> You can of course create an independent attestation database at any time
Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
Come on now.
> minimum security requirements for digital ID use
Also known as "the user has no control over the device".
Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it.
> We use that approach in several other industries.
Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable.
> Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
That sounds mostly like copium just to motivate your complete inaction.
Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU.
But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic.