@Sjors does hashing the national id for recovery basically bake blacklisting right into the design?
Login to reply
Replies (1)
The one-to-one coupling does it, yes. It would still be the case if they follow my suggestion to generate (and store) a random number for each BSN and then hash that.
It's not fundamental to the EU directive afaik, it's a problem with this particular architecture. But I suspect that any conceivable architecture that's permitted under the law (which is flexible) is going to have serious issues like this.