That’s just the reality of doing business on the Internet. This is by far the best way of doing it right now, not that this information appears to have made it down under so far.
While Australia’s new legislation is ham-fisted and poorly thought out, the intent isn’t wrong and there’s broad consensus for it (77% approval in Australia). We need to do something about the uncontrolled exploitation, manipulation and endangerment of minors by social media services. Corporations are clearly not interested in protecting them and parents are obviously incapable of it as well (although I could have told you the same thing 20 years ago). That’s precisely the kind of issue where the government is supposed to step in with regulation of some sort.
shasta@lemm.ee 3 weeks ago
And you need a central online API to validate the token’s validity, which means any system using it needs to be connected to the Internet, and that API needs to be very reliable, kept up-to-date, and DDOS resistant.
Or require the user to enter a PIN like with x509 certs, but then you also need a way for people to reset their PIN when it gets forgotten or compromised which means a huge bureaucratic burden and expense. And between the time of needing a reset and getting it, you’ll be unable to access any services requiring your ID token which will almost definitely cause some people from making payments (if banks change to requiring a digital ID token) and who knows what else.