- From: Steffen Schwalm <Steffen.Schwalm@msg.group>
- Date: Thu, 11 Jun 2026 14:57:28 +0000
- To: Adrian Gropper <agropper@healthurl.com>
- CC: Manu Sporny <msporny@digitalbazaar.com>, Kyle Den Hartog <kyle@pryvit.tech>, Filip Kolarik <filip26@gmail.com>, Anders Rundgren <anders.rundgren.net@gmail.com>, W3C Credentials Community Group <public-credentials@w3.org>
- Message-ID: <PR3P191MB0954F2E27A7B99C5F53EB516FA1B2@PR3P191MB0954.EURP191.PROD.OUTLOOK.COM>
Seems a bit like acc. “EUDI technical framework may need some update concerning decentralized identity management requirements and corresponding technical measures like e.g. DID, decentralized trust registries etc. and bit more flexibility in comparison to what we have now” but happy to improve
Von: Adrian Gropper <agropper@healthurl.com>
Gesendet: Donnerstag, 11. Juni 2026 16:53
An: Steffen Schwalm <Steffen.Schwalm@msg.group>
Cc: Manu Sporny <msporny@digitalbazaar.com>; Kyle Den Hartog <kyle@pryvit.tech>; Filip Kolarik <filip26@gmail.com>; Anders Rundgren <anders.rundgren.net@gmail.com>; W3C Credentials Community Group <public-credentials@w3.org>
Betreff: Re: AW: AW: AW: EU Payment Wallet Standard(s) - Proposed W3C Community Group
Caution: This email originated from outside of the organization. Despite an upstream security check of attachments and links by Microsoft Defender for Office, a residual risk always remains. Only open attachments and links from known and trusted senders.
What are the similarities?
- Adrian
On Thu, Jun 11, 2026 at 10:43 AM Steffen Schwalm <Steffen.Schwalm@msg.group<mailto:Steffen.Schwalm@msg.group>> wrote:
Hi Adrian,
I guess a possible consensus might be that EUDI technical framework may need some update concerning decentralized identity management requirements and corresponding technical measures like e.g. DID, decentralized trust registries etc. and bit more flexibility in comparison to what we have now.
It`s pity that in many parts we are not so far away from each other that`s why I would recommend to focus on similarities instead of differences
Best
Steffen
Von: Adrian Gropper <agropper@healthurl.com<mailto:agropper@healthurl.com>>
Gesendet: Donnerstag, 11. Juni 2026 16:33
An: Steffen Schwalm <Steffen.Schwalm@msg.group<mailto:Steffen.Schwalm@msg.group>>
Cc: Manu Sporny <msporny@digitalbazaar.com<mailto:msporny@digitalbazaar.com>>; Kyle Den Hartog <kyle@pryvit.tech<mailto:kyle@pryvit.tech>>; Filip Kolarik <filip26@gmail.com<mailto:filip26@gmail.com>>; Anders Rundgren <anders.rundgren.net@gmail.com<mailto:anders.rundgren.net@gmail.com>>; W3C Credentials Community Group <public-credentials@w3.org<mailto:public-credentials@w3.org>>
Betreff: Re: AW: AW: AW: EU Payment Wallet Standard(s) - Proposed W3C Community Group
Caution: This email originated from outside of the organization. Despite an upstream security check of attachments and links by Microsoft Defender for Office, a residual risk always remains. Only open attachments and links from known and trusted senders.
This thread is frustrating to follow and it feels to me like people are stuck. Is there any consensus at all about anything? If so, can someone articulate what it is?
- Adrian
On Thu, Jun 11, 2026 at 9:12 AM Steffen Schwalm <Steffen.Schwalm@msg.group<mailto:Steffen.Schwalm@msg.group>> wrote:
Hi Manu,
nobody question your experience only your assumptions which lack of well-grounded justification.
You speak of " completely beholden to large US tech companies and large monied interests" without providing any reasons for your assumptions beside a diffuse rejection of EUDI. Where exactly in EUDI are US Tech Companies involved? Where exactly EU bounds itself to US companies. Please provide any facts to be taken seriously.
