You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We should add to the security considerations section that the VCDM does not prevent from MITM, replay and cloning attacks. This applies to online and offline use cases. The VCDM does not have any mechanisms to allow a verifier to understand whether the presented VC belongs to the holder.
The text was updated successfully, but these errors were encountered:
We should probably point out that this is typically handled by securing mechanisms or contextual claims matching, e.g., picture matching, identifier matching etc. Contextual claims matching requires additional vocabs that are out of scope of the core data model.
+1 to pointing to this being handled by securing mechanisms. As part of this it may be worth opening issues on existing securing mechanisms to make sure this is covered.
We should add to the security considerations section that the VCDM does not prevent from MITM, replay and cloning attacks. This applies to online and offline use cases. The VCDM does not have any mechanisms to allow a verifier to understand whether the presented VC belongs to the holder.
The text was updated successfully, but these errors were encountered: