eu-digital-identity-wallet / eudi-doc-architecture-and-reference-framework

The European Digital Identity Wallet
https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/
Other
431 stars 60 forks source link

User ability to check Wallet instance authenticity and security must not be considered #240

Open GSMA-EIG opened 4 months ago

GSMA-EIG commented 4 months ago

§ 6.5.2.1: “The User verifies that the Wallet Instance (i.e., the application the User is installing) is genuine and authentic and does not contain any malware or other threats.” This requirement puts a lot of responsibilities on the shoulders of the user. This expectation is not realistic as all users may not have the skills to perform all the checks needed to verify the authenticity and security of a Wallet Instance.