Typically better because the phone is locked & the data is stored within the SE, which puts it out of reach for most people. The proposal (not sure if adopted) was also that these have extremely short expiration times (like on the order of a month) so that you need to resign the credentials through the government body regularly. This further limits the damage - just report the device is stolen. This should put it on the revocation list & will prevent the government issuer from reissuing the ID (this also keeps the revocation lists shorter as they can be pruned).
That raises an interesting new dimension: the ability to revoke someone's ID remotely (if there is no physical version) by twiddling a few bits in a server somewhere.
Wouldn't someone be able to do that now if they were able to gain access to the DMV/police/state database? You might have a physical ID but if they called it in it could be flagged as revoked or something else.
I think you would still at least have a shot in hell since that physical id is in-hand. Maybe it could be flagged as revoked but the cops would have alternative ways of checking it out or at the least visually inspecting it and deciding you are at least who you say you are on the ID. This versus your soft-id just disappearing.
Your ID wouldn't disappear from your wallet, though. It would probably just show an alert. Either way, the cops would have to check the validity of your license/ID. They don't just accept IDs at face value unless they're only verifying something like your age.
> That raises an interesting new dimension: the ability to revoke someone’s ID remotely (if there is no physical version) by twiddling a few bits in a server somewhere.
For most critical uses, you can do that now, since IDs are electronically verified against a central server. For incidental uses, sure, an unverified physical ID works.
Of course, using a third-party ID storage system on which you have an account increases the threat surface to which that threat applies, since there are more places where compromise can occur with the ability to kill your usable ID that way (your account, the storage system, the ID issuers systems vs. just the first of those.)