Re: Centralization dangers of applying OpenID Connect to wallets protocols (was: Re: 2022-2026 Verifiable Data Standards Roadmap [DRAFT])

On 3/24/22 1:37 PM, Oliver Terbu wrote:
> Btw. app links are more secure than custom URL schemes and they are the 
> recommended way of invoking a native app. Interop is not established based
> on the concrete app link, it is established through the
> `authorization_endpoint` config parameter which can be any sort of URL,
> e.g., an app link. There is no issue regarding interop since RPs don't need
> to know the particular app link, just the place where to look for the
> config parameter.

Unless I'm missing something, App Links only work on Android mobile devices to
invoke Android native apps, they don't work for web apps. On iPhone, universal
links are hobbled outside of Safari (just like you can't install a PWA through
Chrome on iPhone).

So, they would be a solution if your wallet was a native app on the same
mobile device (Android or iPhone), but they are NOT a solution if your wallet
is a web app on the same device... or if you are on a non-Android or
non-iPhone device -- like a Windows laptop/workstation.

What am I missing? Is there some universal implementation of App Link /
Universal Links across all operating systems that I'm unaware of?

-- manu

