Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

271–280 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#271

Earlier quoted context omitted.

You're screwed. This has been the way for a while now. You cannot exist in society without a smart phone and it's only going to get worse.

If you can't exist in society without a smart phone already, how is it going to get worse?

Perhaps you won't be able to exist in private without a smart phone. Or there will be some technology beyond a smartphone that you can't exist without.

Re: German implementation of eIDAS will require an Apple/Google account to function

#272

Earlier quoted context omitted.

> The reputation/trust damage self inflicted by the current US administration is triggering a pushback that will expand into the future. This barely even seems like the relevant part. If Google was founded in Japan and Apple in Brazil, it would still be foolish to entrench them as a dependency. It would barely even be better to do it with a local company. > They will move their data it the EU (where else? China?). Th…

Relying on open protocols to make all the difference is much more potent hopium than what GP wrote. Open protocols are kind of thing techies do when in cooperative mode, when industry isn't looking. But this is not this kind of problem - this is an economic, geopolitical problem. It's not about your local school moving off Windows to Linux, it's about the European corporations moving off Azure to some other cloud sol…

great counterpoint! (no i'm not an LLM, it is a actually a crucial perspective) i especially agree with > But open anything won't save the day - more corporations will.

i am not advocating for a pure "open source will save the world" there are just a few points i'd like you to consider, and hopefully give me insights i can learn from

* other than code, open source has also given us governance "experiments" capable of running critical systems. As another poster was mentioning, the risk is to fallback on "big corps", usually run by "big man", and we are back to zero. The hope? expectations? is that the open source governance ecosystem has tackled this space in enough dimensions to be able to build something over this. I am looking specifically at the area around licenses (mariadb, redis, ...) and just overall governance frameworks, as in "deteach business ownership from ethical frameworks"

* in order to build anything this big/reliable, without megacorp budgets, you can just ... pay FLOSS? They are one of the 2 majorly screwed groups by the current SV setup (with PLENTY of cavaets,amongst them that SV is a huge open soure contributor) The other one being content creators. Slogan? "For this to succeed, you need the best coders and the best marketing departments in the world" Looks to me like incentives are aligned towards them being available. Talking broadly on a systemic level: details need refinement, and space beyond this single message.

* EU (the political instituion) desperately needs this. An innovative tech ecosystem (not startup, not product) driven by "european values" that puts them on the spot. Start with redefining it: there are no users, but citizens. Something effectively out-innovating SV, not just trying to get on par. The risk of "being bought out/copied" doesn't really apply, since (as I said in my original comment) the discriminator is existential: US companies cannot be trusted because they built the existing system. Any attempt to block this (stop users from getting their data back) is going to be challenged by the EU (GDPR violations cannot be brought to court by citizens, only by nation's data authorities, which means a citizen gets big guns and doesn't ned to pay). Also, go on and explain that to all you other (US and not) users.

* A EU cloud provider doesn't have to provide the same services an US provides. That would hardly be innovative. You also don't need to focus on corporations. Provide data storage for citizens, that will be the basis to build a privacy focus cloud, and then business might want that. There is a possible continuation into "advantages of storage&privacy based vs compute", that i skip.

But essentially, to me it seems that an open source, true, "give me back my data" business driven initiative has never been as actionable as now. I short, such a project can make 2 bold statements "We are more innovative than SV" "We have better freedoms than the US"

Re: German implementation of eIDAS will require an Apple/Google account to function

#273

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

You should think about how easy it is to permanently lose access to your Google account for very trivial issues and Google doesn't offer any form of recovery. That in addition to the current geopolitical situation should be reason enough not to rely on that for any justification. And personally as a software developer myself i know that nothing is more permanent than a temporary solution. No one will prioritize or gi…

Can't you just make a new google account then?

Re: German implementation of eIDAS will require an Apple/Google account to function

#274
post #231

Earlier quoted context omitted.

Tbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.

Banks actually have high fraud rates today because of weak security mechanisms. If attackers steal your money, the bank will reimburse you. If attackers steal your identity, you are really screwed. Security requirements for banking and identity are simply different.

Mobile Google account based is even weaker than hardware tokens used by banks. Make of that what you will.

