REVIEW 2 major objections 1 minor 98 references
Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigations
T0 review · 2 major / 1 minor · reviewed 2026-06-28 · grok-4.3
Pith's one-line read Users of the EU digital identity wallet are likely to overshare official IDs with inappropriate websites.
desk verdict Survey finds users would overshare EUDI credentials and an assistant tool cuts stated mistakes in half, but all data is self-reported intentions with no real-world validation. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The Credential Assistant, an interface that displays expert recommendations and user opinions to guide which identity attributes to disclose.
What would settle it
A deployment study that logs actual attribute disclosures made by real EUDI Wallet users when visiting websites and compares those logs against the survey predictions.
Extended reading notes
Core claim
The paper establishes that users are likely to overshare credentials from the EUDI Wallet, for example by disclosing official IDs to news websites at a rate of around 20 percent, and that this stems from difficulty judging appropriate disclosure. The Credential Assistant, which presents expert recommendations and aggregated user opinions, lowers the rate of such disclosure mistakes from around 15 percent to 7 percent, though it leaves a residual error rate that the authors say may require stronger interventions for sensitive attributes.
Load-bearing premise
Survey participants' stated disclosure intentions accurately reflect the real-world behavior of future EUDI Wallet users across the EU population.
Editorial extensions
If this is right
- Oversharing will reduce the usability of the EUDI Wallet.
- Oversharing will produce privacy violations, identity theft, and other abuses of leaked credentials.
- The Credential Assistant cuts disclosure mistakes from roughly 15 percent to 7 percent.
- Stronger interventions may still be needed, especially when sensitive attributes are involved.
Reading between the lines
- The same disclosure difficulties could appear in any digital credential system that lets users choose which attributes to release.
- Wallet software could embed the assistant by default to lower error rates without requiring separate user action.
- Long-term monitoring of live wallet traffic would be needed to check whether the survey numbers hold once the system launches.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper reports results from a large-scale survey of users and experts on credential disclosure decisions for the forthcoming EU Digital Identity (EUDI) Wallet. It claims that users are prone to oversharing (e.g., ~20% would disclose official ID to news websites) and that the authors' Credential Assistant intervention, which shows expert recommendations and user opinions, reduces disclosure mistakes from ~15% to ~7%. The work concludes that stronger interventions may still be needed for sensitive attributes.
Significance. If the survey-based findings hold, the paper provides timely empirical evidence of privacy risks in the EUDI Wallet rollout and demonstrates a feasible UI-based mitigation. The dual user/expert survey design and the before/after evaluation of the Credential Assistant are strengths that could inform both policy and wallet implementations across the EU.
major comments (2)
- [Abstract and § on survey methodology] Abstract and survey results section: The headline quantitative claims (~20% oversharing of official ID; reduction of mistakes from ~15% to ~7%) are derived solely from stated disclosure intentions. No validation, correlation study, or behavioral measurement is reported that links these intentions to actual credential disclosure decisions once users hold an EUDI Wallet. This assumption is load-bearing for both the risk assessment and the effectiveness claim of the Credential Assistant.
- [Abstract] Abstract: Concrete percentages are presented without sample size, recruitment method, statistical tests, confidence intervals, or error bars. This omission prevents assessment of the reliability and generalizability of the central empirical results.
minor comments (1)
- [Results] Results section: The presentation of the Credential Assistant evaluation would be clearer if the exact survey items, response scales, and how 'mistakes' were coded were shown in a table or appendix.
Simulated Author's Rebuttal
We thank the referee for the constructive feedback highlighting important aspects of our survey methodology and presentation. We address both major comments below and will revise the manuscript to improve clarity and transparency while preserving the core contribution of the pre-deployment study.
read point-by-point responses
-
Referee: [Abstract and § on survey methodology] Abstract and survey results section: The headline quantitative claims (~20% oversharing of official ID; reduction of mistakes from ~15% to ~7%) are derived solely from stated disclosure intentions. No validation, correlation study, or behavioral measurement is reported that links these intentions to actual credential disclosure decisions once users hold an EUDI Wallet. This assumption is load-bearing for both the risk assessment and the effectiveness claim of the Credential Assistant.
