Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

361–370 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#361
post #306

Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.

So what can be used as an attestation API? WHAT will make sure that when a phone says "you're paying 10 euro to $coffee_place" that it isn't a bitmap being shown over "you're paying 10.000 euro to $scammer", above the pay button. Note: needs to be a real guarantee that isn't a permission question away from going away. Either governments can develop (and pay for) THAT technology, or they can use Apple/Google ...

In case of Android - AOSP attestation.

Not necessarily the company that locks out entire family because one of the family member jacked off on the chat with Gemini model.

Re: German implementation of eIDAS will require an Apple/Google account to function

#362

Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.

Maybe that will force the companies to not be allowed to just lock you out of the account.

You, your siblings, your parents, etc, etc.

Re: German implementation of eIDAS will require an Apple/Google account to function

#363

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

This is simply unacceptable. You are not making an innocent pragmatic compromise here, you are launching digital infrastructure which initially will tie everyone to Google/Apple and give alternatives a huge disadvantage for an unknown amount of time. Nobody knows when, or even if ever, support for open platforms will arrive. You should be ashamed of being involved in this monopoly handover to American big tech.

Fingers crossed for the judiciary - if the implementers ignore the intention of the law, then lawyers will have to help them understand the limits of corner cutting - and block this.

Re: German implementation of eIDAS will require an Apple/Google account to function

#364

Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.

Yes but in the real world all smartphones are either Apple or Android. Europe has zero footprint in either software or hardware. It is not creating a requirement to use specific products, it is using the products people already have. So one may argue that the implementers are only taking the pragmatic approach regarding something that is out of their hands.

It literały has created the dependency on google when thought Android offers the standard/generic AOSP attestation.

Also you weirdly forget all the Chinese phones. There's also some tiny European brand which will have absolutely no way to limit their users dependency on the famously hostile and unconctactable provider.

Re: German implementation of eIDAS will require an Apple/Google account to function

#365

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

Exactly this. And whats more, the idea of device attestation makes people trust those devices, and the history of rooting consoles and phones proves that nothing holds, even tech backed by billions in commercial interest.

The whole point in reducing the blast radius is valid - by all means make this optional and allow the user to elect to tie their identity to the device. For everyone else, implement validation of actual transactions, not just user secrets and device secrets.

Re: German implementation of eIDAS will require an Apple/Google account to function

#366
post #172

Earlier quoted context omitted.

> The current policy trend in the EU is definitely not based on the principle of each user evaluating their own risk. Yes and if you look back this is not new. Just look at the extraordinary restrictions that apply to: - What houses you can build, - What vehicle you can drive, - What food you can grow and sell. The result is real estate has become unaffordable for younger people, our car industry is being annihilated…

I really have to wonder where in the EU you live. In Vienna, I got to buy an apartment in my mid-twenties by just saving up, which was easy, as many apartments are rent-capped and there's lots of cheap social housing. I got to enjoy free university, allowing me to get a high paying job. I get to use very cheap all electric state-subsidized rental car offerings if I need them, which is rare since we have federally goo…

> apartments are rent-capped > cheap social housing > free university > high paying job > very cheap all electric state-subsidized rental car offerings > affordable meat, dairy and vegetables

And here we can simply examine the tax structure and conclude that the problem isn't whether the country sucks, but whether the side you're on sucks.

After all, how can housing be affordable for ordinary workers if they have to subsidize from their own pocket free university, cheap housing, electric cars, high wages, and everything else for the privileged class?

> Maybe your country sucks?

And maybe your country sucks too. It is just North Korea is also the best country to live in (if you're Kim Jong Un).

Re: German implementation of eIDAS will require an Apple/Google account to function

#367

Earlier quoted context omitted.

Well the comment above was expressing disbelief that more people are not up in arms about this. When you realize the tiny tiny percentage of people that have a phone that is not apple or google, you understand why few people are up in arms. It simply doesn’t affect many people.

This feels like arguing that people wouldn't object to having a shock collar padlocked around their neck because it's not currently shocking them. You don't have to see very many moves ahead to guess what happens if you don't object. Whereas if the collar is touted as fashionable and the lock is hidden until it's engaged, now your problem is not that people don't care , it's that they don't know , which is different.

I’m not for one second saying I like it, agree with it, or support it.

I’m just saying there are not many people impacted, so there are not going to be many people making noise.

People are simply too deep in the trenches of day to day to object to things that don’t impact them personally

Re: German implementation of eIDAS will require an Apple/Google account to function

#368
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Do all German hospitals serve vegan food? If you were averse to carrots (without any health restrictions on eating them), would every government institution in Germany be required to serve you carrot-free food? If not, why should they be forced to accommodate every smartphone brand in existence, even if there's only 3 people in Germany using it? THe list has to end somewhere.

> Do all German hospitals serve vegan food?

Can't speak for Germany, but they do in the UK. It would be illegal discrimination against a belief for them not to.

Re: German implementation of eIDAS will require an Apple/Google account to function

#369
post #291

Earlier quoted context omitted.

Or it's just way easier to implement this way and they don't want to waste time on stuff only HN crowd cares about ?

Implementing Play Integrity is something developers have to go out of their way to do. Not implementing it requires literally zero effort. So no, it's not easier to do it this way.

One could say the same thing about virus scanners. They are obviously too little too late "security" so standards that require them have given up on real requirements like a way to achieve actual assurance of no buffer overflows. Nonetheless, an implementation to such a standard that chooses any off the shelf scanner is a lot less work than implementing a new scanner.

Re: German implementation of eIDAS will require an Apple/Google account to function

#370
post #228

Earlier quoted context omitted.

Just a quick question, and sorry if it might have been answered already... why preventing duplication is so important? I know it’s in the spec probably [1], but I can’t figure out the reason. And a suggestion: add external HSM support at least? (e.g. things like NitroKey/YubiKey) [1]: https://eudi.dev/latest/architecture-and-reference-framework... I suppose?

Preventing credential duplication is a requirement to achieve high level of assurance. One of its purpose is to limit the potential damage that can be done by attacks. If credentials are bound to hardware-bound keys, attackers will always need access to this key store to make any miss-use. If you don't prevent duplication, attackers may extract credentials and miss-use them at a 1000 places simultaneously.

Okay, but Google certifies phones which are not updates for the last several years.

They can be trivially rooted, then they spoof the signature and get a pass in Integrity while being wide open for malware (or cooying the ID, ID presume).

Post reply on HN