https://store.ui.com/us/en/category/internet-solutions/colle...
181 karma · joined May 29, 2020
https://store.ui.com/us/en/category/internet-solutions/colle...
It has no concept of “who” you are, only that it got positively authenticated while on a wrist by proximity to your iPhone unlock or a manual correct PIN entry and hasn’t separated from that wrist since.
That said, I hope the service doesn't implicitly trust data sent by untrusted clients like web browsers, otherwise someone could just use something like this to send it a false location: https://chromewebstore.google.com/detail/spoof-geolocation/i...
The user's credential is bound to the device and protected by their biometrics (Face ID/Touch ID), and the consent screen feels very similar to using a Passkey (gaining in mainstream popularity) or Apple Pay (pretty mainstream at this point).
- https://www.w3.org/TR/digital-credentials/
- Apple's implementation - https://developer.apple.com/wallet/get-started-with-verify-w... (and moving to the browser in iOS 26 https://support.apple.com/en-gb/guide/apple-business-connect...)
The challenge here is adoption and availability of digital credentials. It appears State Department is allowing iOS 26 to issue digital credential representations of US passports also. Japan are also providing their national ID card in this way. Given some US states' online age verification laws (and whatever it is the UK are trying to do at the moment), seems like a great incentive for those governments to provide robust digital ID infrastructure.
Enforcement and policing of this is presently unclear (and will likely be delegated to local environmental health and licensing authorities, from what I’ve read - so may be inconsistent across the country).
I suppose if an outbreak is linked to a venue that hasn’t implemented the recommendations it will (at best) reflect badly, and at worst attract attention from the local authority in the same way as if other recommended public health measures were not implemented.
UK pubs will reopen on Saturday but government issued guidance recommends that venues require customers to leave contact details in case of a localised Corona outbreak. We designed a simple service to collect the bare minimum data to comply with both the registration guidance and GDPR.
Customers just send a four digit SMS locator to a number (or an email to a special mailbox) and we log either the sender's phone number or email address against the venue and the time of entry. We reply to the message with a confirmation that can be shown to security/service staff. All data is encrypted on the back end and retention periods are enforced. Data export is controlled (and similarly encrypted) in the event that a venue is required to provide by the public health authority.
This approach means data is accurate (non-trivial to forge sender headers) and low friction for the customers. Not asking for personal details to be input makes for a less invasive check in experience for the customer, whilst maintaining compliance for the venue.