Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

291–300 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#291

Earlier quoted context omitted.

Or someone could be getting kickbacks on the down low.

Or it's just way easier to implement this way and they don't want to waste time on stuff only HN crowd cares about ?

Implementing Play Integrity is something developers have to go out of their way to do. Not implementing it requires literally zero effort. So no, it's not easier to do it this way.

Re: German implementation of eIDAS will require an Apple/Google account to function

#292

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

> We have to use some kind of attestation mechanism per the eIDAS implementing acts.

Sounds like these "eIDAS implementing acts" are the problem, and were influenced by ulterior motives.

Re: German implementation of eIDAS will require an Apple/Google account to function

#293

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

> The initial limitation to Google/Android is not great

It’s also illegal on both accessibility grounds as well as violating the eIDAS spirit of no dependency on specific providers.

By shrugging it off as “not great”, you’re also dooming every citizen to have to comply with whatever whimsical terms of service Google and Apple have.

Have you ever tried to unban your Apple/Google account? So in effect, everyone’s access to eID services will depend on some crappy automation some intern in California setup to detect “abuse” or whatever.

There are technical solutions to avoid this dependency and you’re probably getting paid to find, research and adopt them. So … do your job?

Re: German implementation of eIDAS will require an Apple/Google account to function

#294
post #270

Earlier quoted context omitted.

Yes congratulation, you get to benefit from a lot of regulated and subsidized things: housing, education and transportation. While enjoying a high paying job in probably a still very unregulated domain (computers/internet related). This is not about one country vs another. The problem is you cannot have a society with everybody winning on both fronts unfortunately. You also need people making, cleaning stuff, growing…

> Vienna is probably not food self sufficient No, but Austria is. And our farmers enjoy much support through subsidies - from the EU and our own budget - and social protections, often having better and cheaper health care than most other Austrians, since they are insured under their very own social insurance law (BSVG), contrary to other employees (ASVG) and self-employed (GSVG). Farmers also enjoy very high levels o…

> And our farmers enjoy very high levels of subsidies

Yes, thanks. This was my original point "the agriculture sector hold by a string". It is by design unsustainable and if you cut those "high levels of subsidies" it collapses.

> Calling Information Technology an 'unregulated domain' in the EU when we're all busy implementing NIS2 regulation and preparing for the Cyber Resilience Act entering into force soon seems disingenuous.

Yes this is why I said "still"

Re: German implementation of eIDAS will require an Apple/Google account to function

#295
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Do we have stats how many germans use something else than Google Android, Samsung Knox or Apple? I recon it should be less than 1% which quite honestly is in fact „all“ citizens.

In fact „all“ citizens who are willing to be surveilled by Google and Apple, unless German government provides each citizen with similar eID hardware there won't be any digital equality any time soon. Maybe they should pay to some subsidiary company of IBM (like RedHat) to do this, they already have such a good track record of storing nationality on their machines /s

https://en.wikipedia.org/wiki/Dehomag#Holocaust

Re: German implementation of eIDAS will require an Apple/Google account to function

#296
post #231

Earlier quoted context omitted.

Tbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.

Banks actually have high fraud rates today because of weak security mechanisms. If attackers steal your money, the bank will reimburse you. If attackers steal your identity, you are really screwed. Security requirements for banking and identity are simply different.

If they use SSN as a password, it doesn't mean you can't have something slightly more reasonable without going full cyberpunk dystopia.

Re: German implementation of eIDAS will require an Apple/Google account to function

#297
post #260

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

In light of all of these shortcomings with platform attestation, why go with the eIDAS 2 wallet approach at all? eIDAS 1 already solved this with Mobile-ID (SIM-based, no Google/Apple dependency) and Smart-ID (server-side key management with minimal platform reliance). What does the wallet model give you that justifies this level of dependency on two American corporations’ proprietary backends? Especially considering…

Isn't the eIDAS 2 wallet approach a legal requirement of eIDAS 2 (which is an EU regulation, i.e. the law).

Re: German implementation of eIDAS will require an Apple/Google account to function

#298

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

[deleted]

Re: German implementation of eIDAS will require an Apple/Google account to function

#299

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

This is simply unacceptable. You are not making an innocent pragmatic compromise here, you are launching digital infrastructure which initially will tie everyone to Google/Apple and give alternatives a huge disadvantage for an unknown amount of time. Nobody knows when, or even if ever, support for open platforms will arrive.

You should be ashamed of being involved in this monopoly handover to American big tech.

Re: German implementation of eIDAS will require an Apple/Google account to function

#300
post #260

Earlier quoted context omitted.

In light of all of these shortcomings with platform attestation, why go with the eIDAS 2 wallet approach at all? eIDAS 1 already solved this with Mobile-ID (SIM-based, no Google/Apple dependency) and Smart-ID (server-side key management with minimal platform reliance). What does the wallet model give you that justifies this level of dependency on two American corporations’ proprietary backends? Especially considering…

Isn't the eIDAS 2 wallet approach a legal requirement of eIDAS 2 (which is an EU regulation, i.e. the law).

It is, mandated by the EU commission.

Instead they could have mandated the use of eIDAS 1 to all countries + extend it with attribute/credential support, and let countries choose their implementation (cards, SIM, server-side).

Instead we’re back to the drawing board with the big shortcomings highlighted in this thread.

Post reply on HN