Re: Web Identity 1.0 -- Draft Spec

On 2014-01-01 22:24, Melvin Carvalho wrote:
> https://web-payments.org/specs/source/web-identity/
>
> This is some work going on in the web payments community group.
>
> Still a very early draft, but it may be interesting to compare how the payments group does identity compared with this groups efforts.
>
> Bear in mind that there's quite a bit of industry backing behind payments, including active participation from Mozilla, so this set of specs may end up winning the race to become w3c RECs.

I have one major objection to this draft.

Identity tends to be a very context-dependent thing.

WebID was designed to cover the needs of the social web which I think is a well-defined context.
For payments there are entirely different requirements, usually regulated through laws and also seem to have fairly local/national interpretations.

I guess the web-payment group is targeting KYC (Know You Customer)?  Having recently moved to France I can testify that French banks do KYC  based on physical IDs and various papers such as electricity bills, salary statements.  Fast and efficient? No!  Will they change?  Very unlikely.

Authentication of the payer is very important but taking care of the bootstrap/association of that authentication is IMO simply overdoing it.
The EU have toiled with eID for 10 years without getting much acceptance by the financial sector and one reason is that there is a general distrust between governments and banks.

Cheers,
Anders

Received on Thursday, 2 January 2014 07:59:08 UTC