Hacker News new | ask | show | jobs
by rtb 1097 days ago
You completely miss the point. The crypto key held by the EIDAS provider is not the weak link. They are very securely attesting ONLY that the signatory controlled a given email address at the time of the signature. If I can get control of your email address then I can sign anything in your name with EIDAS. It's worthless, as the signatory can just claim that their email was hacked. You might as well just rely on emails, as we do in the UK.