But basically you're saying that I need a QR code for each site I'm using? That's not obvious from reading the blog post. And still doesn't address that someone else could use the same code on the same site?
Also I don't think I understand what "the secrecy of your social insurance number/credit card doesn't matter as long as nobody else can generate a certificate for it" means. Is that assuming everyone only accepts certificates and not the raw information anymore?
I'm sure fraudsters would happily take credit card numbers even without being able to generate certificates.