(I actually do know where my key material is. It's on a smartcard that nothing that exists today can read. Back in the day laptops had smartcard ports! Crazy.)
(I actually do know where my key material is. It's on a smartcard that nothing that exists today can read. Back in the day laptops had smartcard ports! Crazy.)
I do miss built-in smartcard readers though; carrying a USB reader is just not the same and I usually don't have mine with me when I need it.
That said, I also wish browsers would support the ISO 7816 transport of CTAP2 for WebAuthN using these readers. That would allow me to use a card form factor WebAuthN authenticator not only on my phone (both iOS and Android support CTAP2 over contactless), but also on my computer.
AFAIK, and I might be wrong here, you do have the right to be forgotten - art 17. But there is no need to periodically renew consent. As long as the period for consent is understood and is relatable for the reason of the consent, it can be basically for ever. In this case, that period seems to be 'until he withdraws his consent' and that seems fine by my reading of the GDPR.
> Your company/organisation should establish time limits to erase or review the data stored.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
> In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review.
Have you not gotten, over the past few years, emails from services you no longer use and probably forgot that you ever setup an account for, informing you that they will delete your account if you don't use it soon? It's because of the GDPR.