Particle.news

German d-you Wallet Draws Sharp Criticism Over Security, Privacy and Readiness

Experts and officials say unresolved device insecurity, withheld code, missing provider vetting and no clear pseudonymous option prevent the project from meeting EU notification rules.

Overview

  • A parliamentary hearing produced broad expert criticism of the d-you project’s design and governance and concluded the system needs substantial work before it can be considered ready.
  • Government officials told MPs that d-you is not yet an eIDAS/EUDI-compliant wallet and cannot currently be notified to the European Commission for cross‑EU use.
  • Lawmakers were warned that the planned Digitale-Identitäten-Gesetz must be passed quickly to create the national legal links the wallet needs and to set clear supervisory and liability rules.
  • Security experts highlighted a central risk that compromised smartphones would let attackers impersonate users to carry out actions such as bookings or loans and said a cloud security anchor and clearer emergency lock/suspension procedures are required.
  • Critics also flagged the absence of an ex-ante vetting process for service providers, withheld code for a security component (RASP), and centralised signature handling that raises privacy and future quantum-resilience concerns.