> A real verifier needs to additionally check the encoded data matches the human-readable data on the front of the card.
I mean, not really? Only the machine-readable part is signed, so it should be treated as the sole source of truth. Besides, only an idiot forger would put different data in the human-readable part - it would be the easiest way to get caught!