Authors: We agree that the results reflect stated intentions rather than observed behavior in a deployed system. The EUDI Wallet is not yet available for real-world deployment studies, so behavioral validation is not feasible at this stage. We will add an explicit 'Limitations' section that discusses the intention-behavior gap, notes that the expert survey provides complementary grounding for the recommendations shown in the Credential Assistant, and frames the findings as indicative of potential privacy risks ahead of rollout. This revision will make the load-bearing assumption transparent without altering the reported survey results. revision: yes
-
Referee: [Abstract] Abstract: Concrete percentages are presented without sample size, recruitment method, statistical tests, confidence intervals, or error bars. This omission prevents assessment of the reliability and generalizability of the central empirical results.
Authors: We accept that the abstract should convey basic reliability information. In the revised version we will add the overall sample sizes for the user and expert surveys, the recruitment approach (online panel), and a brief statement that differences were evaluated with appropriate statistical tests (full details, including any confidence intervals or effect sizes, remain in the methods and results sections). Abstract length limits preclude full error bars, but the added context will allow readers to assess generalizability. revision: yes
Circularity Check
No circularity: purely empirical survey study
full rationale
The paper reports results from large-scale user and expert surveys on stated credential disclosure intentions and the effect of a proposed Credential Assistant. All quantitative claims (e.g., ~20% oversharing, reduction from ~15% to ~7% mistakes) are direct tabulations or comparisons of survey responses. There are no equations, derivations, fitted parameters, or self-citation chains that reduce any result to its own inputs by construction. The central claims rest on the external validity of self-reported intentions rather than on any internal definitional or predictive loop. This is a standard empirical user study whose derivation chain is self-contained.
Assumptions & free parameters
Cite this review
Pith. "Pith review of Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigations." pith.science (2026). https://pith.science/paper/JZWCPWMZ
@misc{pith2026260606354,
author = {Pith},
title = {Pith review of: Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigations},
year = {2026},
howpublished = {\url{https://pith.science/paper/JZWCPWMZ}},
note = {Machine review of arXiv:2606.06354}
}
read the original abstract
The European Union will introduce the EUDI Wallet by late 2026, which allows users to hold digital credentials (i.e., representations of physical official identity documents) on their devices. This will allow users to securely and privately disclose identity attributes to websites. Although such a system has many benefits, it also introduces risks caused by poor credential disclosure decisions. In this paper, we (i) conduct a large-scale survey on credential disclosure with users and experts and (ii) evaluate the effectiveness and feasibility of our Credential Assistant that displays expert recommendations and user opinions. Our results show that users are likely to overshare (e.g., ~20% of users disclosed their official ID to news websites). This indicates that users struggle to protect their privacy, which will impact the usability of the EUDI Wallet and lead to privacy violations, identity theft, and other abuses of leaked credentials. Finally, we show that our Credential Assistant significantly reduces users' credential disclosure mistakes from ~15% to ~7%. However, it does not fully eliminate poor credential disclosure decisions, indicating that stronger interventions may be necessary, especially for sensitive attributes.
Figures
Figures from the paper (15 more)
Reference graph
Works this paper leans on
-
[1]
Alessandro Acquisti, Idris Adjerid, Rebecca Balebako, Laura Brandimarte, Lor- rie Faith Cranor, Saranga Komanduri, Pedro Giovanni Leon, Norman Sadeh, Florian Schaub, Manya Sleeper, et al . 2017. Nudges for privacy and security: Understanding and assisting users’ choices online.ACM Computing Surveys (CSUR)50, 3 (2017), 1–41
