Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

401–410 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#401

Earlier quoted context omitted.

Comparing being able to run the hardware and software of your choice to "wanting a passport in a different color or whatever" is so completely fucked, and it's beyond insane as a justification for giving two American tech companies with a well established track record for doing evil control over your citizens' ID. The world has gone absolutely mad, what the fuck am I even witnessing? It is quite literally becoming 19…

You keep lashing out at people in this thread. Demanding full control over something like an ID will fundamentally not happen. The same way you won't have full control over the way passports or paper bills are made. Take for example the expectation that some poor fool's ID can't be cloned and reused by malicious actors - full control directly contradicts that. It will not and must not be possible.

We don't need 'full control' over an ID. We need the status quo, where we have mostly have control over our devices, and where paper IDs are still the foundation of society. Things are fine the way they are. There are problems, sure, but no problems that are made better by an all-encompassing surveillance state.

If I am lashing out, it is because this is perhaps the most dangerous thing I've ever seen proposed, and it is deeply distressing how people are sleepwalking into it. To be honest, if I were German, I would probably just kill myself the day I was legally mandated by my government to register my identity with Google. That might sound hyperbolic, but I'm really not kidding. I have lived with privacy, anonymity, and freedom for all of my life. If the future of this world is one where the government and Google have complete control over every single thing you do, I'd rather die having lived a satisfying life than witness the horrors that are to come.

Re: German implementation of eIDAS will require an Apple/Google account to function

#402

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Thank you for chiming in. > We have to use some kind of attestation mechanism per the eIDAS implementing acts. What does this attestation need to prove? Is this only about ensuring that private keys are managed by a secure enclave or a TPM? > we have support for other OSs on our list (like, e.g., GrapheneOS) I appreciate that, even though I am really not enthusiastic of eIDAS. But time will tell. Thank you.

They won't implement alternatives later, they'll be no point if "most of out customers is using either of the major providers".

Concerning secure enclave - what other device except iphones and Pixels have it actually safe?

Re: German implementation of eIDAS will require an Apple/Google account to function

#403

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Why not do it right from the beginning? https://grapheneos.org/articles/attestation-compatibility-gu...

They don't really want to.

Re: German implementation of eIDAS will require an Apple/Google account to function

#404
post #254

Earlier quoted context omitted.

Why is a trusted device chain needed? It will put more trust in the potential Chinese device maker and American software companies than the user who's id is shown?

This is necessary because the wallets contain an identity proofing functionality called PID(Person Identification Data). Showing these credentials basically approves you are you. There are high requirements for identity proofing that even pre-date wallets and that makes sense, because the potentially blast radius of identity theft is huge. Historically, these have been secured in smartcards, like eID cards or passpor…

OK, but Google will happily confirm android device running Oreo is safe.

While it's dramatically worse than devices Google refuses to certify (ie these not running their spyware as privileged services).

Re: German implementation of eIDAS will require an Apple/Google account to function

#405

Earlier quoted context omitted.

Why is a trusted device chain needed? It will put more trust in the potential Chinese device maker and American software companies than the user who's id is shown?

Simply because the law was written that way. But also the whole idea of identity verification becomes pretty useless, if there is no chain of trust. You could run a modified client that lets you assume any identity you choose, exactly the opposite of what eIDAS is trying to achieve.

But you can run modified client already.

Rooted, wildly insecure devices can pass the attestation easily: https://magisk.dev/modules/play-integrity-fix-inject/

Safe, updated devices cannot unless they permit Google to run their surveillance services in the privileged, unconstrained mode.

Re: German implementation of eIDAS will require an Apple/Google account to function

#406

Earlier quoted context omitted.

Simply because the law was written that way. But also the whole idea of identity verification becomes pretty useless, if there is no chain of trust. You could run a modified client that lets you assume any identity you choose, exactly the opposite of what eIDAS is trying to achieve.

> You could run a modified client that lets you assume any identity you choose Provided you know the secret key to a government-issued certificate. Making it impossible to copy said certificate is not really a requirement for identity verification.

Some countries fixed it already, see Estonian ir Polish IDs with digital layer (performing signing, authentication, etc), and the devices only acting as untrusted interfaces to these.

Re: German implementation of eIDAS will require an Apple/Google account to function

#407
post #382

Earlier quoted context omitted.

I thought this was about identity, though, not securing payments. Isn’t that sufficiently tackled with the digital signature?

It is about supporting "online cross-border transactions", in other words for providing a legally binding way for agreements to be made. This will be the basis for VISAs, proving you hold credentials (initially driving license, but will extend further), proving you've signed a contract. This MAY include a central-bank wallet with "digital Euro", or it may not, but even without, it's about money. You can smell where t…

Btw a visa is a document allowing entry into a country, while VISA is a word mark used by Visa, inc. for their payment cards and network. I think you're referring to the travel document, but since the context also includes payment networks, I'm not 100% sure.

Re: German implementation of eIDAS will require an Apple/Google account to function

#408

Earlier quoted context omitted.

You should think about how easy it is to permanently lose access to your Google account for very trivial issues and Google doesn't offer any form of recovery. That in addition to the current geopolitical situation should be reason enough not to rely on that for any justification. And personally as a software developer myself i know that nothing is more permanent than a temporary solution. No one will prioritize or gi…

Can't you just make a new google account then?

That's crazy.

Imagine cheering for the company that will block the criminal prosecutors investigating war crimes and genocide from having the ID at all(1) once the supporter of the investigated sanctions the law-abiding persons: https://www.whitehouse.gov/presidential-actions/2025/02/impo...

But anyway - why the requirement in the first place?

(1) because sanctioned person must not be allowed to create another account.

Re: German implementation of eIDAS will require an Apple/Google account to function

#409
post #397

Earlier quoted context omitted.

That seems like a weak argument to require attestation? What would attestation prevent that scenario, specifically?

Oh I see your confusion. It is not trying to prove it's not cheating with the UI (or remote control, or ...) to the owner of the phone. It's proving to the owner of the website (or app, or SIM, or ...) that it's really the user agreeing to the contract on the screen. Or, more to the point, it's proving it to courts after the fact so they'll convict the owner of the phone rather than the business or government. The sc…

Do you imply that google can prove such a thing or it's just a security theater for (((compliance)))? AFAIK attestation attests hardware, not software, but hardware attestation is self contained and doesn't require any remote cartel permission, cf yubikey attestation.

Re: German implementation of eIDAS will require an Apple/Google account to function

#410
post #51

Earlier quoted context omitted.

If an account is required, then yes. Good catch. This may not be unwelcome for authorities considering the recent extrajudicial “unpersoning” of many political enemies in the EU.

It definitely would be unwelcome for EU authorities in cases like the recent US sanctions against ICC officials.

Fair... they should think about this then
Post reply on HN