
>> It seems that anyone could go about pasting QR codes in any place that
>> lead to attack sites.
>>
>> The text in section 5 is still a bit misleading (esp. re encrypted:wallet
>> provider clientid and encrypted:authentication context) and the information
>> about verifier authentication is missing in the current revision.
>>
>> The fundamental idea of the draft is to use the messages defined in the
>> OID4VP base spec and send them over a secure BLE connect. The description
>> of the actual OID4VP message exchange starts at Section 7.
>>
>> Section 7.2 states "The Request contains a signed request object
>> containing the parameters as defined in [OpenID4VP].“ but does not
>> explain the rest.
>>
>> The wallet can authenticate the verifier using this signed OID4VP
>> request object, that is sent through the BLE connection.
>>
>> It is still an early draft, we will improve the text. So thanks for
>> raising that issue.
>>
>> best regards,
>> Torsten.
>>
>>
>> I am creating some BLE code to see if section 5.1 is any better. It is
>> not clear from the docs that i have what information is in the ad.
>> ..tomj
>>
>>
>> On Tue, Apr 25, 2023 at 4:37 AM Torsten Lodderstedt via Openid-specs-ab <
>> openid-specs-ab at lists.openid.net
>> <https://mailto:openid-specs-ab@lists.openid.net>> wrote:
>>
>> Hi all,
>>
>> the initial revision of the OpenID for Verifiable Presentations over BLE
>> draft is now available
>> https://openid.bitbucket.io/connect/openid-4-verifiable-presentations-over-ble-1_0.html
>> .
>>
>> Please review the specification and give feedback either here on the list
>> or through issues at
>> https://bitbucket.org/openid/connect/issues?status=new&status=open&status=submitted&is_spam=!spam
>> .
>>
>> Thanks in advance,
>> Torsten.
>> _______________________________________________
>> Openid-specs-ab mailing list
>> Openid-specs-ab at lists.openid.net
>> <https://mailto:Openid-specs-ab@lists.openid.net>
>> https://lists.openid.net/mailman/listinfo/openid-specs-ab
>>
>>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20230729/55015447/attachment-0001.html>
More information about the Openid-specs-ab
mailing list