...so I'll return the time to you.
Well, I'm still the governmental co-chair for the Taiwan Open Government National Action Plan Taskforce.
The supporting work was already and always done by the NDC. In fact, when NDC first formed, it was specifically tasked to do this kind of participation. The Join platform, for example, despite being a digital platform, is still at the NDC; it's not MoDA.
The NDC still maintains the entire infrastructure for participation. Now, specifically on the digital realm, when it comes to, as I mentioned, open data, data altruism, and so on, I'm still the governmental co-chair.
Awesome. Thank you.
Awesome.
Thank you. I think it was very well received. A lot of press coverage.
How shall we proceed?
I use TW FidO dozens of time a day.
Certainly, and we have the head of the administration for digital industries in charge of digital transformation, the cybersecurity industry, and the adoption of cybersecurity in industries.
I'm sure that you will have many in common. And the head of Democracy Network, also our account representative of W3C. We just joined yesterday the Decentralized ID Working Group.
Yeah, we're putting a lot of bets on the DIDs. Taiwan is a unique situation internationally. We want to interoperate actively with the eIDAS or as many identity centers as possible, but we cannot join the EU very quickly. [laughs]
Just like certain other countries that cannot quickly join the EU, we're looking at ways to tap into the common infrastructure, so that we can share some of the underlying tech. That's why it's called the Department of Democracy Network, not the Department of International Cooperation.
Of course. It's all in Creative Commons. Everything we do are in the commons.
Can we just say "Passkeys, not passwords"?
Yeah, like memorizing 52 English words.
Card-carrying cypherpunk, here.
It's everywhere.
Taiwan's criminals, scam and phishing is very developed.
A very strong criminal activity, so without FIDO support, the administration for digital industries, if just relying on server hygiene awareness lectures alone, is a lost cause.
I explained this to our President. I said, "It's a measure for defense." We change the battlefield so it works better for the defense side, to make the attackers pay more. Whereas the old battleground, the defenders have to pay more.
You can take out the Captchas. The passwords, when it's eliminated, and with a good UX, the Captchas also goes away, which is a major usability and accessibility gain.
Our new services all use Cloudflare Turnstile, which uses passkey in lieu of "Identify this car" or whatever Captcha.
Great. We recently invited Muan, who used to be head of accessibility at GitHub, a Taiwanese, to join our National Institute of Cybersecurity. She will be heading a team with the digital service department for the UX of systems such as our upcoming 6000.gov.tw. I'm sure that we can work together.
We're very passionate about it.
Excellent. I'll refer the experts to you.
We've got 20 national languages, including sign language, so we're in a very unique...
Yeah.
SMS OTP is super unfriendly to adult people.
Risky too.
Like worst of both worlds [laughs]
Not for Taiwanese people. [laughs]
During the whole pandemic, we get consistent...
...smished. In fact, we launched a g0v.tw URL shortener specifically to counter smishing.
I think my GitHub account is already a passkey.
I don't use passwords to log in anymore. It's just touch ID.
Excellent.
Awesome. Anything you'd like to add?
Anything further, Jang Hwa?
Sure. I'm looking forward to it.
As I mentioned, I think accessibility and usability will be our main goal this year. To comprehensively counter against SMS phishing and phishing in general, if we want to say, "OK, pass keys, no passwords," we better follow through with that.
For example, during the pandemic, the civic hack community invented a novel way of a privacy-enhancing technology where you just scan a QR code, and it sends an SMS, a ring of code. Without divulging your mobile phone number to the venue, you can still get social notifications. It's more private than many other designs.
The thing with that is, of course, people living with blindness cannot scan a QR code, [laughs] so we need to design with an extra amount of care that says, "OK, they can still stamp their way in." If they stamp their way in, you better put it in a kind of ballot box so that people queuing after them don't see their phone number and so on.
It's not just usability for the pass key scenario, but also for people who have not yet migrated to pass key. They must feel that there is a smooth transition for them, especially if they have accessibility needs. Once we achieve that, then it will be much easier for us to tell the industry you now have to convert. That would be my main objective this year.
Excellent. Anything from our web3 department?
It was mainly the idea of some web3 wallets already use, for example, the Google login. The Google login can also, like in Kukai, that app, the rule of intra rules as a digital signature that can be used to see a threshold key for the Web3 part of the world.
Of course, the Google sign in flow itself has been revamped by the passkeys, so some way to bridge these two together so that people feel natural, like I'm not creating specifically a public key pair for Polygon, for Tezos, and things like that. Rather, the wallet lives on the same passkey device as I usually use. That would be very useful.
In Taiwan, we use the TW FidO to also sign official document through the KCS, like the old standard. We have to support both interfaces within the same app. For some circumstances, the user gets confused, like, "Am I signing or am I authenticating?" and so on.
A much more streamlined view for those di identity parts and the signing part will help everybody involved because the Web3 is really just a bunch of people signing documents. There's no [laughs] encryption in cryptocurrency.
It's just digital signatures.