[Openid-specs-ab] OpenID for Verifiable Presentations over BLE - draft 00 ready for review

torsten at lodderstedt.net torsten at lodderstedt.net
Sun Jul 30 07:40:27 UTC 2023


the qr code already contains the client id of the rp. What would be the subject id?
Am 29. Juli 2023, 20:25 +0200 schrieb Tom Jones <thomasclinganjones at gmail.com>:
> i should have added - that is easy to fix, just include the subject id with the qr code (or whatever).
>
> Be the change you want to see in the world ..tom
>
>
> > On Sat, Jul 29, 2023 at 8:59 AM Tom Jones <thomasclinganjones at gmail.com> wrote:
> > > thanks for the response - I remain unconvinced that the privacy of the user can be protected with what i have seen. No PII can be released before the holder is aware of the entity receiving the pII and consented to the release.  ANY ID, including the ID of the wallet, is PII as it can be used to track the user.
> > >
> > > ..tom
> > >
> > >
> > > > On Sat, Jul 29, 2023 at 2:53 AM <torsten at lodderstedt.net> wrote:
> > > > > Hi Tom,
> > > > > Am 28. Juli 2023, 20:51 +0200 schrieb Tom Jones <thomasclinganjones at gmail.com>:
> > > > > > I have a fundamental problem with OpenID for Verifiable Presentations over BLE flow diagrams.It seems that the user wallet identifies itself to the verifier before the user knows the identifier of the verifier.
> > > > > > There is a statement about the advertisement "5.2 The QR Code contains the name and the ephemeral public key of the Verifier."Is the presumption that the physical context of the QR code is sufficient?.
> > > > > > It seems that anyone could go about pasting QR codes in any place that lead to attack sites.
> > > > > The text in section 5 is still a bit misleading (esp. re encrypted:wallet provider clientid and encrypted:authentication context) and the information about verifier authentication is missing in the current revision.
> > > > >
> > > > > The fundamental idea of the draft is to use the messages defined in the OID4VP base spec and send them over a secure BLE connect. The description of the actual OID4VP message exchange starts at Section 7.
> > > > >
> > > > > Section 7.2 states "The Request contains a signed request object containing the parameters as defined in [OpenID4VP].“ but does not explain the rest.
> > > > >
> > > > > The wallet can authenticate the verifier using this signed OID4VP request object, that is sent through the BLE connection.
> > > > >
> > > > > It is still an early draft, we will improve the text. So thanks for raising that issue.
> > > > >
> > > > > best regards,
> > > > > Torsten.
> > > > > >
> > > > > > I am creating some BLE code to see if section 5.1 is any better. It is not clear from the docs that i have what information is in the ad.
> > > > > > ..tomj
> > > > > >
> > > > > >
> > > > > > On Tue, Apr 25, 2023 at 4:37 AM Torsten Lodderstedt via Openid-specs-ab <openid-specs-ab at lists.openid.net> wrote:
> > > > > > > Hi all,
> > > > > > >
> > > > > > > the initial revision of the OpenID for Verifiable Presentations over BLE draft is now available https://openid.bitbucket.io/connect/openid-4-verifiable-presentations-over-ble-1_0.html.
> > > > > > >
> > > > > > > Please review the specification and give feedback either here on the list or through issues at https://bitbucket.org/openid/connect/issues?status=new&status=open&status=submitted&is_spam=!spam.
> > > > > > >
> > > > > > > Thanks in advance,
> > > > > > > Torsten.
> > > > > > > _______________________________________________
> > > > > > > Openid-specs-ab mailing list
> > > > > > > Openid-specs-ab at lists.openid.nethttps://lists.openid.net/mailman/listinfo/openid-specs-ab
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20230730/d468c9af/attachment-0001.html>


More information about the Openid-specs-ab mailing list