Earlier quoted context omitted.
You're screwed. This has been the way for a while now. You cannot exist in society without a smart phone and it's only going to get worse.
If you can't exist in society without a smart phone already, how is it going to get worse?
German implementation of eIDAS will require an Apple/Google account to function
271–280 of 674 posts
Re: German implementation of eIDAS will require an Apple/Google account to function
#272Earlier quoted context omitted.
> The reputation/trust damage self inflicted by the current US administration is triggering a pushback that will expand into the future. This barely even seems like the relevant part. If Google was founded in Japan and Apple in Brazil, it would still be foolish to entrench them as a dependency. It would barely even be better to do it with a local company. > They will move their data it the EU (where else? China?). Th…
Relying on open protocols to make all the difference is much more potent hopium than what GP wrote. Open protocols are kind of thing techies do when in cooperative mode, when industry isn't looking. But this is not this kind of problem - this is an economic, geopolitical problem. It's not about your local school moving off Windows to Linux, it's about the European corporations moving off Azure to some other cloud sol…
i am not advocating for a pure "open source will save the world" there are just a few points i'd like you to consider, and hopefully give me insights i can learn from
* other than code, open source has also given us governance "experiments" capable of running critical systems. As another poster was mentioning, the risk is to fallback on "big corps", usually run by "big man", and we are back to zero. The hope? expectations? is that the open source governance ecosystem has tackled this space in enough dimensions to be able to build something over this. I am looking specifically at the area around licenses (mariadb, redis, ...) and just overall governance frameworks, as in "deteach business ownership from ethical frameworks"
* in order to build anything this big/reliable, without megacorp budgets, you can just ... pay FLOSS? They are one of the 2 majorly screwed groups by the current SV setup (with PLENTY of cavaets,amongst them that SV is a huge open soure contributor) The other one being content creators. Slogan? "For this to succeed, you need the best coders and the best marketing departments in the world" Looks to me like incentives are aligned towards them being available. Talking broadly on a systemic level: details need refinement, and space beyond this single message.
* EU (the political instituion) desperately needs this. An innovative tech ecosystem (not startup, not product) driven by "european values" that puts them on the spot. Start with redefining it: there are no users, but citizens. Something effectively out-innovating SV, not just trying to get on par. The risk of "being bought out/copied" doesn't really apply, since (as I said in my original comment) the discriminator is existential: US companies cannot be trusted because they built the existing system. Any attempt to block this (stop users from getting their data back) is going to be challenged by the EU (GDPR violations cannot be brought to court by citizens, only by nation's data authorities, which means a citizen gets big guns and doesn't ned to pay). Also, go on and explain that to all you other (US and not) users.
* A EU cloud provider doesn't have to provide the same services an US provides. That would hardly be innovative. You also don't need to focus on corporations. Provide data storage for citizens, that will be the basis to build a privacy focus cloud, and then business might want that. There is a possible continuation into "advantages of storage&privacy based vs compute", that i skip.
But essentially, to me it seems that an open source, true, "give me back my data" business driven initiative has never been as actionable as now. I short, such a project can make 2 bold statements "We are more innovative than SV" "We have better freedoms than the US"
Re: German implementation of eIDAS will require an Apple/Google account to function
#273German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
You should think about how easy it is to permanently lose access to your Google account for very trivial issues and Google doesn't offer any form of recovery. That in addition to the current geopolitical situation should be reason enough not to rely on that for any justification. And personally as a software developer myself i know that nothing is more permanent than a temporary solution. No one will prioritize or gi…
Re: German implementation of eIDAS will require an Apple/Google account to function
#274Earlier quoted context omitted.
Tbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.
Banks actually have high fraud rates today because of weak security mechanisms. If attackers steal your money, the bank will reimburse you. If attackers steal your identity, you are really screwed. Security requirements for banking and identity are simply different.
Re: German implementation of eIDAS will require an Apple/Google account to function
#275German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
The device chain is a classic misdirection, it seems everyone here is just following Meta’s lobbying to put this into the OS.
Even the carrier layer would be better than the mobile device layer.
Or, you know, just look at Singapore’s or Swiss National SSO - it functions on an app that layer just fine, no issues
See https://github.com/eu-digital-identity-wallet/eudi-app-andro...
Re: German implementation of eIDAS will require an Apple/Google account to function
#276Earlier quoted context omitted.
Sorry but this is nonsense - most users, even the Linux toting power users - don't have the time, ability or knowledge to verify the contents of their OS in a way that would catch issues prevented by attestation. The problem with modified phones containing malware is very real and unless you want a full on Apple "you're not allowed to touch the OS" model you need some kind of audited OS verification that you as a use…
No, what you're saying is nonsense. I can burn a key into efuses of this phone to make it only boot things signed by me and make the whole boot path verified, OS image immutable etc. and all of this can provide me some value, but it's absolutely not in my interest to let applications be picky on what can or can't happen in the OS (even if they would accept my key being there rather than Google's, which they won't). T…
But to remove that incentive you first need to stop punishing app companies for compromised user OSes from legal perspective.
Are you willing to absolve Google, Apple and Deutsche Bank from responsibility of damage that happens on compromised user OSes?
Re: German implementation of eIDAS will require an Apple/Google account to function
#277Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.
Maybe that will force the companies to not be allowed to just lock you out of the account.
Re: German implementation of eIDAS will require an Apple/Google account to function
#278Earlier quoted context omitted.
Sorry but this is nonsense - most users, even the Linux toting power users - don't have the time, ability or knowledge to verify the contents of their OS in a way that would catch issues prevented by attestation. The problem with modified phones containing malware is very real and unless you want a full on Apple "you're not allowed to touch the OS" model you need some kind of audited OS verification that you as a use…
There's also a problem with unmodified phones containing malware, namely an operating system made by an advertising company, which is designed to collect as much information about you as possible. And this malware is largely based on open source code (Linux) that was originally developed on open, documented hardware, where the firmware boot loader did nothing more than load the first 512 bytes of your hard disk to ad…
Re: German implementation of eIDAS will require an Apple/Google account to function
#279German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
We're talking about a state-issued digital identity system, the European equivalent of your ID card, that cannot function without accounts at two US corporations. That's not a UX limitation. That's a structural dependency on foreign infrastructure for core state sovereignty.
The concerns aren't abstract. The US has a documented history of mass surveillance programs (PRISM, XKeyscore) that directly targeted European citizens and governments. Both Apple and Google operate under US jurisdiction, which means CLOUD Act requests, national security letters, and executive pressure are all legal avenues for US government access. PlayIntegrity is explicitly described in your own architecture docs as a black box: "we do not know what they are actually doing in their backend." A critical security component of a state identity system, and you don't know what it does. That's not an engineering trade-off, that's an accountability gap.
GrapheneOS being "on the list" is not reassuring. It means the system launches in a state where European citizens who have actively chosen to reduce their dependence on US Big Tech are excluded from their own national digital identity infrastructure.
The EU passed GDPR to establish digital sovereignty. It's building eIDAS to establish identity sovereignty. Baking in a hard dependency on Google and Apple at the attestation layer undermines both, by design, at launch.
Re: German implementation of eIDAS will require an Apple/Google account to function
#280Earlier quoted context omitted.
Do people outside of Europe do not understand how Germany is just a small fraction of Europe.
While true, it influences a lot in the EU