Apple Wallet passes use CMS signatures. you're right that only hashes are signed. but Apple requires an official Developer certificate ($99/year) with a private key that can't be exposed to browsers. for true privacy, each user would need their own cert. and defeats the "free" goal. and if you have a dev certificate it's trivial to generate one on your own machine.
gruez|2 months ago
Why can't the browser send the hash to the server for signing?
alentodorov|2 months ago
saagarjha|2 months ago
alentodorov|2 months ago
the_lucifer|2 months ago