Digital License Privacy & Disclosure Inspector ISO/IEC 18013-5

Auditing Apple Wallet & Google Wallet mdoc reader interrogation vectors

ISO/IEC 18013-5 mdoc

1. Verification Scenario

Target context

2. Wallet Platform & Protocol

Cryptographically hide unrequested fields via signed attribute digests

Enforce reader certificate trust chain & rotating MAC addresses

Audit Diagnostic Engine

Active Specification ISO/IEC 18013-5 mdoc Reader Authentication
Hardware Keystore Apple Secure Enclave (EAL6+)
Channel Handshake NFC Engagement -> BLE Data Transfer
Persistent Device Tracker Risk Zero (Ephemeral Key Agreement)
Calculated Exposure Risk
Low Score: 92/100 (Hardened)
Exposed / Total Attributes
1 / 6

Optimal privacy preservation active. Using ISO/IEC 18013-5 signed attribute tokens, the verifier only receives a cryptographic boolean confirmation that you are 21 or older. Your legal name, physical address, and exact date of birth remain sealed in hardware storage.

BLE Sniffing Vector: Protected

Data Payload Transmitted Over Proximity Channel

Payload encoding: CBOR / mdoc
Terminal Handshake & Verification Frame Session ID: 0x9F4C...B82
// 18013-5 DeviceEngagement
> NFC Engagement: Handover Select -> BLE Central (UUID: 00000005-0000-1000-8000-00805F9B34FB)
> ReaderAuth: Terminal Cert Verified (CA: AAMVA Trust Root)
> Requested Elements: [age_over_21]
> DeviceResponse: MSO Digest Verified, IssuerSignature Valid, Blinding Proof: Passed

Why Digital License Privacy Matters

As reported by technology analysts and security researchers, digital IDs in Apple Wallet and Google Wallet leverage standard ISO/IEC 18013-5 mdoc profiles. Unlike handing an officer or a bouncer a physical plastic card—revealing your home address, exact birthdate, organ donor status, and driver license number at once—the digital mdoc architecture allows selective disclosure.

However, privacy risks remain if untrusted reader hardware queries unauthorized namespaces, or if users present credentials without biometric consent. Furthermore, unauthenticated BLE broadcast channels can theoretically allow commercial foot-traffic tracking unless ephemeral MAC rotation and strict mutual reader authentication are enforced.

Privacy audit downloaded successfully
Enjoy this tool? Build your own with Super