A Threat Model for Digital Identity Wallet in the age of eIDAS 2.0

June 27, 2026
3:10 PM
Golden Wave 2

About this session

Digital identity wallets, introduced under eIDAS 2.0, enable decentralized and user-controlled management of personal data across online services. However, as a new model with new entities and interaction patterns, their security and privacy risks remain insufficiently understood. This session presents a structured threat modeling using STRIDE and LINDDUN, and outlines potential threats with key mitigation strategies while inviting community feedback to identify missing threats and mitigations.

About the speaker

About the speakers

Simone is the W3C Security Lead. He has 20+ years of expertise in red/blue Teaming and Web security. He has spoken at OWASP, TEDx, and other events and authored Attacking and Exploiting Modern Web Applications.

Speaker

Speakers

Simone Onofri
Security Lead, W3C
Amir Sharif
Researcher, Fondazione Bruno Kessler
Zahra Ebadi Ansaroudi
Researcher, Fondazione Bruno Kessler