Hacker News new | ask | show | jobs
by elric 1840 days ago
It's not just about working on various platforms. The whole thing is just ... weird. When you're signing something with eID, you have no idea what you're signing. It could be anything. You have to trust that's signing what you think it's signing. Even the difference between signing and authenticating isn't always clear. It would be super easy to trick a user into signing a document while pretending to present a login form.