Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

321–330 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#321
post #62

Earlier quoted context omitted.

I think because most people, even tech savvy ones don’t understand how this might effect their lives. It’s too abstract. At least how it’s portrayed here. Contrast that with chat control. My government can read my WhatsApp messages? Not good! What’s the non-technical narrative here?

The non-technical narrative is very simple: Google, Apple, or the German government can revoke your ID at any time. You cannot purchase or sell anything[1], sign any contracts, have a job, rent an apartment, use public transportation, or receive any kind of government services without an ID. This should sound extremely alarming to everyone regardless of technical knowledge. [1] Maybe with cash, for now, but cash is c…

It also makes you sound like a conspiracy theory nutjob, and the current political climate in Europe is such that people are really sensitive to this sort of alarmist messaging (which they erroneously perceive as fascist rhetoric) and will not listen to you because they don't want to be associated with those people.

I don't think we can win this fight. Personally I tried to advocate against eIDAS in Austria and I've had negative success. After my warnings, people like it more.

"Oh, it's an EU thing? it must be good!".

Re: German implementation of eIDAS will require an Apple/Google account to function

#322

Earlier quoted context omitted.

What if I don’t have a smartphone?

No one is required to use EUDI: https://ec.europa.eu/digital-building-blocks/sites/spaces/EU... Companies and providers (like banks) have to support it, but use is voluntary. Check out the spec and legal framework, it actually makes sense and is open to different implementations, though you might need to certify it.

You are not required to accept anything other than digital ids. So from experience, whatever demands euid has will be what is required to identify you.

Re: German implementation of eIDAS will require an Apple/Google account to function

#323
post #90

I'm not quite sure if the German implementation is possible without mobile devices (couldn't find anything on that at first glance). the Austrian implementation on the other hand does not require a mobile device, if you want to do it on a pc you just need a fido2 token

As strange as it is, but Austria is quite far ahead in terms of eIDAS since we've had Handysignatur for more than a decade. I wouldn't be surprised, if the Germans are planning to support hardware tokens, but haven't had the time yet.

> Austria is quite far ahead

Yeah, quite ahead in terms of making anonymous phone numbers illegal and requiring the government to know your phone number.

And if you don't want to use a smartphone, ID Austria does not work with regular FIDO security keys, you need special ones. Same for the old SmartCard system which didn't work without government-mandated malware.

Re: German implementation of eIDAS will require an Apple/Google account to function

#324

Earlier quoted context omitted.

It's not just that "user experience is worse", it's an existential threat to Free Software. In the past, when you had a proprietary tool you needed to use to do something, people could analyze and reimplement it. The reasons to do that varied - someone needed "muh freedomz", someone else wanted to do the thing on an unsupported platform, someone else wanted to change something in the way the tool worked (perhaps anno…

> The ability for us as users to lie to the apps is actually essential to preserving our agency. Without that we're screwed, as now to connect ourselves to the fabric of the society we'll need to find and exploit vulnerabilities that are going to be patched as soon as they become public. The same freedom is being abused by malicious actors. Even on Windows (like BlackLotus), but also on pre-infected phones emptying p…

A lot of other freedoms are being abused and always have been, but somehow we don't go and ban kitchen knives, as having them around is valuable. This is a false dichotomy. Systems can be secure and trusted by the user without having to cede control, and some risks are just not worth eliminating.

Most importantly - it's the user who needs to know whether their system has been tampered with, not apps.

Re: German implementation of eIDAS will require an Apple/Google account to function

#325

Earlier quoted context omitted.

We're talking about an essential government service, not just another weather app. You have to look at this through the lense of national security, the debate about EU digital sovereignty, and the requirements of the GDPR in light of the US CLOUD Act, as well as prior decisions of EU courts about these issues.

Yes all that you wrote is true. But that does not magically change anything to what I previously stated: in the real world all smartphones are either Apple or Android... I don't know what the eIDAS 2.0 requires in term of security but it may make the choice the implementers made here unavoidable in practice, as hinted by @webhamster. If so, it seems that a solution, if technically possible, might be to mandate that O…

correction. in the real world all smartphones are either apple, android or none/other. in terms of legals, you really do have to cater to all three, which is why we don't have one world government.

Re: German implementation of eIDAS will require an Apple/Google account to function

#326
post #229
post #90

I'm not quite sure if the German implementation is possible without mobile devices (couldn't find anything on that at first glance). the Austrian implementation on the other hand does not require a mobile device, if you want to do it on a pc you just need a fido2 token

I havent looked into the details of either, but what would prevent Germans from using the Austrian implementation?

Austria provides their implementation only to people with Austrian citizenship or people working in Austria

Re: German implementation of eIDAS will require an Apple/Google account to function

#327
post #284

Earlier quoted context omitted.

> That doesn't work without operating system support Do you realize where this path is going? Certain European governments would have greatly benefited from KYC/attestation in the late 1930s had it existed.

Yup. But apparently the EU is refusing to take lessons from history.

Germany is just part of EU - as many other people pointed out, there is no requirement from the EU to implement it this way. Same as California or New York making extremely Draconian laws around 3D printing doesn't represent all of US.

Re: German implementation of eIDAS will require an Apple/Google account to function

#328

Earlier quoted context omitted.

I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…

Users have the right to modify any app running on their own device. Software security should never depend on the user having no control over their own device. Smartphones are essentially just regular computers, and on them you can use a debugger and do whatever you want. Viewing smartphones as closed systems like game consoles where you need the manufacturer’s permission for everything only leads us into the dystopia…

Once SafetyNet was brought to Android a decade ago the tendency has been clear - these freedoms are going to be restricted heavily.

Because how do you make sure it's the user who does those modifications, willingly and well-informed? That it's not a malicious actor, not an user getting socially engineered or phished? Incredibly difficult compared to the current alternative.

If it's not a software root of trust that provides an attestable environment like Android or iOS. It's going to be a hardware root of trust that provides an attestable hardware environment, like SGX. I can predict no other practical avenue taken. Unless the orangutan really forces a demonstration on how untrustworthy these environments can be and a lot of money and effort is spent.

Re: German implementation of eIDAS will require an Apple/Google account to function

#329

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Will eIDAS be the only way to identify yourself in cases where it's needed, or will we be able to user other mechanisms like the german ID card stuff or an entirely separate alternative? Or to put it another way, is a smartphone required? If not, that would already clear up a lot of issues, I think. EDIT: Whoops, just saw the answer to another comment asking precisely this. So it's not a requirement. Good. Is there a…

One datapoint: at least in practice, it used to be impossible to delete an entry in the French INPI database (trademarks and company names) without eIDAS. It forced me to unearth an old unmodified Android phone (I run LineageOS on my main phone).

If you read French:

* https://www.plus.transformation.gouv.fr/experiences/4531155_...

* https://linuxfr.org/users/jch-2/journaux/l-identite-numeriqu...

Re: German implementation of eIDAS will require an Apple/Google account to function

#330

Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.

There are no alternatives.

I mean you could use Huawei and others, but the FUD campaigns against chinese manufacturers was pretty agressive in the EU.

Post reply on HN