mashbean 黃豆泥
mashbean.eth
豆泥的以太坊地址:mashbean.eth
狀態:未簽名
0x930eb3c429bdca28e4d59e914e9983b1e0ccc8dce771a7903037fc9a87e45fd3
已簽名表示這篇文章已建立獨特的身分證字號(內容雜湊,contentHash)並且由豆泥簽署認證,簽署是採用以太坊區塊鏈的豆泥專用地址(signer.mashbean.eth)。只要內容一經修改,就會需要重新驗證換發新的身分證字號。但豆泥不是每天都在公所上班,所以偶爾會慢一點認證。
完成數位皮夾「監測儀表板」與「請收下卡片」,意外發現官方羊羊卡、多莉卡、薯條卡?XD
暨完成可以一鍵部署的「請出示皮夾」之後,也順手開發了「請收下卡片」的發行模組,同樣可以一鍵部署,並且與你的既有資料庫聯動,同樣因為可以零嚕 Cloudflare,建置成本為 0。
本來有點興趣缺缺,懶得做「請收下皮夾」,因為這會牽涉到發行、信任清單、撤銷列表等等的模組,而且數發部官方的「數位憑證皮夾」 App 在沒有申請正式介接的情況下,是吃不到民間自行發行的卡片的,所以有點麻煩。(有備而來 App 倒是原生就可以吃,不過還在考慮會不會正式上線)
不過因為有臉友來敲,很真誠地想要解決一些職安服務的困難問題,我雖然建議他直接洽詢皮夾官方客服(這本來就是他們的工作!),不過也好奇要發卡的話,實務上需要多少成本。結果驗證下來,不算工錢(也不算 AI token)的話,可以壓到 0 元,就順手開源服務了。
不過這倒不是今天要分享的,走完這一輪,我發現官方釋出的資訊藏在各種地方,官網也沒有把所有我認為該揭露、該整合的資訊匯聚在一起,所以我就順手做完了,我做了一個:
數位憑證皮夾生態系「監測儀表板」
是不是可以得黑客松獎項了XD
這個儀表板日更,紀錄了API 健康度、信任清單、區塊鏈上的信任清單同步、撤銷清單,以及 Github 更新的時間還有回 Issue 的狀態。
*
先講有趣的,做完以後有一些有趣的發現。
撤銷清單透露了非常多有意思的資訊。
比如三大電信的門號驗證卡都有大量的撤銷紀錄,冠軍是台哥大,已經撤銷了 9,536 張卡片,中華加上遠傳只有台哥的一半不到,因此我們可以逆推,台哥大發卡量有多大(甚至月租卡也有發)。
駕照驗證卡抓不到撤銷清單。
然後意外抓到這咖股份有限公司(Jcard)發了一堆中新興村花漾卡,有門卡、會員卡、集點卡,不知道在玩什麼花樣?Jcard 背後有宏碁投資,感覺是數位皮夾特意找了實體場域來合作(?),然後資服業者是 Jcard。不過撤銷數字為 0,猜測還沒有正式服務上線。
雖然我對 Jcard 的印象只有沒什麼人在買的元宇宙 NFT,不過現在還有人在討論 NFT 嗎?
此外從撤銷清單可以發現,許多大學有在數位皮夾支援學位證書卡,包含台大、成大、台科大。我的母校中國醫大竟然也有發教職員數位證件卡,中國醫大何時這麼先進了我都不知道,真棒!
還有我沒什麼在關注,但可能已經上線的卡片還有工商憑證、教育部的助學補助系統登入識別證、中華電信企業分公司訪客卡。
最後是一批有點荒謬,且我覺得不應該存在在撤銷清單上的卡片,應該就是測試卡片,有羊羊卡(sheep)、多利卡(dolly)、餅乾卡(cookies)、薯條卡?(fires)。
數位憑證皮夾不是有測試版的沙盒系統嗎?為何這些看起來好笑的測試卡會出現在「正式」系統的撤銷清單上面,總感覺應該清一清。即便撤銷清單沒有公開(雖然我覺得應該要),且放在正式撤銷清單上無傷大雅,不過觀感上有點礙虐(台語)。
不然就很像軟體工程師犯了不小心把 STAGING 與 PROD 混在一起的低級錯誤。對…我自己就是從隕石系開發開始上手的,曾經也錯把 PROD 當成 STAGING 部署過,害我的夥伴渾身冒汗,也出過包,誰沒出過包。
且我記得數位皮夾有 IV&V(獨立驗證與確效)的廠商,現在不知道還有沒有,這上線前應該要抓龍一下?
