Sort:  

So basically, you need his phone right? This is somehow the same way you steal someones wallet file and then brute force it. Like here on Steem too...

Am I understanding what you mean correctly?

Either way, I agree that if having an ID like that allows you to just execute those kind of actions, then it can be too much of a risk. Maybe multi-sig is somehow part of a better solution to Civic. Also, having 2-factor authentication (finger and eye) could help on encryption.

PS: Your strawman conversation, is for me subject for another post =)

So basically, you need his phone right? This is somehow the same way you steal someones wallet file and then brute force it. Like here on Steem too...
Am I understanding what you mean correctly?

Yes I think so. Multisig sounds good.

PS: Your strawman conversation, is for me subject for another post =)

Glad to hear that! When I first read it I was like

Whaaaaat?