Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

61–70 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#61
post #14

Earlier quoted context omitted.

Not in software. German software is awful. Think german cars, banks, telecoms etc

Ah yes, the fabulous car engineering of Dieselgate.

Well they got caught..

Re: German implementation of eIDAS will require an Apple/Google account to function

#62
post #30

I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.

I think because most people, even tech savvy ones don’t understand how this might effect their lives. It’s too abstract. At least how it’s portrayed here.

Contrast that with chat control.

My government can read my WhatsApp messages? Not good!

What’s the non-technical narrative here?

Re: German implementation of eIDAS will require an Apple/Google account to function

#64
post #43

They're taking feedback here: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

Source? You're linking to a bugtracker. I doubt they're inviting people to spam it with duplicate entries — valid as I think the concern is. But maybe it says somewhere that you can leave feedback here and I just haven't seen it?

There is a 8 months old open ticket, with an official answer, here: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

Re: German implementation of eIDAS will require an Apple/Google account to function

#65
post #62
post #30

I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.

I think because most people, even tech savvy ones don’t understand how this might effect their lives. It’s too abstract. At least how it’s portrayed here. Contrast that with chat control. My government can read my WhatsApp messages? Not good! What’s the non-technical narrative here?

But there is nothing abstract here. A private entity, situated in a country that is very hostile and pro-Russia, controls parts of the software stack and implementation here. That's a law written by lobbyists.

Re: German implementation of eIDAS will require an Apple/Google account to function

#66
post #59
post #30

I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.

> at some point parents need to parent You write it as if companies provided tons of help to parents and children. Meanwhile, they spend a lot of money to make it as hard as possible. Second, kids in Germany have generally a lot more freedom and there is less of knee jerk impulse to blame parents for every accident. Expectation is that adults dont harm them without parents having perfect control every sevond.

The age verification sniffing laws will come to the EU and Germany too, so your assessment is, in my opinion, too limited and incomplete. It's not really about parenting, it is about grabbing more and more data from people.

Re: German implementation of eIDAS will require an Apple/Google account to function

#68
post #56

Earlier quoted context omitted.

There's no such thing as "legitimacy of the bootloader, OS" that can be verified by someone who isn't the device's user. The bootloader that booted the phone I type this on is patched by me, which makes it more "legitimate" than any other bootloader that could be placed there.

Sorry but this is nonsense - most users, even the Linux toting power users - don't have the time, ability or knowledge to verify the contents of their OS in a way that would catch issues prevented by attestation. The problem with modified phones containing malware is very real and unless you want a full on Apple "you're not allowed to touch the OS" model you need some kind of audited OS verification that you as a use…

No, what you're saying is nonsense. I can burn a key into efuses of this phone to make it only boot things signed by me and make the whole boot path verified, OS image immutable etc. and all of this can provide me some value, but it's absolutely not in my interest to let applications be picky on what can or can't happen in the OS (even if they would accept my key being there rather than Google's, which they won't). The only thing it manages to do is to prevent me from using the device the way I want or need it to be used.

Re: German implementation of eIDAS will require an Apple/Google account to function

#69
post #36

Does this mean sanctioned individuals, such as those in the International Criminal Court, would be unable to access eIDAS, among other things? As it requires, from my understanding, installing app(s) from the play store, thus requiring an account there and being able to access it, which isn't happening if you're among those or really, in any group that might get the same treatment in the future.

Yes? I don't think it's a bad idea though. If only for bringing the issue to the public And while I do think an alternative would be good, the fact is that protecting the private key is the most important part (for example by keeping it on a smartcard with NFD) - hence why the need for a secure device "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env.

> "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env.

I feel like this is getting to the point of gaslighting. Many of the allowed devices are bargain bin Android phones running out of date software with known vulnerabilities in both the operating system and the hardware which is supposed to be protecting the keys.

Meanwhile you could be using a hardware security module in a bank vault in a nuclear bunker surrounded by armed guards and the excuse would be that this "isn't secure" because it hasn't been approved by Google or Apple.

Governments shouldn't be requiring you to use any specific vendor or set of vendors. They should be publishing standards so that anyone who implements the standard can interact with the system.

Re: German implementation of eIDAS will require an Apple/Google account to function

#70
post #25

All these requirements for specific hardware and software are ridiculous. Let every citizen use whatever computer they want. It should be up to the user to secure themselves. Authentication should only require a password or a key pair. If the user wants more security, they can set up TOTP or buy a security dongle or something. It's also ridiculous how it seems we've forgotten computers other than smartphones exist an…

> let every citizen use whatever computer they want.

That's just not possible, or should the system be legally required to run on an Apple II?

Post reply on HN