*
再來來點認真的。
想了想這些公開資訊竟然還沒有一個公開網頁來呈現,我有點訝異,看了看反正不難,就順手把整包做掉了。
我希望官方網頁最好也要有,因為這是數位信任中,除了機器可驗證性,人類的可讀性很重要的一環,至少這些公開資料要部署在人類可讀的 gov . tw 上面。
比如說,官方信任清單中發行者的 did:key 金鑰需要完整呈現。因為皮夾在讀取發行者與驗證者互動的過程,需要知道互動對象是不是真的,目前官方皮夾 App 是用內部鎖住的方式來與這些「白名單」互動。
不過如果未來要做到跨國憑證的互相驗證,這種白名單制的維護成本就會數量級上升。隨便舉一個例子,歐盟明年所有會員國的皮夾就要上路了,而且他們的信任清單也都會公開(跟著既有的電子簽章),如果台灣的皮夾要吃歐盟的「請出示皮夾」,現在實務上是會出現警示,更不用說拿不到對方的卡片。
此外有了信任清單,撤銷清單就會跟著出現。比如你原本有駕照驗證卡,但因為酒駕被吊銷執照,撤銷清單上面就會出現這筆作廢的紀錄。撤銷清單很重要,因為驗證者不可能只從你的皮夾就相信你的駕照(證明曾經持有,不代表現在有效),還需要多一道確認有沒有撤銷的手續,租車業者才敢租車給你。
不過官方其實沒公布撤銷清單,沒有任何地方公告它們,我是從已簽發的卡片裡挖出來的。具體做法是每天走一次官方信任清單,向每個發行者索取它的 OID4VCI metadata 取得卡種,再逐一讀出每個卡種背後的撤銷清單並清點。
最後集成一個儀表板,夠貼心了吧。
所以 API 健康度、信任清單、撤銷清單是一套三板斧全家桶,三個東西一次揭露才會完整。另外,數發部目前的信任清單是有上區塊鏈保存的喔,目前只有上在 Arbitrum。儀表板也有去比對區塊鏈與官方中心化儲存的信任清單有沒有一致。
不過我的個人建議是,現在以太坊(Ethereum)主網已經很便宜了,其實不需要上在第二層的 Arbitrum,而且 EVM 一定相容,遷移過去只需要動動手指,我甚至可以自己寫一個智慧合約去抓官方資料,自己部署鏈上信任清單,也不需要花多少錢,但這樣就失去了「官方營運」的意義了。
*
大概就是這樣,做了儀表板以後有了許多有趣的發現。
最後是也放了監測 issue 的區塊。原因是想知道官方什麼時候會回應,因為真的有一些資安上的風險需要修正XD,不到很 critical,但不修掉心裡會不踏實,畢竟選擇性揭露現在不完全算真的選擇性揭露,感謝 Agent 抓出來,我自己也沒看出來。(詳情可以看 issue)
這算是公共程式精神的一次具體測試,要算是公共程式,必須真的有人維護原始碼,不然就是掛羊頭賣狗肉。
話說個人寫的 code 其實沒辦法貢獻到現在數發部的公共程式平台,因為資格上必須是政府機關、或者收受政府委託、補助的廠商,才能夠貢獻。所以我連登都登不進去。
本來想說,授權就使用有感染風格的 copyleft GPL 授權,在公共程式平台使用 GPL 不知道會發生什麼事,本來是如此期待的說。
今天大概就是這樣,補完了「免費一鍵發行卡片」、「監測儀表板」的功能,整個數位皮夾發現之旅就這樣走完了,我們下次見。
*
I finished the digital wallet’s “Monitoring Dashboard” and “Please Accept This Card” — and accidentally found official Sheep cards, Dolly cards, Fries cards? XD
After finishing the one-click-deployable “Please Present Your Wallet,” I also casually built the issuing module for “Please Accept This Card.” It, too, can be deployed with one click, hooks into your existing database, and — because it also runs entirely on Cloudflare — costs zero to set up.
