Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

101–110 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#101
post #76

Earlier quoted context omitted.

Well, it affects a tiny percentage of people today, so why would they see it as impacting them?

Do people in Europe not intuitively understand that willingly making yourself [more] dependent on a foreign corporation is disadvantageous to you?

Do people outside of Europe do not understand how Germany is just a small fraction of Europe.

Re: German implementation of eIDAS will require an Apple/Google account to function

#102

Earlier quoted context omitted.

Yes? I don't think it's a bad idea though. If only for bringing the issue to the public And while I do think an alternative would be good, the fact is that protecting the private key is the most important part (for example by keeping it on a smartcard with NFD) - hence why the need for a secure device "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env.

> "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env. I feel like this is getting to the point of gaslighting. Many of the allowed devices are bargain bin Android phones running out of date software with known vulnerabilities in both the operating system and the hardware which is supposed to be protecting the keys. Meanwhile you could be using a hardwa…

> Meanwhile you could be using a hardware security module in a bank vault

Yeah you could, but most people won't

Should they allow for a yubikey on a non-google phone? Or your own private key? Yes they should. But then there's the issue of enrollment, etc.

Re: German implementation of eIDAS will require an Apple/Google account to function

#103

Earlier quoted context omitted.

Not in software. German software is awful. Think german cars, banks, telecoms etc

While I agree, it'd be hard to say that SAP is not good

Strong =! Good

Re: German implementation of eIDAS will require an Apple/Google account to function

#104
post #101

Earlier quoted context omitted.

Do people in Europe not intuitively understand that willingly making yourself [more] dependent on a foreign corporation is disadvantageous to you?

Do people outside of Europe do not understand how Germany is just a small fraction of Europe.

While true, it influences a lot in the EU

Re: German implementation of eIDAS will require an Apple/Google account to function

#105

Same in Switzerland. The app needed to sign in to fill out my taxes doesn't work on ungoogled Android.

Can you do your taxes on a computer without a phone?

Yes. Without any issues still.

Gladly.

There was a time window 2 years ago where it appeared that I need an actual phone number to do my taxes, but even that was replaced with something more universal.

Re: German implementation of eIDAS will require an Apple/Google account to function

#106

Earlier quoted context omitted.

Any bootloader or OS that doesn't allow the user to tamper with it or the other tools they're using on it is obviously illegitimate malware.

It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS. Which was the motivation for cryptographically attesting the boot process and OS, and in part paved the way for app attestation. There are alternatives though: The Android Hardware Attestation API enables attestation on custom ROMs, but the attestation verifier needs a list of hashes for all "acceptable" ROMs. Graphene…

Nothing funny in it, I'm afraid. Socially accepted malware is still malware. Caffeine is a stimulant, alcohol is a drug, a piece of software that works against the user is a malware.

Cryptographic attestation is not a problem in itself, the problem is exactly what you already somewhat hinted at: it's who and how decides who to trust and who gets to make (or delegate) the choices. You can make a secure system that lets the user be in charge, but these systems we're discussing here don't (and that's by design; they're made to protect "apps", not users).

Re: German implementation of eIDAS will require an Apple/Google account to function

#107

Earlier quoted context omitted.

Not in software. German software is awful. Think german cars, banks, telecoms etc

While I agree, it'd be hard to say that SAP is not good

We had people formerly saying that in our org and going to a _decade_ of several failed ERPs. Now we run SAP. Still people are unsatisfied with SAP. Not even recognising that the failures are mostly self instricted policies. The organisation worked somehow before having an ERP, because people ignored the given organisation and improvised. That's close to impossible if you use digital processes from end to end. And yet, the ones with the poor organisational skills blame software.

Re: German implementation of eIDAS will require an Apple/Google account to function

#108
post #101

Earlier quoted context omitted.

Do people outside of Europe do not understand how Germany is just a small fraction of Europe.

While true, it influences a lot in the EU

I don't think they influence more than France does. But I don't know, I live in Europe but don't care for the EU

Re: German implementation of eIDAS will require an Apple/Google account to function

#109

Earlier quoted context omitted.

> "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env. I feel like this is getting to the point of gaslighting. Many of the allowed devices are bargain bin Android phones running out of date software with known vulnerabilities in both the operating system and the hardware which is supposed to be protecting the keys. Meanwhile you could be using a hardwa…

> Meanwhile you could be using a hardware security module in a bank vault Yeah you could, but most people won't Should they allow for a yubikey on a non-google phone? Or your own private key? Yes they should. But then there's the issue of enrollment, etc.

> Yeah you could, but most people won't

When something is required by law, it needs to work for all people.

It also specifically needs to not entrench incumbents by impeding the ability of challengers that don't currently have market share from ever getting any.

> Should they allow for a yubikey on a non-google phone? Or your own private key? Yes they should. But then there's the issue of enrollment, etc.

There is no such issue because enrollment should be part of the standard so any device that implements the standard can be enrolled.

Re: German implementation of eIDAS will require an Apple/Google account to function

#110
post #85

Earlier quoted context omitted.

> every energy crisis brings opportunity to saturate the airwaves with shallow noise that gets people overly upset and they’ll ignore everything else. At least their version has an obvious solution: Make electric cars and solar panels and then stop having oil problems.

The speeding debate won't go away with this, though, as speeding is not about oil.

I believe the idea is that friction and resistance is proportional to the square of the speed. After a certain speed, every 10 mph extra starts to really count in your mileage.
Post reply on HN