Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

251–260 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#251

As someone living in Germany, the alternative would be snail mail, which is used to send a pre-authentication code, username and then another code. This is pretty common with insurance providers, German traditional banks, etc. However, the annoying part is that if you ever forget or lose the code, then you would have to request a new one via mail that would arrive like 2 weeks after.

The alternative is a secure physical device and that's also the correct way to go if you insist on having online ID checks and take digital sovereignty seriously instead of making it a joke lip service like these implementers do.

Re: German implementation of eIDAS will require an Apple/Google account to function

#252

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

There's a new initiative by some non-google non-apple phone vendors called *UnifiedAttestation* which I hope you will support at some point in the future:

https://www.heise.de/en/news/Paying-without-Google-New-conso...

Re: German implementation of eIDAS will require an Apple/Google account to function

#253

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

German citizen here. I find this attitude horrible and threatening. You are working on sacrificing yet another part of our digital sovereignty to a US company. There are trillions of better things to do with your life.

European Citizen here, and indeed lots of people in IT turn a blind eye onto the collateral damage their work may create.

I know someone who happily codes "verifiable credentials" in Elixir, disregarding all externalities.

Re: German implementation of eIDAS will require an Apple/Google account to function

#254

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Why is a trusted device chain needed? It will put more trust in the potential Chinese device maker and American software companies than the user who's id is shown?

This is necessary because the wallets contain an identity proofing functionality called PID(Person Identification Data). Showing these credentials basically approves you are you. There are high requirements for identity proofing that even pre-date wallets and that makes sense, because the potentially blast radius of identity theft is huge. Historically, these have been secured in smartcards, like eID cards or passports and are not shifting to the smartphone. Verifying the security posture of your device and app is therefore crucial.

Re: German implementation of eIDAS will require an Apple/Google account to function

#256
post #164

Earlier quoted context omitted.

What if I don’t have a smartphone?

I wonder if there will be a big enough market for a very compact smartphone equivalent device that can be used just for credentials? A device that is offline on standby except when you need it. Perhaps the size of a car key.

What if it was the size of a credit card and it had stuff like your name, date of birth and even a picture of your face. I want to name this invention an ID card…

Re: German implementation of eIDAS will require an Apple/Google account to function

#257

What if you „lose“ your google / apple account, like this sanctioned judge of the international criminal court? Crazy to imagine that we are still baking in dependency on US providers in european societies, even though there is clear indications we should be doing the opposite?

You wouldn't even have to be a high profile target like a sanctioned judge. Simply getting your account banned by some automated process that marked you as "suspicious" will basically render you excluded from society. It is absolutely insane to put this amount of power in 2 foreign companies that will be able to destroy your life with zero reason, oversight, or due process.

This is not a hypothetical problem and you don't need to be deliberately targeted. It actually happens to normal people. And if it does you have absolutely zero recourse.

Source: I have a banned Google account (it's over 20 years old at this point). I know the password, but Google doesn't let me log into it. Every few years I try to unsuccessfully recover it.

If you have a Google account and having it banned would be a problem for you here's my advice: migrate. Right now. You never know when one of their bots will deem you a persona non grata.

Re: German implementation of eIDAS will require an Apple/Google account to function

#258
post #214

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Do we have stats how many germans use something else than Google Android, Samsung Knox or Apple? I recon it should be less than 1% which quite honestly is in fact „all“ citizens.

Re: German implementation of eIDAS will require an Apple/Google account to function

#259
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

because then it will never get done. There are still people using old Nokia phones, for those there will never be a solution. The usual 80/20 rule applies here as well. And if you really are a German citizen, you know how slow the wheels of government already turn in Germany, I assume next week you would be the one complaining that "Germany is so far behind" and that "other countries are so much faster at implementin…

Nah, I'm that one idiot who uses alternative open software and just accepts when services aren't offered to me. The older I get, the easier it feels to not give a fuck anymore.

Can't buy any single fare public transport tickets online here in Stuttgart? Sure, I'll use the DeutschlandTicket NFC card. Can't view the EPA? Fine then I don't. Can't pay with Wero? Fine, I don't actually need to use shops that don't offer SEPA Vorkasse or Lastschrift (only without a dodgy "identity verification" fintech startup of course.

Re: German implementation of eIDAS will require an Apple/Google account to function

#260

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

In light of all of these shortcomings with platform attestation, why go with the eIDAS 2 wallet approach at all? eIDAS 1 already solved this with Mobile-ID (SIM-based, no Google/Apple dependency) and Smart-ID (server-side key management with minimal platform reliance). What does the wallet model give you that justifies this level of dependency on two American corporations’ proprietary backends?

Especially considering that mobile-ID has been around since 2007.

Post reply on HN