oauth-wg / oauth-sd-jwt-vc

draft-terbu-sd-jwt-vc
Creative Commons Zero v1.0 Universal
19 stars 12 forks source link

Potential Privacy implications of verifier knowing display information #247

Open Sakurann opened 3 months ago

Sakurann commented 3 months ago

Per John Bradley comment during IETF 120

danielfett commented 1 month ago

Per the meeting minutes:

John B: Metadata is interesting - nothing in metadata is disclosed to verifier? Brian: intended for holder, but could be used by verifier - not secret and is retrievable John B: Might leak what claims are availabile - might be some reasons not to disclose to the verifier John B: Should disucss policies for wallets, etc? e.g. Some gov may only want to permit disclosure or presentation to approved parties - if we want interop we should consider issuer to wallet policies - could metadata help with this? Question - is metadata a way of annotating policy type info? Brian: metadata could be, but debate around this and it is yet to be determined John B: we should figure this out Brian: agree John B: we should have an answer around privacy and consider it especially in regards to metadata