Remote-onboarding attack types
Classify the attack before selecting the control. Presentation-attack detection does not stop every injection; document validation does not establish ownership; and strong onboarding does not protect a weak recovery channel.
Threat techniques change faster than static certification cycles. Maintain a current threat model and confirm which attack classes a provider's evidence actually covers.
For: fraud, security engineering, identity operations and vendor-assurance teams. This is independent information, not legal, compliance or security advice.
Attack and primary control
| Attack | Control family | Residual issue |
|---|---|---|
| Forged/altered document | Document/chip validation | Fraudulently issued or stolen genuine evidence |
| Photo/replay/mask | PAD and capture controls | Untested artefacts and thresholds |
| Digital injection/deepfake | Capture integrity, injection detection, session binding | Compromised device or new bypass |
| Synthetic identity | Attribute consistency, duplication and monitoring | Real fragments and slow cultivation |
| Account recovery takeover | Risk-based recovery and re-proofing | Support social engineering |
Process attacks
Attackers target retry rules, queue boundaries, support staff, referral links and manual overrides. Include business logic and people in testing rather than limiting review to the biometric model.
Test cases
- Repeated documents, faces, devices and addresses.
- Modified media through supported and unsupported capture paths.
- Session replay, swapping and automation.
- Reviewer disagreement and escalation.
- Recovery immediately after onboarding.
- Vendor outage and degraded-mode pressure.
Living threat model
Assign an owner, evidence source, control, monitoring signal and residual risk to every material threat. Revisit after vendor, SDK, document, channel, threshold or attacker change.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing