eu-digital-identity-wallet / eudi-doc-architecture-and-reference-framework

The European Digital Identity Wallet
https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/
Other
431 stars 60 forks source link

supply chain vulnerability in wallet eco system #230

Open rveeghem opened 4 months ago

rveeghem commented 4 months ago

In the current reference framework, the provider of the wallet is to be registered as a trusted party (see link: EUDI wallet provider to Trusted List Registrar). However, there's no such requirement for the wallet provider's own suppliers. This allows a wallet provider to use non-trusted parties as a supplier, thus increasing the risk for a supply chain attack on the wallet eco-system, eroding the trust level of the eco-system.