2017
-
[2]
Alessandro Acquisti, Laura Brandimarte, and George Loewenstein. 2015. Privacy and human behavior in the age of information.Science347, 6221 (2015), 509–514
2015
-
[3]
Alessandro Acquisti, Leslie K John, and George Loewenstein. 2012. The impact of relative standards on the propensity to disclose.Journal of Marketing Research 49, 2 (2012), 160–174
2012
-
[4]
Alessandro Acquisti, Leslie K John, and George Loewenstein. 2013. What is privacy worth?The Journal of Legal Studies42, 2 (2013), 249–274. Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigations , ,
2013
-
[5]
Ayman Alarabiat and Isabel Ramos. 2019. The Delphi method in information systems research (2004-2017).Electronic Journal of Business Research Methods17, 2 (2019), pp86–99
2019
-
[6]
Bonnie Brinton Anderson, Jeffrey L Jenkins, Anthony Vance, C Brock Kirwan, and David Eargle. 2016. Your memory is working against you: How eye tracking and memory explain habituation to security warnings.Decision Support Systems 92 (2016), 3–13
2016
-
[7]
Arcom. 2024. Technical guidelines on age verification for the protection of persons under 18 from online pornography. https://www.arcom.fr/en/find- out-more/legal-area/legal-resources/technical-guidelines-age-verification- protection-persons-under-18-online-pornography
2024
-
[8]
Cybercrime Atlas. [n. d.]. Unmasking Cybercrime: Strengthening Digital Identity Verification against Deepfakes. https://reports.weforum.org/docs/WEF_Unmas king_Cybercrime_Strengthening_Digital_Identity_Verification_against_Deep fakes_2026.pdf
Show all 98 references
-
[9]
Tammy Bahmanziari, J Michael Pearson, and Leon Crosby. 2003. Is trust important in technology adoption? A policy capturing approach.Journal of Computer Information Systems43, 4 (2003), 46–54
2003
-
[10]
Phoebe E Bailey, Tarren Leon, Natalie C Ebner, Ahmed A Moustafa, and Gabrielle Weidemann. 2023. A meta-analysis of the weight of advice in decision-making. Current Psychology42, 28 (2023), 24516–24541
2023
-
[11]
Yakov Bart, Venkatesh Shankar, Fareena Sultan, and Glen L Urban. 2005. Are the drivers and role of online trust the same for all web sites and consumers? A large-scale exploratory empirical study.Journal of marketing69, 4 (2005), 133–152
2005
-
[12]
Ian Belton, George Wright, Aileen Sissons, Fergus Bolger, Megan M Crawford, Iain Hamlin, Courtney Taylor Browne L ¯uka, and Alexandrina Vasilichi. 2021. Delphi with feedback of rationales: How large can a Delphi group be such that participants are not overloaded, de-motivated,...
2021
-
[13]
Andrew Besmer, Jason Watson, and Heather Richter Lipford. 2010. The impact of social navigation on privacy policy configuration. InProceedings of the Sixth Symposium on Usable Privacy and Security. 1–10
2010
-
[14]
Laura Brandimarte, Alessandro Acquisti, and George Loewenstein. 2013. Mis- placed confidences: Privacy and the control paradox.Social psychological and personality science4, 3 (2013), 340–347
2013
-
[15]
Stefano Calboli and Bart Engelen. 2025. AI-enhanced nudging in public policy: why to worry and how to respond.Mind & Society(2025), 1–19
2025
-
[16]
Cloudflare. 2026. Domain categories. https://developers.cloudflare.com/cloudfla re-one/traffic-policies/domain-categories/
2026
-
[17]
European Comission. 2025. 2025 Consumer Conditions Scoreboard. https: //commission.europa.eu/strategy-and-policy/policies/consumers/consumer- protection-policy/key-consumer-data_en
2025
-
[18]
European Commission. 2023. EUDI Architecture and Reference Framework. https://eudi.dev/1.1.0/arf/
2023
-
[19]
European Commission. 2025. Commission Implementing Regulation (EU) 2025/848 of 6 May 2025 Laying Down Rules for the Application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as Regards the Regis- tration of Wallet-Relying Parties.Official Journal...
2025
-
[20]
European Commission. 2025. Commission Implementing Regulation (EU) 2025/848 of 6 May 2025 Laying Down Rules of the Application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as Regards the Regis- tration of Wallet-Relying Parties.Official Journal ...