Honestly I wasn’t that interested at first; I couldn’t be bothered to build the “Please Accept Your Wallet” side, because it drags in modules for issuance, trust lists, revocation lists, and so on. And the Ministry of Digital Affairs’ official “Digital Credential Wallet” app can’t take cards privately issued by third parties unless you’ve applied for a formal integration, which makes it a bit of a hassle. (The Bonds app, on the other hand, can take them natively — though I’m still weighing whether it’ll formally launch.)
But a Facebook friend reached out, sincerely wanting to solve some genuine occupational-safety-service problems. Even though I suggested he just contact the wallet’s official customer support directly (that’s literally their job!), I was also curious how much it would actually cost, in practice, to issue cards. It turned out that, not counting labor (and not counting AI tokens), you can push it down to zero dollars — so I just open-sourced the service on the side.
That’s not actually what I want to share today, though. Having gone through the whole cycle, I realized the information the government releases is tucked away in all sorts of places, and even the official site doesn’t bring together everything I think should be disclosed and integrated in one spot. So I just went ahead and built one. I made a:
Digital Credential Wallet Ecosystem “Monitoring Dashboard”
Could this win a hackathon prize? XD
The dashboard updates daily, tracking API health, the trust list, the on-chain synchronization of the trust list, the revocation lists, plus the last GitHub update times and the status of Issue responses.
*
Let me start with the fun stuff — I made some interesting discoveries once it was done.
The revocation lists reveal a remarkable amount of interesting information.
For instance, the phone-number verification cards from the three big telecoms all have large numbers of revocation records. The champion is Taiwan Mobile, which has already revoked 9,536 cards; Chunghwa and FarEasTone combined don’t even add up to half of Taiwan Mobile’s total. From this we can reverse-engineer just how large Taiwan Mobile’s issuance volume is (they even issue cards for monthly-plan numbers).
The driver’s-license verification card yields no reachable revocation list.
Then I unexpectedly caught this outfit, Jcard (a limited company), which had issued a bunch of “Zhongxinxing Village Blossom” cards — access cards, membership cards, loyalty-stamp cards. No idea what game they’re playing. Jcard is backed by Acer investment, and it feels like the digital wallet deliberately sought out a physical venue to partner with (?), with Jcard as the IT service provider. But the revocation count is 0, so my guess is the service hasn’t formally launched yet.
My only impression of Jcard is their metaverse NFTs that basically nobody was buying — but is anyone even still talking about NFTs these days?
Beyond that, the revocation lists show that many universities support diploma/degree-certificate cards in the digital wallet, including NTU, NCKU, and NTUST. Even my alma mater, China Medical University, turns out to issue digital staff-ID cards. When did China Medical get this advanced? I had no idea. Nice!
There are also cards I haven’t been paying much attention to but that may already be live: the business certificate (工商憑證), the Ministry of Education’s student-aid system login ID, and Chunghwa Telecom’s enterprise-branch visitor card.
And finally there’s a batch that’s a little absurd — and that I don’t think should be on the revocation list at all. These must be test cards: there’s a Sheep card (sheep), a Dolly card (dolly), a Cookies card (cookies), and a Fries card? (fires). (Dolly, of course, being the cloned sheep — cute.)
Doesn’t the Digital Credential Wallet have a sandbox test environment? Why would these silly-looking test cards show up on the “production” system’s revocation list? It really feels like they should be cleaned out. Even though the revocation list isn’t public (though I think it should be), and having them sit on the production revocation list is harmless, it’s a bit off-putting (that’s Taiwanese: 礙虐) all the same.
Otherwise it looks a lot like a software engineer who made the rookie mistake of accidentally mixing STAGING and PROD together. Yeah… I myself came up through meteor-driven, cowboy-coding development. I’ve deployed to PROD thinking it was STAGING before, leaving my teammate drenched in cold sweat, and I’ve shipped bugs too. Who hasn’t shipped a bug?
