Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

201–210 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#201

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Thank you for chiming in.

> We have to use some kind of attestation mechanism per the eIDAS implementing acts.

What does this attestation need to prove? Is this only about ensuring that private keys are managed by a secure enclave or a TPM?

> we have support for other OSs on our list (like, e.g., GrapheneOS)

I appreciate that, even though I am really not enthusiastic of eIDAS. But time will tell. Thank you.

Re: German implementation of eIDAS will require an Apple/Google account to function

#202

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Just a quick question, and sorry if it might have been answered already... why preventing duplication is so important? I know it’s in the spec probably [1], but I can’t figure out the reason.

And a suggestion: add external HSM support at least? (e.g. things like NitroKey/YubiKey)

[1]: https://eudi.dev/latest/architecture-and-reference-framework... I suppose?

Re: German implementation of eIDAS will require an Apple/Google account to function

#203

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

I think it should be possible IMHO, like it is for many banks (still), to get a hardware token and then use whatever hardware/browser. Even a nice EU hardware token which allows banks , govs etc to add their keys/seeds in the enclave would be nicer so I don't have the lug 1000 tokens around, but it's still better than having to trust non sovereign companies for anything without backup; like multiple here said; Google/Apple getting the command from the Dep of War to shut down EU phone attestation, you losing your account etc, or, you know, me simply not wanting to use their stuff.

Re: German implementation of eIDAS will require an Apple/Google account to function

#204
post #25

All these requirements for specific hardware and software are ridiculous. Let every citizen use whatever computer they want. It should be up to the user to secure themselves. Authentication should only require a password or a key pair. If the user wants more security, they can set up TOTP or buy a security dongle or something. It's also ridiculous how it seems we've forgotten computers other than smartphones exist an…

Last week I was watching a YouTube video, talking about the EU creating payment services independent of VISA and MasterCard. What struck me is that they are all apps, which will require an app store.

Great, I can pay with a digital Euro, Wero or something else, without routing my payments via VISA. I just can't do it without an account with Apple or Google. I'm absolutely baffled by politicians, regulators, banks, merchants and implementors lack of ability to think more than one or two steps out.

Sure, the EU is forcing 3rd. party app store, but no one is using them, so no one is pushing apps to them, especially not governments, banks or payment services, they'll be the last to use them.

Re: German implementation of eIDAS will require an Apple/Google account to function

#205

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…

Comparing being able to run the hardware and software of your choice to "wanting a passport in a different color or whatever" is so completely fucked, and it's beyond insane as a justification for giving two American tech companies with a well established track record for doing evil control over your citizens' ID.

The world has gone absolutely mad, what the fuck am I even witnessing? It is quite literally becoming 1984 in front of my eyes, with people complying completely voluntarily and openly advocating for it, not even a threat of force to make it happen.

Re: German implementation of eIDAS will require an Apple/Google account to function

#206
post #5

So what was the point of putting a crypto chip into every ID if you are gonna try and reinvent the entire trusted environment in the fucking smartphone?

ID cards don’t connect to the internet.

These days an ID system that doesn’t work online is next to useless.

Re: German implementation of eIDAS will require an Apple/Google account to function

#207

Earlier quoted context omitted.

What if I don’t have a smartphone?

No one is required to use EUDI: https://ec.europa.eu/digital-building-blocks/sites/spaces/EU... Companies and providers (like banks) have to support it, but use is voluntary. Check out the spec and legal framework, it actually makes sense and is open to different implementations, though you might need to certify it.

If they have to support something that most everybody has they will soon stop supporting alternatives that are not required by law. What then?

Re: German implementation of eIDAS will require an Apple/Google account to function

#208

Earlier quoted context omitted.

US dependency did bring a lot of value to a lot (albeit not all) of Europeans in past, specifically 1938-1988. If you were born, raised and lived in that timespan, you might have developed a deep seated and hard to break habit to rely on that dependency for security and lifestyle/wealth. Also, that same lifestyle is based on ignoring externalities applied to commons and/or events happening “somewhere else”, even when…

> The reputation/trust damage self inflicted by the current US administration is triggering a pushback that will expand into the future. This barely even seems like the relevant part. If Google was founded in Japan and Apple in Brazil, it would still be foolish to entrench them as a dependency. It would barely even be better to do it with a local company. > They will move their data it the EU (where else? China?). Th…

Relying on open protocols to make all the difference is much more potent hopium than what GP wrote.

Open protocols are kind of thing techies do when in cooperative mode, when industry isn't looking. But this is not this kind of problem - this is an economic, geopolitical problem. It's not about your local school moving off Windows to Linux, it's about the European corporations moving off Azure to some other cloud solution offered by European corporations (do we even have any?).

I'll grant it, the turmoil of such transitions is a perfect moment for pushing for open protocols, federated solutions, etc. - the industry is distracted, there's more space to sneak in some good solution before everyone notices, and EU has cultural and political tradition of pushing towards FLOSS (even if largely just as an alternative to Microsoft) and associated values/memetic complex. But open anything won't save the day - more corporations will.

It's a blind spot for some software folks, because they forget that FLOSS is an exception here; everything else in the real world - including computing hardware and supporting power and network infrastructure - plays by rules of market economy, with proprietary solutions and clear structures of ownership.

It makes no sense to try and fight this here - but it does make sense to go along with the flow and improve things by pushing for more globally optimal solutions, especially that EU is known to be favorable to using openness in protocols and standards as a policy vehicle, both internally and externally.

Re: German implementation of eIDAS will require an Apple/Google account to function

#209

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

You should think about how easy it is to permanently lose access to your Google account for very trivial issues and Google doesn't offer any form of recovery. That in addition to the current geopolitical situation should be reason enough not to rely on that for any justification. And personally as a software developer myself i know that nothing is more permanent than a temporary solution. No one will prioritize or gi…

What? They should freaking think of sanctions, not about "how easy is to lose Google account". Both Google and Apple are American companies. If someone lands on a sanctions list, they close your account without further notice [1].

Let me get this straight: you can be a defender of human rights, aligned with the country you live in, but if you fall in disgrace with the American government, _you can't even do transactions with your own country_.

So this is fundamentally flawed, and violates the fundamental rights of German citizens in Germany.

[1] https://www.lbc.co.uk/article/british-icc-chief-prosecutor-l...

Re: German implementation of eIDAS will require an Apple/Google account to function

#210

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Tbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.

I'm pretty sure electronic IDs are a good starting point for exactly this. Hopefully they get wider use inside the EU.
Post reply on HN