Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

351–360 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#351
post #214

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Do all German hospitals serve vegan food?

If you were averse to carrots (without any health restrictions on eating them), would every government institution in Germany be required to serve you carrot-free food?

If not, why should they be forced to accommodate every smartphone brand in existence, even if there's only 3 people in Germany using it? THe list has to end somewhere.

Re: German implementation of eIDAS will require an Apple/Google account to function

#352

Earlier quoted context omitted.

Nobody is seriously discussing speed limits right now ...

all speed limits in highways are stupid. It should be follow distance enforcement instead.

Single-vehicle accidents exist.

Re: German implementation of eIDAS will require an Apple/Google account to function

#353

Earlier quoted context omitted.

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Operate European tech infrastructure without a dependency on America challenge (Impossible) For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account. Why remove a dependency on Google, when you'll still be 100% dependent on Google? Anybody working on "Digital ID" has alre…

It's an objection to adding a new dependency, not an attempt to remove an existing one. If we can't stop adding new dependencies, we are certain to be stuck with the status quo forever.

Re: German implementation of eIDAS will require an Apple/Google account to function

#354

Earlier quoted context omitted.

> The ability for us as users to lie to the apps is actually essential to preserving our agency. Without that we're screwed, as now to connect ourselves to the fabric of the society we'll need to find and exploit vulnerabilities that are going to be patched as soon as they become public. The same freedom is being abused by malicious actors. Even on Windows (like BlackLotus), but also on pre-infected phones emptying p…

A lot of other freedoms are being abused and always have been, but somehow we don't go and ban kitchen knives, as having them around is valuable. This is a false dichotomy. Systems can be secure and trusted by the user without having to cede control, and some risks are just not worth eliminating. Most importantly - it's the user who needs to know whether their system has been tampered with, not apps.

> somehow we don't go and ban kitchen knives

False analogy. You can’t have your kitchen knife exploited by a hacker team in North Korea, who shotgun attacks half of the public Internet infrastructure and uses the proceeds to fund the national nuclear program, can you? (I somewhat exaggerate, but you get the idea.)

> Systems can be secure and trusted by the user without having to cede control

In an ideal world where users have infinite information and infinite capability to process and internalize it to become an infosec expert, sure. I don’t know about you, but most of us don’t live in that world.

I agree it’s not perfect. Having to use liquid glass and being unable to install custom watch faces is ridiculous. There’s probably an opportunity for a hardened OS which can be trusted by interested parties to not be maliciously altered, and also not force so many constraints onto users like current walled gardens do. But a fully open OS, plus an ordinary user who has no time or willingness to casually become a tptacek on the side, in addition to completely unrelated full-time job that’s getting more competitive due to LLMs and whatnot, seems more like a disaster than utopia.

Re: German implementation of eIDAS will require an Apple/Google account to function

#355

Earlier quoted context omitted.

It should be legally required to provide enough interoperation capabilities for a compatible frontend to be written for an Apple II by whoever would like to do that, as the government can't be expected to write and maintain clients for every platform that's now in existence or that will be created in future. If only currently popular platforms are to be supported, how could a new platform join them in the future if t…

> If only currently popular platforms are to be supported, how could a new platform join them in the future if the use of existing ones is mandated by governments? The viable solution for that is to provide a trusted hardware implementation that can be used with any computing platform that has a documented interface. It can't be a software-only implementation, basically.

Glad you mentioned this possibility

Countries have centuries of experience providing attestation services through notaries. Germany is even infamous for requiring them for things that would sound ridiculous even in Brazil (both movie and country)

I can’t see why governments couldn’t incorporate this existing infrastructure into the digital world. Make them sell hardware ID wallets, enforce the real identity owner to be present to invalidate a previous ID or whatever, and add legal restrictions for the government not be able to alter these registries

Re: German implementation of eIDAS will require an Apple/Google account to function

#356
post #91

Earlier quoted context omitted.

Simple, provide a simple API, let the community build the clients for the machines they have.

That's antithetical to the goal of a secure ID. It has to be really impossible to get stolen, or as difficult as a physical card. If the ID is just a password, you can tell other people your password, and it can be stolen, and it can be cloned. Germany is a strict liability country, and you will be fined or imprisoned for anything that is done with your identity card that was cloned because your PC was infected by ma…

And as we know it is impossible to give someone your physical card.

Re: German implementation of eIDAS will require an Apple/Google account to function

#357
post #30

I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.

I'm not. Parents are very much in favour of restrictions on what can be accessed online.

Parents can't control what their children are doing 24/7, and neither should they. But they should expect a society where children are protected from billion dollar corporations stealing their attention and radicalising them, at least until they are old enough to leave mandatory schooling.

There are many "real world" age restrictions that exist, and we have decided those are of benefit to society in general. The "online world" is no different.

If we can't have age restrictions online then they should just be abolished in the real world as well, in the name of preserving "privacy and freedom". The online world doesn't exist in isolation like it did in the 90s and 00s.

Re: German implementation of eIDAS will require an Apple/Google account to function

#358

Earlier quoted context omitted.

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Operate European tech infrastructure without a dependency on America challenge (Impossible) For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account. Why remove a dependency on Google, when you'll still be 100% dependent on Google? Anybody working on "Digital ID" has alre…

Step by step. We realize we will not get there in one day.

Its the same as with bicycle paths. Initially - those make no sense, leading from nowhere to nowhere. Give it a few years, and a usable network emerges.

Right now there is serious money and brainpower being poured into sovereign cloud tech. Thanks to the gift of open source and standards, its actually not impossible to create modern systems with zero US dependency.

I fear, though, that as with everything else Microsoft Excel will be the hardest dependency to deal with.

Re: German implementation of eIDAS will require an Apple/Google account to function

#359

Earlier quoted context omitted.

Users have the right to modify any app running on their own device. Software security should never depend on the user having no control over their own device. Smartphones are essentially just regular computers, and on them you can use a debugger and do whatever you want. Viewing smartphones as closed systems like game consoles where you need the manufacturer’s permission for everything only leads us into the dystopia…

Once SafetyNet was brought to Android a decade ago the tendency has been clear - these freedoms are going to be restricted heavily. Because how do you make sure it's the user who does those modifications, willingly and well-informed? That it's not a malicious actor, not an user getting socially engineered or phished? Incredibly difficult compared to the current alternative. If it's not a software root of trust that p…

[dead]

Re: German implementation of eIDAS will require an Apple/Google account to function

#360

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

I think it should be possible IMHO, like it is for many banks (still), to get a hardware token and then use whatever hardware/browser. Even a nice EU hardware token which allows banks , govs etc to add their keys/seeds in the enclave would be nicer so I don't have the lug 1000 tokens around, but it's still better than having to trust non sovereign companies for anything without backup; like multiple here said; Google…

The hardware tokens ate being phased out by banks and replaced with SMS OTP codes + passwords.

Cost saving measures.

Its funny to see that I can access the bank account through FaceID but to actually make a payment I need to use an SMS code.

Post reply on HN