You speak of EU, ARF, sometimes European SDO and put everything in same box. For your understanding:
- ARF and European SDO are different
- ARF developed mainly by Member States Experts, EC, NiScy (Consortium for EUDI reference implementation, Large Scale Pilots)
- SDO determined by ARF but they do not take part there
Issue for European SDO a bit with ARF: They are a bid bound to it without being really involved, means that even if they might not agree to everything they cannot ignore it. Means, if you criticize ARF then pls criticize its real authors which are not the European SDO.
“You cheer as "government wallets" will ensure EU control while not realizing that you just locked out all other competition and so it will be your government wallets competing with the platform wallets.”
* As eIDAS does not forbid any private wallet even as EUDI 8see. Art.5a nor non-EUDI you are wront
* The only subject eIDAS achieves is common technical ground
* EUDI won`t compete with platform wallets, it will be integrated as one system platform wallet need to interact (as Google btw already announced…)
* Means EUDI will IMHO included in the Google/Apple universe, which is actual risk
* But: 95% of the people do not care about our nerd discussions here, they want to use their known environment in Google or Apple – this won`t change any great privacy preserving standard – means we need to accept reality I we want to achieve adoptions and recognition.
* eIDAS recognize this by forcing Relying Parties to be registered and give holder chance to inform privacy officers and start action against cheating RP.
“There continue to be no mandatory certifications for web browsers, no client-side certificates by default -- that was by design, and open web demands it. Brave, Ladybird, Atlas, Comet -- none of them have to be certified to exist on the web and none of them have to identify themselves to connect to a website. The architects of EUDI and ARF believed they knew better and required both wallet certifications and client-side certificates without understanding why the Web does not demand both of those things by default. Just a really dumb, catastrophically bad move fueled by naivety, fear, and hubris.”
* Which does not matter if you have RP registration and access certificates, but yes QWAC and harder QWAC regulation in eIDAS would have been better way
“Integrating w/ DC API and HAIP requires you to register with the US big tech platforms to get a verifier certificate so you can request a digital credential. So, for one government agency to read another government agency's credentials, within the same nation state, you have to get permission from Google, Apple, Samsung, and any other wallet because the EU chose to back OID4 HAIP and DC API.
* Registration done at national registrars in MS where you have headquarter, this is no BigTech.
* See 2025/848
* Certificate is signing certificate acc. ETSI EN 319 411-1 and issued by de facto TSP (even if not legally)
So while I´m not big fan of HAIp and OID4VCI/VP I recommend you to understand eIDAS first before making assumptions.
So it`s bit funny: You accuse of naivety while not providing any justification of your assumptions while they are easily to refute.
Against the background my 10 cents:
- Why decentralized approaches were not successful:
* No standards for DID
* No standards for decentralized trust registries
Something Europe now fix. Recommend to put down walls and collaborate.
Best
-----Ursprüngliche Nachricht-----
Von: Manu Sporny <msporny@digitalbazaar.com<mailto:msporny@digitalbazaar.com>>
Gesendet: Donnerstag, 11. Juni 2026 14:45
An: Kyle Den Hartog <kyle@pryvit.tech<mailto:kyle@pryvit.tech>>
Cc: Steffen Schwalm <Steffen.Schwalm@msg.group<mailto:Steffen.Schwalm@msg.group>>; Filip Kolarik <filip26@gmail.com<mailto:filip26@gmail.com>>; Anders Rundgren <anders.rundgren.net@gmail.com<mailto:anders.rundgren.net@gmail.com>>; W3C Credentials Community Group <public-credentials@w3.org<mailto:public-credentials@w3.org>>
Betreff: Re: AW: AW: AW: EU Payment Wallet Standard(s) - Proposed W3C Community Group
Caution: This email originated from outside of the organization. Despite an upstream security check of attachments and links by Microsoft Defender for Office, a residual risk always remains. Only open attachments and links from known and trusted senders.
On Wed, Jun 10, 2026 at 10:52 AM Kyle Den Hartog <kyle@pryvit.tech<mailto:kyle@pryvit.tech>> wrote:
> As the person who directly engaged during the formal objection process with W3C management I’ll respectfully disagree. EU basically was going to shop the standard around and use custom schemes to force big tech to adopt digital credentials.
Yes, and the EU strategy has backfired horribly.
In an attempt to protect EU sovereignty, security, and privacy, it's done the opposite... made yourself completely beholden to large US tech companies and large monied interests.
