Earlier quoted context omitted.
Verification apps should check the issuer. But you can issue and sign your own vaccine codes trivially. Some apps will go a step further to check that the issuer is “trusted.” For example, there is a good list of issuers considered trusted here: https://github.com/the-commons-project/vci-directory/blob/ma... The most popular reader app I know of will mark issuers that are not on this list as “Partially-verified.” I’m…
This seems odd given that EU+CH did implement things properly wrt to cryto and trusted certs, but yes I guess there's a possibility that UK messed it up :)
I assumed we were just talking about SHC, but UK could do something outside that standard. These all look the same, like a QR code, but the underlying structure could be different. I believe NY’s Excelsior Pass is also doing something slightly different, although I won’t claim it has anything to do with the signing aspect.