Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

141–150 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#141

Earlier quoted context omitted.

The reason (or, depending on your inclinations, the excuse) for trusted computing to exist is not to guarantee that I didn’t patch the bootloader of the phone on which I type my comment; it’s to guarantee I didn’t patch the bootloader of the phone on which your grandma logs in to her bank without her knowledge.

No, the reason is to let application providers decide which platforms you can run their software on. The reasons why they need that are diverse: DRM, preventing reverse engineering, shifting liability, "cheating" prevention - to name a few, but ultimately they're all about asserting control over the user, just motivated differently in various use cases. "Think of the grandmas".

What's the problem with the current status quo, or the status quo 5 or 10 years ago? 20 years ago there were basically no cheating prevention, but nobody cared. We just didn't play with cheaters. There are still cheaters in all games. No matter what kind of DRM streaming platforms use, their movies are on torrent immediately. The only difference compared to 5-20 years ago is that user experience is worse. I need to install a lot of intrusive bullshits, and I cannot watch movies with proper resolution. For literally nothing.

Re: German implementation of eIDAS will require an Apple/Google account to function

#142
post #25

All these requirements for specific hardware and software are ridiculous. Let every citizen use whatever computer they want. It should be up to the user to secure themselves. Authentication should only require a password or a key pair. If the user wants more security, they can set up TOTP or buy a security dongle or something. It's also ridiculous how it seems we've forgotten computers other than smartphones exist an…

> let every citizen use whatever computer they want. That's just not possible, or should the system be legally required to run on an Apple II?

You can make an argument without pulling it into the ridiculous, you know?

Re: German implementation of eIDAS will require an Apple/Google account to function

#143
post #36

Does this mean sanctioned individuals, such as those in the International Criminal Court, would be unable to access eIDAS, among other things? As it requires, from my understanding, installing app(s) from the play store, thus requiring an account there and being able to access it, which isn't happening if you're among those or really, in any group that might get the same treatment in the future.

Yes? I don't think it's a bad idea though. If only for bringing the issue to the public And while I do think an alternative would be good, the fact is that protecting the private key is the most important part (for example by keeping it on a smartcard with NFD) - hence why the need for a secure device "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env.

> but you know this is a non-secure-(enough) env.

No I do not. It is plenty secure compared to a corporate version and nobody should be legally able to deny service over me having control over my own computer.

Needing the entire OS to be secure to protect a key is also a dumb idea in general.

Re: German implementation of eIDAS will require an Apple/Google account to function

#144
post #62
post #30

I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.

I think because most people, even tech savvy ones don’t understand how this might effect their lives. It’s too abstract. At least how it’s portrayed here. Contrast that with chat control. My government can read my WhatsApp messages? Not good! What’s the non-technical narrative here?

[dead]

Re: German implementation of eIDAS will require an Apple/Google account to function

#145
Possibly I‘m not smart enough to understand, but from what I see is that the implementers intend to leverage existing security architecture of Android/Google and iOS/Apple, respectively- arguably to drive adoption. The document doesn’t state anywhere that Apple / Google account is a requirement to use German eIDAS. From what I can tell, one may (continue to) use its government issued ID card with electronic signature for authentication.

Please prove me wrong, I genuinely want to understand the implication of the linked document.

Re: German implementation of eIDAS will require an Apple/Google account to function

#146

What if you „lose“ your google / apple account, like this sanctioned judge of the international criminal court? Crazy to imagine that we are still baking in dependency on US providers in european societies, even though there is clear indications we should be doing the opposite?

> Crazy to imagine that we are still baking in dependency on US providers in european societies

As long as the capital city is in Washington, this is normal.

Re: German implementation of eIDAS will require an Apple/Google account to function

#147
post #25

All these requirements for specific hardware and software are ridiculous. Let every citizen use whatever computer they want. It should be up to the user to secure themselves. Authentication should only require a password or a key pair. If the user wants more security, they can set up TOTP or buy a security dongle or something. It's also ridiculous how it seems we've forgotten computers other than smartphones exist an…

> let every citizen use whatever computer they want. That's just not possible, or should the system be legally required to run on an Apple II?

The problem to solve is trust.

The technical solution is a hardware root of trust. This is typically a specially hardened chip in the device. A Trusted Platform Module (TPM).

Your Apple ][ does not have a TPM. It cannot run software that can assess it's identity in a trusted manner.

Re: German implementation of eIDAS will require an Apple/Google account to function

#148

Self Sovereign Identity (aka SSI) is the only way out of those identity sovereignty issues. It shouldn't be acceptable that your identity depends on anything or anyone. It should just be your identity. A paper or certificate can prove an entity trusts your identity to be but that shouldn't be your identity. You just are. Not your google Id, not your Apple Id either of course. Governments are lame.

You are conflating the philosophical notion of identity with functional identification in the real world. There is no cryptographic escape hatch from the social contract.

>You just are/I just am

Is not an acceptable thing to say to a bar tender when being served an alcoholic drink when you're 22. You hand them government issued ID.

Re: German implementation of eIDAS will require an Apple/Google account to function

#149
post #7

That sounds like a very smart move at the time where Europe realize the US isn't such a gray partner and it's trying to reduce it's critical dependencies on foreign nations tech and infra. Good job. I'm actually very surprised to see this from the germans who have this reputation of great engineering culture

I think the reputation is fading. I know I’d take a Chinese car over a German one.

I wouldn't, as China being the largest single market for motor vehicles and the cutthroat competition there is what caused all this.

Everyone is trying to cut costs so as to be able to compete there and Europeans are paying the cost of financing this.

Personally I'm going to wait until the average car age in China crosses the 10-year mark to get a new vehicle. Until that happens there will be no incentive to think about longevity.

Re: German implementation of eIDAS will require an Apple/Google account to function

#150

It makes no sense. eIDAS 2.0 specs don't require specific hardware [0]. They basically store verifiable credentials [1] and any other cryptographically signed attestations. This feels like laziness from German implementers, as they don't want to (quoting the spec literally) "implement a mechanism allowing the User to verify the authenticity of the Wallet Unit". 0: https://eudi.dev/latest/architecture-and-reference-fr…

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Why would this be? Bureaucracy / inability to change?
Post reply on HN