When a website has you type a name as a signature it’s a legal representation of that signature. There’s nothing cryptographic at all about it. Wjere would you even store the key? I’ve made ways to use Webauthn keys to do this, but no signatory uses these methods.
I claimed no such thing. That is not a digital signature
Fmstrat@lemmy.world 21 hours ago
But that’s what OP is describing with the “”'s, so I assumed you were responding to the question, which they may have as well.
Interesting, I hadn’t realized Finland added a separate cert from the ZKP ( suomi.fi/…/dc540ff4-0030-46b2-add0-9f7ceb2a41c8), new info gleaned.
Though this may still be “slightly” off. Seems the finish ID is a standard Zero Knowledge Proof (ZKP) plus a pin activated signature (Citizen) certificate.
This should mean you can identify yourself, or that you are over 18 without revealing your full identity) without the PIN, as that operates separately from the signing certificate which can be activated independently. The PIN would be used for signatures or encrypting things. Very cool.
MentalEdge@sopuli.xyz 20 hours ago
There are two PINs, PIN1 for ZKP and PIN2 digital signing. The card does nothing without one.
Most EU countries provide some way for citizens to sign documents using a private key tied to their legal personage.
Putting it on the ID card they are given anyway just makes sense.
My final paragraph is there to explain that a lot of “digital signatures” aren’t really signatures in any meaningful way. What goes into the actual file doesn’t matter at all, UNLESS it’s the aforementioned cryptographic signature.