Does anyone have more knowledge about how they use the digital identities in Estonia? It sounds like everybody has a personal key that they use for signing stuff. Is that correct? How is it distributed? If so, that's the most fascinating part of the article to me.
We all have either a credit-card sized chip card with our keys or a similar mobile SIM card which uses SIM applications. Using those we can do basically everything online, be it authentication to private or public services (using PIN1), or digital signatures (using PIN2).
Is there much concern in Estonia about the potential privacy leaks? We also now have digital ID cards here in Portugal, but its use is for now fairly limited - you can use them to log in to some governmental sites (like the IRS), but no banks or other sites have adopted them.
I read on Wikipedia that some of your newspapers have started requiring it to comment on their articles, and I'd be wary of such developments, since they're so easy to justify (even to oneself) and to accept (since it makes authentication even easier than remembering password).
How do you deal with the fact that most sites would like to have your unique, cross-site identifiable key fingerprint?
Web commentary columns of some Estonian newspapers, most notably Eesti Päevaleht, used to support ID-card based authentication for comments. This approach caused some controversy in the internet community.[3]
People are too lazy to use ID cards for something like commenting. More importantly though, most Estonian comments are anonymous with people attacking each other or politicians or whoever they like. Nobody wants to comment using their real identity.