Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

281–290 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#281

It makes no sense. eIDAS 2.0 specs don't require specific hardware [0]. They basically store verifiable credentials [1] and any other cryptographically signed attestations. This feels like laziness from German implementers, as they don't want to (quoting the spec literally) "implement a mechanism allowing the User to verify the authenticity of the Wallet Unit". 0: https://eudi.dev/latest/architecture-and-reference-fr…

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

I don't feel they resist. Quoting them:

> We understand your concerns and truly appreciate your suggestions. As previously mentioned, this is not something that is enforced by the reference implementation — these are simply recommendations, not requirements, for any wallet implementer. That said, we recognize that this is a sensitive topic, and we may need to revisit it, even at the level of recommendations.

> The README files for both the iOS and Android Wallets have been updated to mention only OWASP MASVS compliance, without referencing any specific APIs.

I understand their position, but I also get the concern, especially around existing implementations like the Italian app. I think it's mostly that they have different priorities than ensuring that the reference implementation is a perfect guideline for member states.

This looks like a good vector for a European Citizen Initiative around removing all technological dependency on non-EU providers.

Re: German implementation of eIDAS will require an Apple/Google account to function

#282

It makes no sense. eIDAS 2.0 specs don't require specific hardware [0]. They basically store verifiable credentials [1] and any other cryptographically signed attestations. This feels like laziness from German implementers, as they don't want to (quoting the spec literally) "implement a mechanism allowing the User to verify the authenticity of the Wallet Unit". 0: https://eudi.dev/latest/architecture-and-reference-fr…

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Operate European tech infrastructure without a dependency on America challenge (Impossible)

For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account.

Why remove a dependency on Google, when you'll still be 100% dependent on Google?

Anybody working on "Digital ID" has already made peace with the fact that it can be turned off overnight if Trump says so.

Re: German implementation of eIDAS will require an Apple/Google account to function

#283
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Do we have stats how many germans use something else than Google Android, Samsung Knox or Apple? I recon it should be less than 1% which quite honestly is in fact „all“ citizens.

Sure, let's just arbitrarily exclude ~1million people because they're not running the government's preferred American spyware.

Re: German implementation of eIDAS will require an Apple/Google account to function

#284

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

> That doesn't work without operating system support Do you realize where this path is going? Certain European governments would have greatly benefited from KYC/attestation in the late 1930s had it existed.

Yup. But apparently the EU is refusing to take lessons from history.

Re: German implementation of eIDAS will require an Apple/Google account to function

#285
post #5

So what was the point of putting a crypto chip into every ID if you are gonna try and reinvent the entire trusted environment in the fucking smartphone?

ID cards don’t connect to the internet. These days an ID system that doesn’t work online is next to useless.

It's an NFC card that can be read with any NFC card reader, USB or smartphone based.

https://www.ausweisapp.bund.de/en/open-source I just saw that it's available in alpine.

So I tried installing it on my postmarketOS smartphone and it runs out of the box: https://i.imgur.com/nRIAyrq.png

My Shift6mq is listed has not having NFC support in postmarketOS, so I can't actually test it, but I assume the USB card reader option will work once it's supported.

Re: German implementation of eIDAS will require an Apple/Google account to function

#286

ISO7816 (smartcard) has existed for nearly 4 decades as the standard secure identity card, widely used by the banking industry among others. Very unintrusive and not hostile beyond needing to carry a little chip. If governments want a national ID, they could just give everyone one of those.

Belgium has had exactly this for decades. But now they want to get on the hype train for smartphone based ID, because card reader support is still shit in browsers in 2026.

Adding to this: anyone older than 12 years old is required by law to have their government issued ID on them at all times when in public. If your ID is suddenly your smartphone, you're essentially required to have that on you 24/7. Dystopian spyware.

Re: German implementation of eIDAS will require an Apple/Google account to function

#287

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Shouldn't the energy instead be focused on creating a standardized eIDAS driver API that OS vendors are required to implement?

Re: German implementation of eIDAS will require an Apple/Google account to function

#288

Earlier quoted context omitted.

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Operate European tech infrastructure without a dependency on America challenge (Impossible) For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account. Why remove a dependency on Google, when you'll still be 100% dependent on Google? Anybody working on "Digital ID" has alre…

On Android you don't need to sign in with a Google account. You do need it for the play store but many brands have alternatives. Like the Samsung app store, Honor has their own too, I'm sure more brands do. And there's always aurora.

Yes not many use it but if you cut this path off then people will never get there.

Re: German implementation of eIDAS will require an Apple/Google account to function

#289

Earlier quoted context omitted.

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Operate European tech infrastructure without a dependency on America challenge (Impossible) For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account. Why remove a dependency on Google, when you'll still be 100% dependent on Google? Anybody working on "Digital ID" has alre…

Being able to install whatever apps you want on Android without any sort of dependency on a Google signature or API was the standard for a decade and a half.

Let's not act like things have always been this bad and thus we should just accept it as the norm, because they haven't, the noose is actively tightening as time goes on.

Re: German implementation of eIDAS will require an Apple/Google account to function

#290

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

> The initial limitation to Google/Android [...] is simply a matter of where we focus our energy at the moment

Nice... so the rush is to delegate power to the large American platform?

Post reply on HN