Please note, Steffen, that many of us responding have been doing global technical standards, through multiple global standardization bodies, for a LONG time. It's not that we don't understand what you are saying, it's that we can see the naivety in your responses. You're on a sinking ship and are telling people to come on board, everythings fine and safe and going to plan, and the rest of us can see the giant hole in the side of the boat that's taking on water.
We don't want to get on your sinking ship.
We can see when something has been corrupted, and what's happened with EUDI and ARF is particularly spectacular because some of the folks, such as yourself, think the EU has succeeded when many of us that do this stuff for a living can see that the initiative has failed in the most catastrophic way. The EU has played directly into the very hands they were attempting to avoid being captured by. Naivety and hubris powered that trajectory, and based on your responses, still does.
Let me clearly state that W3C has been corrupted as well... no standardization body is hardened against monied interests. It happened during the W3C Payments initiative in the late 2000s, and it's happening again for the digital credentials work. Based on our current trajectory, I expect the W3C DC API to end up only supporting the EU stack... and it isn't because it's what's best for society, it's because it's what's best for the platform oligopolies. You cheer as "government wallets" will ensure EU control while not realizing that you just locked out all other competition and so it will be your government wallets competing with the platform wallets. We know who will win if competition is stifled in that way... and it's not going to be through government innovation. :)
There continue to be no mandatory certifications for web browsers, no client-side certificates by default -- that was by design, and open web demands it. Brave, Ladybird, Atlas, Comet -- none of them have to be certified to exist on the web and none of them have to identify themselves to connect to a website. The architects of EUDI and ARF believed they knew better and required both wallet certifications and client-side certificates without understanding why the Web does not demand both of those things by default. Just a really dumb, catastrophically bad move fueled by naivety, fear, and hubris.
The difference at W3C is that at least the corruption is publicly visible and documented. Some of us are still fighting because the W3C Process allows for that. Note how Kyle can point to Brave's formal objection on the DC API, whereas the ISO stuff is buried forever. My prediction is that the DC API will execute on the EU vision citing that the EU is on board with it (and they wouldn't back anything anti-competitive, would they!?)... the big tech vendors will go along because it's in their best interest. The EU set the bar so unnecessarily high, because of "security and privacy concerns" (that were hallucinated), that you've put US big tech directly in control of EU's future.
This response isn't so much for you Steffen, as you're a true believer in the EU approach. It's for everyone else that's looking at what's happening and wondering if they're the only person that can see the corruption. You're not. Bad things are definitely happening.
Let me provide just one concrete example of what the EU has unleashed on the rest of the world.
We, as a vendor selling digital credential solutions globally, are now walking our customers through how to integrate w/ OID4 HAIP over DC API. Why? Well, because "this is what the EU is doing!". Integrating w/ DC API and HAIP requires you to register with the US big tech platforms to get a verifier certificate so you can request a digital credential. So, for one government agency to read another government agency's credentials, within the same nation state, you have to get permission from Google, Apple, Samsung, and any other wallet because the EU chose to back OID4 HAIP and DC API.
The governments can't afford to support more than the big platform wallets and their government wallet because of the cost associated with registering all of those verifier certificates, keeping all of them updated and refreshed, and maintaining all the various versions of protocols that have been deployed to date (there isn't just /one/ OID4, there are many of them).
So, there goes digital wallet competition. Vendors need to charge money to do this laborious process, and it never ends because you have to keep renewing the verifier certificates and updating the protocols.
You have to do this over, and over, and over again for every government agency, no matter how small they are... because you can't ask for someone's identification document without this thing in place, even when they know they're on a government website or have a government official standing right in front of them asking them for their ID. It's a tax on society for a really stupid set of technical decisions based on EU protectionism that has backfired so horribly that it's comical.
But, hey... it's good for business... at least, until the governments can't justify the spending to the taxpayers and it collapses under its own weight, ceding control back to the big US tech companies... which was always the plan, we just didn't think the EU would be so helpful in executing it.
-- manu
--
Manu Sporny - https://www.linkedin.com/in/manusporny/
Founder/CEO - Digital Bazaar, Inc.
https://www.digitalbazaar.com/
Received on Thursday, 11 June 2026 14:57:35 UTC