2025
-
[21]
European Commission. 2025. Commission releases enhanced second version of the age-verification blueprint. https://digital-strategy.ec.europa.eu/en/news/co mmission-releases-enhanced-second-version-age-verification-blueprint
2025
-
[22]
European Commission. 2026. A digital ID and personal digital wallet for EU citizens, residents and businesses. https://ec.europa.eu/digital-building- blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/694487738/EU+Dig ital+Identity+Wallet+Home
2026
-
[23]
European Commission. 2026. European Digital Identity Wallet. https://eudi.dev /latest/
2026
-
[24]
European Commission. 2026. The European DigitalIdentity Regulation. https: //ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYW ALLET/pages/915931811/The+European+Digital+Identity+Regulation
2026
-
[25]
Dan Cvrcek, Marek Kumpost, Vashek Matyas, and George Danezis. 2006. A study on the value of location privacy. InProceedings of the 5th ACM workshop on Privacy in electronic society. 109–118
2006
-
[26]
Tobias Dienlin, Philipp K Masur, and Sabine Trepte. 2023. A longitudinal analysis of the privacy paradox.New Media & Society25, 5 (2023), 1043–1064
2023
-
[27]
Paul DiGioia and Paul Dourish. 2005. Social navigation as a model for usable security. InProceedings of the 2005 symposium on Usable privacy and security. 101–108
2005
-
[28]
Yana Dimova, Tom Van Goethem, and Wouter Joosen. 2023. Everybody’s Looking for SSOmething: A large-scale evaluation on the privacy of OAuth authentication on the web.Proceedings on Privacy Enhancing Technologies(2023)
2023
-
[29]
Serge Egelman, Adrienne Porter Felt, and David Wagner. 2013. Choice archi- tecture and smartphone privacy: There’s a price for that. InThe economics of information security and privacy. Springer, 211–236
2013
-
[30]
Serge Egelman, Janice Tsai, Lorrie Faith Cranor, and Alessandro Acquisti. 2009. Timing is everything? The effects of timing and placement of online privacy indicators. InProceedings of the SIGCHI Conference on Human Factors in Computing Systems. 319–328
2009
-
[31]
Pardis Emami Naeini, Martin Degeling, Lujo Bauer, Richard Chow, Lorrie Faith Cranor, Mohammad Reza Haghighat, and Heather Patterson. 2018. The influence of friends and experts on privacy decision making in IoT scenarios.Proceedings of the ACM on human-computer interaction2, CS...
2018
-
[32]
ENISA. 2021. Beware of the Sim Swapping Fraud! https://www.enisa.europa.eu/ news/enisa-news/beware-of-the-sim-swapping-fraud
2021
-
[33]
ENISA. 2021. Countering SIM-Swapping. https://www.enisa.europa.eu/publicat ions/countering-sim-swapping
2021
-
[34]
Epicenter.works. 2023. Open Letter to President and Vice Presidents of EU Member States. https://epicenter.works/fileadmin/import/open_letter_eidas_20 23-01_0.pdf Signed by 39 organizations
2023
-
[35]
Epicenter.works. 2023. Open Letter to Swedish Presidency and Permanent Repre- sentations of EU Member States. https://epicenter.works/fileadmin/import/cso- eidas-open_letter_2023.pdf Signed by 24 organizations
2023
-
[36]
Adrienne Porter Felt, Elizabeth Ha, Serge Egelman, Ariel Haney, Erika Chin, and David Wagner. 2012. Android permissions: User attention, comprehension, and behavior. InProceedings of the eighth symposium on usable privacy and security. 1–14
2012
-
[37]
Jeremy Goecks, W Keith Edwards, and Elizabeth D Mynatt. 2009. Challenges in supporting end-user privacy and security management with social navigation. InProceedings of the 5th Symposium on Usable Privacy and Security. 1–12
2009
-
[38]
Jeremy Goecks and Elizabeth D Mynatt. 2005. Supporting privacy management via community experience and expertise. InCommunities and Technologies 2005: Proceedings of the Second Communities and Technologies Conference, Milano 2005. Springer, 397–417
2005
-
[39]
Gov.UK. 2025. Online Safety Act: explainer. https://www.gov.uk/government/ publications/online-safety-act-explainer/online-safety-act-explainer
2025
-
[40]
Il-Horn Hann, Kai-Lung Hui, Tom Lee, and Ivan Png. 2002. Online information privacy: Measuring the cost-benefit trade-off.ICIS 2002 proceedings(2002), 1
