Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

341–350 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#341

Earlier quoted context omitted.

> let every citizen use whatever computer they want. That's just not possible, or should the system be legally required to run on an Apple II?

It should be legally required to provide enough interoperation capabilities for a compatible frontend to be written for an Apple II by whoever would like to do that, as the government can't be expected to write and maintain clients for every platform that's now in existence or that will be created in future. If only currently popular platforms are to be supported, how could a new platform join them in the future if t…

> If only currently popular platforms are to be supported, how could a new platform join them in the future if the use of existing ones is mandated by governments?

The viable solution for that is to provide a trusted hardware implementation that can be used with any computing platform that has a documented interface. It can't be a software-only implementation, basically.

Re: German implementation of eIDAS will require an Apple/Google account to function

#342
post #306

Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.

So what can be used as an attestation API? WHAT will make sure that when a phone says "you're paying 10 euro to $coffee_place" that it isn't a bitmap being shown over "you're paying 10.000 euro to $scammer", above the pay button. Note: needs to be a real guarantee that isn't a permission question away from going away. Either governments can develop (and pay for) THAT technology, or they can use Apple/Google ...

That seems like a weak argument to require attestation? What would attestation prevent that scenario, specifically?

Re: German implementation of eIDAS will require an Apple/Google account to function

#343

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Side question. How come it is always the most incompetent people who get put in charge of implementing things like that. Over and over apps and services are developed in Germany and completely fail at what they are supposed to achieve. Where are these people recruited from?

Re: German implementation of eIDAS will require an Apple/Google account to function

#344

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…

Well, in that case, if they want full control and attestation yadda yadda, I'm fine with them shipping me a device they fully control exclusively for use of this stuff. But if we're talking about my smartphone that I paid for with my money that I worked for, I will do whatever I damn please with it. So I guess that means eIDAS will be inaccessible to me.

Re: German implementation of eIDAS will require an Apple/Google account to function

#345
post #343

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Side question. How come it is always the most incompetent people who get put in charge of implementing things like that. Over and over apps and services are developed in Germany and completely fail at what they are supposed to achieve. Where are these people recruited from?

[dead]

Re: German implementation of eIDAS will require an Apple/Google account to function

#346

Earlier quoted context omitted.

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Why would this be? Bureaucracy / inability to change?

Several reasons I can think of:

1. Google and Apple have a much larger ecosystem and are entrenched in their OSes, which means that they have a much better picture of the user than any government app ever will. They also have surveillance mechanisms that government apps are unable or unwilling to implement. This helps detect and prevent fraud (fraud prevention is mostly just mass surveillance used for good).

2. The eIDAS standards enable anonymous assertions about your identity. This lets you prove your age to a website / app without revealing any other information. There needs to be a way to prevent you from generating millions of such assertions using one ID and giving them out online to anybody who wants them, verified or not. The way you do that is by limiting their generation to trusted hardware, using hardware attestation mechanisms. Google and Apple provide those.

3. Pure laziness. It's an issue that <1% of the population cares about (which is hard to notice if you're in the HN bubble). Almost nobody uses a modern, eIDAS capable smartphone without a Google or Apple account. They may have decided that the part of the population who cares about this just isn't worth pandering to (just like some government institutions may decide that vegans aren't a part of the population they're interested in pandering to).

Re: German implementation of eIDAS will require an Apple/Google account to function

#347
post #302

Earlier quoted context omitted.

Operate European tech infrastructure without a dependency on America challenge (Impossible) For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account. Why remove a dependency on Google, when you'll still be 100% dependent on Google? Anybody working on "Digital ID" has alre…

You can just as well say "the correct reaction to having a guns aimed at your head is NOT to give the guy another gun ... you know, in case the first one fails to fire when he starts pulling triggers". Plus, the net difference is that this gives Google and Apple the ability to kill the ability of individuals to make payments (and tax them) ... do you want that? (And I would say, compared to having European banks tax…

Oh, but Google doesn't really excel in making phones "secure".

Sure, their researchers are great, but Google itself claims that several years old phones running Oreo are safe and secure. They also extended the time for vendors to bring patches to the new vulnerabilities, they themselves slowed down - compare timeframe between patches released by GrapheneOS and patches released by Google - the latest GOS release provides patches for vulnerabilities that will be fixed by Google in.... October 2026: https://grapheneos.org/releases#2026040300

Re: German implementation of eIDAS will require an Apple/Google account to function

#348
post #266

Earlier quoted context omitted.

I’m sorry to lash out at you but I keep getting disappointed in European countries (more precisely the ever disappointing EU commission) all suffering of the NIH syndrome instead of collaborating and learning from each other

There is mothing to be gained politically by doing this. You think you look good if you say “hey, the Poles had this really good idea, how about we do the same”? Plus, the process is something like: - we want to do $something - hire consultants to help us define $something and produce a document - hire other consultants to write the specs for the project - launch an RFP - select a winner - wait for the implementation…

> You think you look good if you say “hey, the Poles had this really good idea, how about we do the same”?

Yes.

> You think if there was any will wouldn’t the whole EU use whatever the Estonians are doing very well?

Using the Estonian system would be vastly preferable.

If politics doesn’t allow that, the political environment is broken.

Re: German implementation of eIDAS will require an Apple/Google account to function

#349
post #303

Earlier quoted context omitted.

Why would this be? Bureaucracy / inability to change?

It is to move the burden of securing payments ("did the user actually, willingly, to the satisfaction of a court of law, initiate this payment?") onto Google and Apple. Either the government secures internet payments themselves, which means spending now to do so, coming up with a plan, ... or they can have Apple/Google do it.

I thought this was about identity, though, not securing payments. Isn’t that sufficiently tackled with the digital signature?

Re: German implementation of eIDAS will require an Apple/Google account to function

#350
post #306

Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.

So what can be used as an attestation API? WHAT will make sure that when a phone says "you're paying 10 euro to $coffee_place" that it isn't a bitmap being shown over "you're paying 10.000 euro to $scammer", above the pay button. Note: needs to be a real guarantee that isn't a permission question away from going away. Either governments can develop (and pay for) THAT technology, or they can use Apple/Google ...

I'm not sure I want my government to develop that technology.

Government software is usually low-quality, expensive procurement crap, often riddled with security holes, and an exercise in checkbox checking. UX and user friction can't be expressed as a verifiable clause in a procurement contract, so they're ignored.

Besides, every time EU governments tried to force smartphone manufacturers to pre-install government apps, the population freaked out over (unwarranted) surveillance concerns. This isn't something you can do without pre-installing apps (you don't want these APIs opened up because then attestation loses all meaning).

Post reply on HN