"In the limited time that I was allowed to spend with these documents, I was able to confirm that they require that mDL credentials be “provisioned” through a TSA-approved app on a TSA-approved device, with that device biometrically “bound” to an individual. The process of “presenting” a digital ID will be a four-way interaction between the individual, the app (it’s unclear whether or how the user will be able to authenticate the app or know what it is doing), functions on the device to collect biometrics (controlled, in all likelihood, by an operating system with root privileges whose actions can’t be monitored or controlled by the individual), and the credential-issuing driver’s license agency.
mDL apps will be required to log each time a digital ID is presented, and to whom. This is described as a measure to protect ID-holders’ privacy, despite the obvious risk posed by police or others being able to know when and to whom you have shown your ID. If you use your digital ID for age verificaiton to show that you are old enough ton be allowed to access adult information about sexual health or abortion, that fact will be logged on your device.
Supposely these logs will be available only to the device owner. But in reality, they will also be available to anyone who seizes the device while it is unlocked, cracks the device lock with forensic or criminal tools, or forces an individual — legally or illegally — to unlock it."
#privacy #TSA
https://mastodon.online/@ehasbrouck/113544230701295912