2002
-
[41]
Nigel Harvey and Ilan Fischer. 1997. Taking advice: Accepting help, improving judgment, and sharing responsibility.Organizational behavior and human decision processes70, 2 (1997), 117–133
1997
-
[42]
Almut Herzog and Nahid Shahmehri. 2007. User help techniques for usable security. InProceedings of the 2007 symposium on Computer human interaction for the management of information technology. 11–es
2007
-
[43]
Joshua B Hurwitz. 2012. User choice, privacy sensitivity, and acceptance of personal information collection. InEuropean data protection: Coming of age. Springer, 295–312
2012
-
[44]
Consumers International. 2018. World Consumer Rights Day 2018 Briefing: e- commerce backgrounder. https://www.consumersinternational.org/media/154 916/e-commerce-overview-report.pdf
2018
-
[45]
Sirkka L Jarvenpaa, Noam Tractinsky, and Michael Vitale. 2000. Consumer trust in an Internet store.Information technology and management1, 1 (2000), 45–71
2000
-
[46]
Patrick Gage Kelley, Joanna Bresee, Lorrie Faith Cranor, and Robert W Reeder
-
[47]
nutrition label
A" nutrition label" for privacy. InProceedings of the 5th Symposium on Usable Privacy and Security. 1–12
-
[48]
Bart P Knijnenburg and Alfred Kobsa. 2013. Helping users with information dis- closure decisions: potential for adaptation. InProceedings of the 2013 international conference on Intelligent user interfaces. 407–416
2013
-
[49]
Bart P Knijnenburg and Alfred Kobsa. 2013. Making decisions about privacy: in- formation disclosure in context-aware recommender systems.ACM Transactions on Interactive Intelligent Systems (TiiS)3, 3 (2013), 1–23
2013
-
[50]
Lisa J Knoll, Jovita T Leung, Lucy Foulkes, and Sarah-Jayne Blakemore. 2017. Age-related differences in social influence on risk perception depend on the direction of influence.Journal of adolescence60 (2017), 53–63
2017
-
[51]
Spyros Kokolakis. 2017. Privacy attitudes and privacy behaviour: A review of current research on the privacy paradox phenomenon.Computers & security64 (2017), 122–134
2017
-
[52]
Maina Korir, Simon Parkin, and Paul Dunphy. 2022. An empirical study of a decentralized identity wallet: Usability, security, and perspectives on user control. InEighteenth symposium on usable privacy and security (SOUPS 2022). 195–211
2022
-
[53]
Kat Krol and Sören Preibusch. 2016. Control versus effort in privacy warnings for webforms. InProceedings of the 2016 ACM on Workshop on Privacy in the Electronic Society. 13–23
2016
-
[54]
Kevin Lee, Benjamin Kaiser, Jonathan Mayer, and Arvind Narayanan. 2020. An empirical study of wireless carrier authentication for {SIM} swaps. InSixteenth symposium on usable privacy and security (soups 2020). 61–79. , , Zingg et al
2020
-
[55]
Changjiang Li, Li Wang, Shouling Ji, Xuhong Zhang, Zhaohan Xi, Shanqing Guo, and Ting Wang. 2022. Seeing is living? rethinking the security of facial liveness verification in the deepfake era. In31st USENIX Security Symposium (USENIX Security 22). 2673–2690
2022
-
[56]
Bin Liu, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Aerin Zhang, Norman Sadeh, Yuvraj Agarwal, and Alessandro Acquisti
-
[57]
InTwelfth symposium on usable privacy and security (SOUPS 2016)
Follow my recommendations: A personalized privacy assistant for mobile app permissions. InTwelfth symposium on usable privacy and security (SOUPS 2016). 27–41
2016
-
[58]
Jamie Luguri and Lior Jacob Strahilevitz. 2021. Shining a light on dark patterns. Journal of Legal Analysis13, 1 (2021), 43–109
2021
-
[59]
Dominique Machuletz and Rainer Böhme. 2019. Multiple purposes, multiple prob- lems: A user study of consent dialogs after GDPR.arXiv preprint arXiv:1908.10048 (2019)
2019
-
[60]
Robin Martin, Antonis Gardikiotis, and Miles Hewstone. 2002. Levels of consensus and majority and minority influence.European Journal of Social Psychology32, 5 (2002), 645–665
2002
-
[61]
Arunesh Mathur, Gunes Acar, Michael J Friedman, Eli Lucherini, Jonathan Mayer, Marshini Chetty, and Arvind Narayanan. 2019. Dark patterns at scale: Findings from a crawl of 11K shopping websites.Proceedings of the ACM on human- computer interaction3, CSCW (2019), 1–32
