• MoonlightFox@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 hours ago

    Can you elaborate a bit on the google and apple servers for authentication? My impression was that this system uses its own platform.

    • virku@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      45 minutes ago

      BankID is it’s own trusted platform. It is not connected to any of them. I am not sure if I understand what the other person is trying to say. Maybe they are afraid that Google and Apple can use BankID verified sessions to better identify the user?

      • Lifter@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        18 minutes ago

        They are using the phone SDKs to verify that BankID was correctly installed, much like any other client side DRM.

        • virku@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          9 minutes ago

          I don’t think BankID has any sort of SDK that lets other apps access user data like that? All interaction with BankID I know of at least is triggered with the app needing authentication/signature opening a BankID session to the central service where you enter your authentication and then the BankID app is used as MFA to verify this.

          Or am I misunderstanding what you are saying completely?