Why can't they be both?
HN user
zadeh
Perhaps you are right, but we have to create systems for the needs of today's society as well, and in today's society you need to be eligible for a certain benefit in order to get it. Therefore, we need a person's identity (with all the personal information that are required for such eligibility to be checked) when that person is authenticating online and applying for that benefit.
Well none of these social media SSO supports a high Level of Assurance anyway.
1000 percent this!
What if you apply for a state benefits (e.g. benefits for your children, or student state grants)? These kind of services being accessible online are common in the Nordics and when authenticating the service provider would need to know a lot of personal information such as name, age, adress or email, previous given benefits records from other service providers, current loan debt status, university registration status, bank account nr, family members etc...
Zero knowledge proof in identity is a thing, but then the assurance of identity falls on a third party that has to verify your identity. There is also Self-Sovereign Identity and user-centric identity management which many consider the future of identity. But even in that case, most often a third party needs to at least maintain the infrastructure of where your identity is stored.
Banks, governments or any other strong authentication required services.
Yes I am, sorry. English is not my first language.
Could anybody explain (or point me to) the pros and cons of using ISO/IEC 29115 vs NIST 800-63B authentication and identity guidelines? I just started working with electrical identification (eID) but can't find any good resources on which standard to choose.