2019
-
[62]
Arunesh Mathur, Mihir Kshirsagar, and Jonathan Mayer. 2021. What makes a dark pattern... dark? Design attributes, normative considerations, and measurement methods. InProceedings of the 2021 CHI conference on human factors in computing systems. 1–18
2021
-
[63]
Ethan A Meyers, Martin H Turpin, Michał Białek, Jonathan A Fugelsang, and Derek J Koehler. 2020. Inducing feelings of ignorance makes people more recep- tive to expert (economist) opinion.Judgment and Decision Making15, 6 (2020), 909–925
2020
-
[64]
Stuart Mills. 2022. Personalized nudging.Behavioural Public Policy6, 1 (2022), 150–159
2022
-
[65]
Sign in with... Privacy
Srivathsan G Morkonda, Sonia Chiasson, and Paul C van Oorschot. 2025. “Sign in with... Privacy”: Timely Disclosure of Privacy Differences among Web SSO Login Options.ACM Transactions on Privacy and Security28, 2 (2025), 1–28
2025
-
[66]
AP News. 2025. Supreme Court upholds Texas law aimed at blocking kids from seeing pornography online. https://apnews.com/article/supreme-court-porn- age-verification-texas-12a73197796fe8c4bef0d888259543cf
2025
-
[67]
Helen Nissenbaum. 2004. Privacy as contextual integrity.Wash. L. Rev.79 (2004), 119
2004
-
[68]
Patricia A Norberg, Daniel R Horne, and David A Horne. 2007. The privacy paradox: Personal information disclosure intentions versus behaviors.Journal of consumer affairs41, 1 (2007), 100–126
2007
-
[69]
Midas Nouwens, Ilaria Liccardi, Michael Veale, David Karger, and Lalana Kagal
-
[70]
InProceedings of the 2020 CHI conference on human factors in computing systems
Dark patterns after the GDPR: Scraping consent pop-ups and demonstrating their influence. InProceedings of the 2020 CHI conference on human factors in computing systems. 1–13
2020
-
[71]
Graham Overton, Ioannis Evangelidis, and Joachim Vosgerau. 2025. People Believe If 90% Prefer A over B, A Must Be Much Better than B. Are They Wrong? Journal of Consumer Research52, 1 (2025), 135–156
2025
-
[72]
Sameer Patil, Xinru Page, and Alfred Kobsa. 2011. With a little help from my friends: can social navigation inform interpersonal privacy preferences?. InPro- ceedings of the ACM 2011 conference on Computer supported cooperative work. 391–394
2011
-
[73]
Sören Preibusch, Kat Krol, and Alastair R Beresford. 2013. The privacy economics of voluntary over-disclosure in web forms. InThe Economics of Information Security and Privacy. Springer, 183–209
2013
-
[74]
Song Qi, Owen Footer, Colin F Camerer, and Dean Mobbs. 2018. A collabora- tor’s reputation can bias decisions and anxiety under uncertainty.Journal of Neuroscience38, 9 (2018), 2262–2269
2018
-
[75]
Qualtrics. 2022. Improve data quality by using a commitment request instead of attention checks. https://www.qualtrics.com/articles/strategy-research/attenti on-checks-and-data-quality/
2022
-
[76]
Christine Riefa. 2017. The challenge of protecting EU consumers in global online markets. (2017)
2017
-
[77]
Fuming Shih, Ilaria Liccardi, and Daniel Weitzner. 2015. Privacy tipping points in smartphones privacy preferences. InProceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems. 807–816
2015
-
[78]
Laurence Steinberg and Kathryn C Monahan. 2007. Age differences in resistance to peer influence.Developmental psychology43, 6 (2007), 1531
2007
-
[79]
European Data Protection Supervisor. 2025. TechDispatch: Digital Identity Wal- lets. https://www.edps.europa.eu/system/files/2025-12/25-12-16_techdispatch- digital-identity-wallet_en.pdf
2025
-
[80]
Monika Taddicken. 2014. The ‘privacy paradox’in the social web: The impact of privacy concerns, individual characteristics, and the perceived social relevance on different forms of self-disclosure.Journal of computer-mediated communication 19, 2 (2014), 248–273
2014
-
[81]
Joshua Tan, Khanh Nguyen, Michael Theodorides, Heidi Negrón-Arroyo, Christo- pher Thompson, Serge Egelman, and David Wagner. 2014. The effect of developer- specified explanations for permission requests on smartphone user behavior. In Proceedings of the SIGCHI Conference on Hu...