Re: German implementation of eIDAS will require an Apple/Google account to function

#275

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

“Not Great” is the understatement of the century. It fails to protect sovereign identity by handing the default to companies not only under foreign sanctions control but who also lock people from their accounts without recourse.

The device chain is a classic misdirection, it seems everyone here is just following Meta’s lobbying to put this into the OS.

Even the carrier layer would be better than the mobile device layer.

Or, you know, just look at Singapore’s or Swiss National SSO - it functions on an app that layer just fine, no issues

See https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Re: German implementation of eIDAS will require an Apple/Google account to function

#276
post #56

Earlier quoted context omitted.

Sorry but this is nonsense - most users, even the Linux toting power users - don't have the time, ability or knowledge to verify the contents of their OS in a way that would catch issues prevented by attestation. The problem with modified phones containing malware is very real and unless you want a full on Apple "you're not allowed to touch the OS" model you need some kind of audited OS verification that you as a use…

No, what you're saying is nonsense. I can burn a key into efuses of this phone to make it only boot things signed by me and make the whole boot path verified, OS image immutable etc. and all of this can provide me some value, but it's absolutely not in my interest to let applications be picky on what can or can't happen in the OS (even if they would accept my key being there rather than Google's, which they won't). T…

I agree about the part where apps shouldn't be able to see whether the OS is trusted.

But to remove that incentive you first need to stop punishing app companies for compromised user OSes from legal perspective.

Are you willing to absolve Google, Apple and Deutsche Bank from responsibility of damage that happens on compromised user OSes?

Re: German implementation of eIDAS will require an Apple/Google account to function

#277

Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.

Maybe that will force the companies to not be allowed to just lock you out of the account.

Ya, sorry, no, maybe is not really a durable position here.

Re: German implementation of eIDAS will require an Apple/Google account to function

#278
post #56

Earlier quoted context omitted.

Sorry but this is nonsense - most users, even the Linux toting power users - don't have the time, ability or knowledge to verify the contents of their OS in a way that would catch issues prevented by attestation. The problem with modified phones containing malware is very real and unless you want a full on Apple "you're not allowed to touch the OS" model you need some kind of audited OS verification that you as a use…

There's also a problem with unmodified phones containing malware, namely an operating system made by an advertising company, which is designed to collect as much information about you as possible. And this malware is largely based on open source code (Linux) that was originally developed on open, documented hardware, where the firmware boot loader did nothing more than load the first 512 bytes of your hard disk to ad…

Yeah, randomly calling software that you don't like "malware" isn't making a strong case you think it does. Or helps in this discussion.

Re: German implementation of eIDAS will require an Apple/Google account to function

#279

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

"Not great" is quite an understatement from a European perspective.

We're talking about a state-issued digital identity system, the European equivalent of your ID card, that cannot function without accounts at two US corporations. That's not a UX limitation. That's a structural dependency on foreign infrastructure for core state sovereignty.

The concerns aren't abstract. The US has a documented history of mass surveillance programs (PRISM, XKeyscore) that directly targeted European citizens and governments. Both Apple and Google operate under US jurisdiction, which means CLOUD Act requests, national security letters, and executive pressure are all legal avenues for US government access. PlayIntegrity is explicitly described in your own architecture docs as a black box: "we do not know what they are actually doing in their backend." A critical security component of a state identity system, and you don't know what it does. That's not an engineering trade-off, that's an accountability gap.

GrapheneOS being "on the list" is not reassuring. It means the system launches in a state where European citizens who have actively chosen to reduce their dependence on US Big Tech are excluded from their own national digital identity infrastructure.

The EU passed GDPR to establish digital sovereignty. It's building eIDAS to establish identity sovereignty. Baking in a hard dependency on Google and Apple at the attestation layer undermines both, by design, at launch.

Re: German implementation of eIDAS will require an Apple/Google account to function

#280
post #101

Earlier quoted context omitted.

Do people outside of Europe do not understand how Germany is just a small fraction of Europe.

While true, it influences a lot in the EU

Thankfully, not in the technology area. Eg. we in the post-soviet EU block are well beyond using fax, and stuff like that, ... :)
Post reply on HN