Also, I recall the digital wallet has an IV&V (Independent Verification & Validation) vendor — no idea whether that’s still the case — and this really should’ve gotten a thorough going-over (that’s Taiwanese: 抓龍, “dragon-catching,” i.e. a proper once-over) before launch.
*
Now for some serious stuff.
Thinking about it, I was honestly a bit surprised that this public information still didn’t have a single public web page presenting it. I took a look, figured it wasn’t hard anyway, and just knocked out the whole package.
I really hope the official site has this too, because in digital trust — beyond machine-verifiability — human readability is a crucial piece. At the very least, this public data ought to be deployed somewhere human-readable on a gov.tw domain.
For example, the did:key public keys of the issuers in the official trust list need to be presented in full. Because when the wallet reads the interaction between an issuer and a verifier, it needs to know whether the counterparty is genuine. Right now the official wallet app interacts with these “whitelisted” parties in an internally locked-down way.
But if we ever want to achieve cross-border mutual verification of credentials, the maintenance cost of this whitelist model will climb by orders of magnitude. To pick an example at random: next year the wallets of every EU member state go live, and their trust lists will all be public (following the existing electronic-signature framework). If a Taiwanese wallet wanted to accept an EU “Please Present Your Wallet,” in practice today you’d get a warning — never mind not being able to receive the other party’s card at all.
On top of that, once you have a trust list, the revocation list follows. Say you had a driver’s-license verification card, but your license got revoked for drunk driving — that voided record then shows up on the revocation list. The revocation list is important, because a verifier can’t just trust your driver’s license from your wallet alone (proving you once held it doesn’t mean it’s currently valid); they need one more step to confirm it hasn’t been revoked, before a car-rental company will dare rent to you.
But the government actually doesn’t publish the revocation lists — there’s nowhere they’re announced. I dug them out of already-issued cards. Concretely, the method is: walk the official trust list once a day, request each issuer’s OID4VCI metadata to get its card types, then read out and tally the revocation list behind each card type one by one.
Finally I pulled it all together into a dashboard. Thoughtful enough, right?
So API health, the trust list, and the revocation list are a three-pronged combo meal — all three have to be disclosed together for the picture to be complete. Also, the Ministry of Digital Affairs’ current trust list is actually preserved on a blockchain — currently only on Arbitrum. The dashboard also compares whether the on-chain trust list matches the official centralized store.
That said, my personal suggestion is: Ethereum mainnet is already very cheap now, so there’s really no need to put this on the second-layer Arbitrum — and since it’s EVM, it’s guaranteed compatible; migrating over is just a flick of the fingers. I could even write my own smart contract to pull the official data and deploy an on-chain trust list myself, and it wouldn’t cost much — but then it’d lose the whole point of being “officially operated.”
*
That’s roughly it — building the dashboard turned up a lot of interesting discoveries.
Last, I also added a section for monitoring Issues. The reason is I want to know when the government will respond, because there really are some security risks that need fixing XD — nothing very critical, but leaving them unfixed leaves me a little uneasy. After all, the selective disclosure right now doesn’t fully count as genuine selective disclosure. Thanks to the Agent for catching it; I hadn’t spotted it myself either. (See the issue for details.)
This counts as one concrete test of the public-code spirit: to really count as public code, someone actually has to maintain the source — otherwise it’s just bait and switch (掛羊頭賣狗肉, “hang out a sheep’s head but sell dog meat”).
Speaking of which, code written by an individual can’t actually be contributed to the Ministry of Digital Affairs’ current public-code platform, because to be eligible you have to be a government agency, or a vendor commissioned or subsidized by the government. So I can’t even log in.
I’d originally thought I’d license it under the infectious copyleft GPL and see what would happen using GPL on the public-code platform. That was the plan I was looking forward to.
That’s about it for today. I’ve now rounded out the “free one-click card issuance” and “monitoring dashboard” features, and the whole digital-wallet exploration journey is complete. See you next time.
*