German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
Tbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.
German implementation of eIDAS will require an Apple/Google account to function
231–240 of 674 posts
Re: German implementation of eIDAS will require an Apple/Google account to function
#232Earlier quoted context omitted.
You should think about how easy it is to permanently lose access to your Google account for very trivial issues and Google doesn't offer any form of recovery. That in addition to the current geopolitical situation should be reason enough not to rely on that for any justification. And personally as a software developer myself i know that nothing is more permanent than a temporary solution. No one will prioritize or gi…
What? They should freaking think of sanctions, not about "how easy is to lose Google account". Both Google and Apple are American companies. If someone lands on a sanctions list, they close your account without further notice [1]. Let me get this straight: you can be a defender of human rights, aligned with the country you live in, but if you fall in disgrace with the American government, _you can't even do transacti…
Re: German implementation of eIDAS will require an Apple/Google account to function
#233German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
For those that do not know, that is the only way to get the Google account back is to use a hardware 2FA in the first place....
AND yubikeys are $60 per yubikey...and generally you want 2 including a backup
Re: German implementation of eIDAS will require an Apple/Google account to function
#234German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
This is simply unconstitutional and should be escalated ASAP if you don't want to end it before the appropriate court in Leipzig, Karlsruhe, or maybe Luxembourg.
Re: German implementation of eIDAS will require an Apple/Google account to function
#235I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…
I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…
Re: German implementation of eIDAS will require an Apple/Google account to function
#236Earlier quoted context omitted.
US dependency did bring a lot of value to a lot (albeit not all) of Europeans in past, specifically 1938-1988. If you were born, raised and lived in that timespan, you might have developed a deep seated and hard to break habit to rely on that dependency for security and lifestyle/wealth. Also, that same lifestyle is based on ignoring externalities applied to commons and/or events happening “somewhere else”, even when…
> The reputation/trust damage self inflicted by the current US administration is triggering a pushback that will expand into the future. This barely even seems like the relevant part. If Google was founded in Japan and Apple in Brazil, it would still be foolish to entrench them as a dependency. It would barely even be better to do it with a local company. > They will move their data it the EU (where else? China?). Th…
> But then it's not so much that data ends up in "the EU" as that it's on your own device and then backed up or distributed as encrypted chunks in a distributed network which isn't tied to any specific jurisdiction.
100% i launched into a long trajectory from the comment i was originally answering to, and stopped short
i think-of? dream-of? try-to-build? what you just said
my "in the EU" claim is mostly around legislation (EU art 8 vs US CLOUDS act vs vs China approach to citizen's data)
the legislation is there, since GDPR it's a matter of tools
since corps built tools, they "forgot" to add the third button on cookie banners: "give me back my data" ... (and fourth: "delete it") but the legal framework is there, as well as most of the tooling (google takeout, and so on from all other major players)
it's not that pipelines for moving data from US corps to inidividual do not exists, it's more that, up to now, whenever i was talking about "data rights" to people, even in tech, i got yawns back
now we have a "perfect storm": distrust towards US (administration, collpasing onto US businesses) + global uncertainty towards AI (where lots of people just perceive something happening but lack any tool that gives them control over it)
this is what i perceive as a tectonic shift that can be used innovatively, by EU businesses, hopefully leveraging open
for completeness, i have indeed wrapped "EU" as the spearhead for this, given the incentives to build it, but yes, central authority over this should live inside of each citizen nation framework (see, Japan and South Korea, both providing legal frameworks for data protection)
Re: German implementation of eIDAS will require an Apple/Google account to function
#237German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
Re: German implementation of eIDAS will require an Apple/Google account to function
#238German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
Re: German implementation of eIDAS will require an Apple/Google account to function
#239German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.
The usual 80/20 rule applies here as well.
And if you really are a German citizen, you know how slow the wheels of government already turn in Germany, I assume next week you would be the one complaining that "Germany is so far behind" and that "other countries are so much faster at implementing stuff" :)