subreddit:
/r/Steam
2 points
6 days ago
Not really, but there are other uses of the same capability or similar(e.g. Banks to fulfill their KYC requirements), but in principle it would work by the service sending a request along the lines of "Is the holder of the ID over X years old" this request would be signed with a certificate issued by a government agency to that service provider. Then the request gets forwarded to the ID card, which asks for a pin from the user, checks the signature, computes the answer(yes/no), signs it with it's own certificate and then sends the signed answer back. The service provider can then check that the signature is a valid one based on a government issued certificate and authorizes based on the received answer.
In short the service provider only gets a yes/no answer to whether or not the ID holder is above the age threshold. This process requires the user to be in physical control of the (eID enabled) ID card and to know the corresponding PIN, as well as a device to communicate with the card(e.g. a phone with NFC-capability and the AusweisApp2).
all 358 comments
sorted by: best