2014
-
[82]
Moritz Teuschel, Daniela Pöhn, Michael Grabatin, Felix Dietz, Wolfgang Hommel, and Florian Alt. 2023. ’Don’t Annoy Me With Privacy Decisions!’—Designing Privacy-Preserving User Interfaces for SSI Wallets on Smartphones.IEEE Access 11 (2023), 131814–131835
2023
-
[83]
Eran Toch. 2014. Crowdsourcing privacy preferences in context-aware applica- tions.Personal and ubiquitous computing18, 1 (2014), 129–141
2014
-
[84]
Van Hong Tran, Aarushi Mehrotra, Ranya Sharma, Marshini Chetty, Nick Feam- ster, Jens Frankenreiter, and Lior Strahilevitz. 2025. Dark Patterns in the Opt-Out Process and Compliance with the California Consumer Privacy Act (CCPA). In Proceedings of the 2025 CHI Conference on H...
2025
-
[85]
European Union. 2024. Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 Amending Regulation (EU) No 910/2014 as Regards Establishing the European Digital Identity Framework.Official Journal of the European UnionL 2024/1183 (2024), 1–56. h...
2024
-
[86]
Anthony Vance, David Eargle, Jeffrey L Jenkins, C Brock Kirwan, and Bonnie Brin- ton Anderson. 2019. The fog of warnings: how non-essential notifications blur with security warnings. InFifteenth Symposium on Usable Privacy and Security (SOUPS 2019). 407–420
2019
-
[87]
Anthony Vance, Jeffrey L Jenkins, Bonnie Brinton Anderson, Daniel K Bjornn, and C Brock Kirwan. 2018. Tuning out security warnings.MIS Quarterly42, 2 (2018), 355–380
2018
-
[88]
W3C. 2026. Verifiable Credentials Use Cases. https://www.w3.org/TR/vc-use- cases/
2026
-
[89]
Jinping Wang, Maria D Molina, and S Shyam Sundar. 2020. When expert recom- mendation contradicts peer opinion: Relative social influence of valence, group identity and artificial intelligence.Computers in Human Behavior107 (2020), 106278
2020
-
[90]
Yang Wang, Pedro Giovanni Leon, Alessandro Acquisti, Lorrie Faith Cranor, Alain Forget, and Norman Sadeh. 2014. A field trial of privacy nudges for facebook. InProceedings of the SIGCHI conference on human factors in computing systems. 2367–2376
2014
-
[91]
Rick Wash and Molly M Cooper. 2018. Who provides phishing training? facts, stories, and people like me. InProceedings of the 2018 chi conference on human factors in computing systems. 1–12
2018
-
[92]
Lilei Zheng, Ying Zhang, and Vrizlynn LL Thing. 2019. A survey on image tam- pering and its detection in real-world photos.Journal of Visual Communication and Image Representation58 (2019), 380–399
2019
-
[93]
Zheng Zheng, Qian Wang, and Cong Wang. 2023. Spoofing attacks and anti- spoofing methods for face authentication over smartphones.IEEE Communica- tions Magazine61, 12 (2023), 213–219. Credential Disclosure in (EU) Digital Identity Wallets: Privacy Risks and Practical Mitigatio...
2023
-
[94]
Users of the EUDI will need to make complex de- cisions about when to disclose their credentials and when not to
The EUDI is already under development, and it will be de- ployed in 2026. Users of the EUDI will need to make complex de- cisions about when to disclose their credentials and when not to. Prior research has shown that making constant decisions about privacy is challenging for ...
2026
-
[95]
We mitigate this risk by providing a fair assessment of a specific aspect of the EUDI and also discussing its benefits
A risk from a paper like this would be that it reduces trust in the EUDI, which could harm lawmakers developing the system. We mitigate this risk by providing a fair assessment of a specific aspect of the EUDI and also discussing its benefits. Furthermore, we evaluate a potent...
-
[96]
No deception was deployed, and thus, all participants gave informed consent
Prolific participants were informed about the goals and con- tent of the survey/user study through a consent form. No deception was deployed, and thus, all participants gave informed consent. Participants were compensated for their work at a rate of ∼$6.7 for a 25 min survey, ...
-
[97]
No deception was deployed, and thus, all experts gave informed consent
Expert participants were informed about the goals and content of the survey through a consent form. No deception was deployed, and thus, all experts gave informed consent. We did not compensate experts; however, we offered to keep them updated on the findings of our research. ...
-
[98]
Not Fully Comfortable
Our research did not deal with any topics that could harm the research team. As all user studies were based on solid ethical foundations with IRB approval, we believe there is no risk to the research team from this work. B Ground Truth Details To test whether users make creden...
Reviewed June 28, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.