Hacker News new | ask | show | jobs
by sam_lowry_ 1841 days ago
> Belgian eID works (almost) flawlessly on Linux.

The software stack is pretty much standardized. I am a bit worried about aarch64 platforms, but hopefully they will also be supported.

OTOH, the itsme application is a huge security issue aside of being a serious vendor lock-in over passwords, 2FA and OTP. It is tivoising logins like OKTA, except that here, it is mandated by the state.

1 comments

It's not just about working on various platforms. The whole thing is just ... weird. When you're signing something with eID, you have no idea what you're signing. It could be anything. You have to trust that's signing what you think it's signing. Even the difference between signing and authenticating isn't always clear. It would be super easy to trick a user into signing a document while pretending to present a login form.