Hacker News new | ask | show | jobs
by hugolundin 1906 days ago
Additionally, that tweet is wrong. BankID is an authentication system, and won’t give the 3rd party access to your bank account
1 comments

One additional data point, with my DPO hat on.

BankID is both an authentication and user information service system. Swedish customers can sign up with BankID, and the beauty of the setup is that we are exposed to less private information than we otherwise would.

On login, these same customers go through BankID flow, and we get an assertation from the service that essentially tells us "login is valid for this previously assigned unique customer identifier".