Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

151–160 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#151
post #55

Earlier quoted context omitted.

Germany is distracted with its version of “the gun debate” aka speed limits. Like every school shooting, every energy crisis brings opportunity to saturate the airwaves with shallow noise that gets people overly upset and they’ll ignore everything else. Every player on both sides is abusing this mechanic for all eternity.

Imagine we had real democracy where people vote on issues. Speed limits? Vote once every 7 years or so on it and be done with it. Same for abortion laws, drug laws, gambling laws. Have a debate, vote, come back to it in 7 years if there is public interest. Preferably vote locally on issues that can be applied locally (like speed limits/enforcement etc.). Public debate and assessing politicians and parties would be so…

Popular vote would have made sure civil rights legislation never passed and everything down to the schools and bathrooms would still be segregated.

Re: German implementation of eIDAS will require an Apple/Google account to function

#152
post #76

Earlier quoted context omitted.

Well, it affects a tiny percentage of people today, so why would they see it as impacting them?

Do people in Europe not intuitively understand that willingly making yourself [more] dependent on a foreign corporation is disadvantageous to you?

US dependency did bring a lot of value to a lot (albeit not all) of Europeans in past, specifically 1938-1988. If you were born, raised and lived in that timespan, you might have developed a deep seated and hard to break habit to rely on that dependency for security and lifestyle/wealth.

Also, that same lifestyle is based on ignoring externalities applied to commons and/or events happening “somewhere else”, even when factually proven. Little wonder and tiny bit ironic that the same principle has embedded itself so deeply, that it holds true even when the damage is inward, just a few indirections away.

On your side, yes, I think that “people in Europe” intuitively understand that, it just needs time to blossom. The reputation/trust damage self inflicted by the current US administration is triggering a pushback that will expand into the future. As a point in case, it will lead to reconsidering assumptions on habits that many generations of US businesses and diplomats have built.

Many in this thread point at difference instances of services that should be decoupled. Connecting the dots, the larger picture looks painfully obvious to me: Silicon Valley never was a partner to be trusted, and certainly not after they built or bent every business to rely on an ad ecosystem that exploits users.

That original sin, on which a huge portion of Wall Street rests, is now at the center of discussions. Hence, the EU will build tools to address this because it has to, but consumers will flock to them especially from the US, since at this point no one can trust SV companies on data privacy (since Snowdens at least), no one can trust the US administration to protect citizens (since Trump at least), and about half of the US is scared about what’s going on deeply enough (the emotional push needed to break the habit). They will move their data it the EU (where else? China?).

This will be compounded by the fact that everyone tries to build better LLMs and to get AGI, while forgetting that LLMs work on data pipelines.

Re: German implementation of eIDAS will require an Apple/Google account to function

#153
post #141

Earlier quoted context omitted.

No, the reason is to let application providers decide which platforms you can run their software on. The reasons why they need that are diverse: DRM, preventing reverse engineering, shifting liability, "cheating" prevention - to name a few, but ultimately they're all about asserting control over the user, just motivated differently in various use cases. "Think of the grandmas".

What's the problem with the current status quo, or the status quo 5 or 10 years ago? 20 years ago there were basically no cheating prevention, but nobody cared. We just didn't play with cheaters. There are still cheaters in all games. No matter what kind of DRM streaming platforms use, their movies are on torrent immediately. The only difference compared to 5-20 years ago is that user experience is worse. I need to i…

It's not just that "user experience is worse", it's an existential threat to Free Software.

In the past, when you had a proprietary tool you needed to use to do something, people could analyze and reimplement it. The reasons to do that varied - someone needed "muh freedomz", someone else wanted to do the thing on an unsupported platform, someone else wanted to change something in the way the tool worked (perhaps annoyed by paper jams)... Eventually you could end up with an interoperable FLOSS reimplementation. This has happened with lots of various things - IMs, network service clients, appliance drivers, even operating systems, and this is how people like me could switch away from Windows and have their computers (and later phones) remain fully functional in the society around us, perhaps with minor annoyances, but without real showstoppers.

Remote attestation changes this dynamic drastically. Gaim (Pidgin), Kadu couldn't be made if the service provider like AIM, ICQ, Gadu-Gadu etc. could determine whether you're using the Official App™ from the Official Store™ on the Official OS™ and just refuse to handle requests from your reimplementation. They could still try and be hostile to you without it, and often did, but it wasn't an uneven fight. Currently we're still in the early days and you can still go by in the society by defaulting to use services on the Web, using plastic card instead of phone for payments etc. but this is already changing. And it's not just a matter of networked services either - I bet we're going to see peripheral devices refusing to be driven by non-attested implementations too.

Secure boot chains have some value and are worth having, but not when they don't let the user be in charge (or let the user delegate that to someone else) and when they prioritize the security of "apps" rather than users. The ability for us as users to lie to the apps is actually essential to preserving our agency. Without that we're screwed, as now to connect ourselves to the fabric of the society we'll need to find and exploit vulnerabilities that are going to be patched as soon as they become public.

Re: German implementation of eIDAS will require an Apple/Google account to function

#154

Earlier quoted context omitted.

Yes? I don't think it's a bad idea though. If only for bringing the issue to the public And while I do think an alternative would be good, the fact is that protecting the private key is the most important part (for example by keeping it on a smartcard with NFD) - hence why the need for a secure device "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env.

> but you know this is a non-secure-(enough) env. No I do not. It is plenty secure compared to a corporate version and nobody should be legally able to deny service over me having control over my own computer. Needing the entire OS to be secure to protect a key is also a dumb idea in general.

> Needing the entire OS to be secure to protect a key is also a dumb idea in general.

This is the final step in the road to full remote attestation, thankfully PCs already come with Microsoft Pluton chips[1] to make it easier.

[1] https://learn.microsoft.com/en-us/windows/security/hardware-...

Re: German implementation of eIDAS will require an Apple/Google account to function

#155
German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support.

The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Re: German implementation of eIDAS will require an Apple/Google account to function

#156

Earlier quoted context omitted.

Not in software. German software is awful. Think german cars, banks, telecoms etc

While I agree, it'd be hard to say that SAP is not good

SAP is very good at what it is trying to do, which is to define, standardize, automate and run a business process, and it is equipped with a large library of premade processes so you don't have to reinvent the wheel.

It does not have good UX because good UX was never the objective.

Re: German implementation of eIDAS will require an Apple/Google account to function

#157

Earlier quoted context omitted.

Well the comment above was expressing disbelief that more people are not up in arms about this. When you realize the tiny tiny percentage of people that have a phone that is not apple or google, you understand why few people are up in arms. It simply doesn’t affect many people.

This feels like arguing that people wouldn't object to having a shock collar padlocked around their neck because it's not currently shocking them. You don't have to see very many moves ahead to guess what happens if you don't object. Whereas if the collar is touted as fashionable and the lock is hidden until it's engaged, now your problem is not that people don't care , it's that they don't know , which is different.

I don't think this analogy comes even close to holding water.

Re: German implementation of eIDAS will require an Apple/Google account to function

#158

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

What if I don’t have a smartphone?

Re: German implementation of eIDAS will require an Apple/Google account to function

#159

Earlier quoted context omitted.

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Why would this be? Bureaucracy / inability to change?

Or someone could be getting kickbacks on the down low.

Re: German implementation of eIDAS will require an Apple/Google account to function

#160

Earlier quoted context omitted.

I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in pure technical & UX terms, you don't need to be logged in.

[flagged]

[deleted]
Post reply on HN