Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

181–190 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#181
post #131

Earlier quoted context omitted.

I'm ok with enforcing hardware security. Both for banks and governments. But it must not limit the ability of running custom software on a phone. And especially not enforcing every person to get a Google/Apple signed phone. Like if I get GrapheneOS on my phone. Banking/gov apps should work. But I believe this could be possible with enforcing hardware security as well.

The chain of trust always has a software layer. I don’t believe what you want is possible. I find the bank talking point strange, why are they special, are they even targeted more. It just feels like a boogeyman “think of your money!”

The software layer in age verification is not necessary to trust though. The worst that could happen is that a compromised software layer steals your age credential, but it is by design anonymous so you don't risk getting your money or account stolen or anything. This makes it a different threat model from the banking case.

Re: European digital ID wallets rely on safety services of Google and Apple

#182
post #131

Even relying on Android's hardware attestation API instead of Play Integrity is an attack on digital autonomy in my opinion. Any security feature which relies on remote attestation of the users entire platform is government overreach as it ultimately gives the government the power to choose what operating systems are acceptable. It is only a matter of time before this power will be misused to put pressure on OS devel…

I'm ok with enforcing hardware security. Both for banks and governments. But it must not limit the ability of running custom software on a phone. And especially not enforcing every person to get a Google/Apple signed phone. Like if I get GrapheneOS on my phone. Banking/gov apps should work. But I believe this could be possible with enforcing hardware security as well.

You can't have both. "Hardware security" means the manufacturer decides which OS can run and you can't override it.

Re: European digital ID wallets rely on safety services of Google and Apple

#183
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

[flagged]

Re: European digital ID wallets rely on safety services of Google and Apple

#184
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

This is only reflects their market share for now. The EU legally forbids member states from making a smartphone mandatory to access public services. The EU explicitly anticipated the danger of relying entirely on the iOS and Android and designed the EUDI Wallet framework to allow for other physical form factors. For example;

1. Smart Cards (for example The Current National ID)

2. Standalone Hardware Tokens & USB Keys

Re: European digital ID wallets rely on safety services of Google and Apple

#186
post #48

Earlier quoted context omitted.

The only problem is, EU does not control these devices, Google and Apple and by extension the US government does.

Oh they sure do, because Google/Apple have to bend over backwards for the EU as they are not stupid enough to suddenly lose 500 million users.

But if the EU cements their citizens' dependency on Google/Apple even further by effectively mandating the use of these devices, it gives Google/Apple more leverage. Imagine if them pulling out of the EU meant nobody could use their digital wallet? What if the use of digital wallets has become more mandatory by then?

Re: European digital ID wallets rely on safety services of Google and Apple

#187
post #95

Earlier quoted context omitted.

Motorola/GrapheneOS, and FairPhone/e/OS.

Fairphone/e/OS is Dutch and French respectively. It'd be funny if the EU forgot to permit the use of a pure european system.

Prepare to laugh then. Most EU politicians don't have a clue that these systems exist.

Re: European digital ID wallets rely on safety services of Google and Apple

#188
I like how we quickly moved past the fact that the government wants to know who we are, what we visit, what we say, what we buy, and has explicitly said that they want to control what we buy, where we go, and what we are allowed to say. But we are focused on what specific mega-corporation those systems will use to function.

I agree of course, Europe should not be using US services for critical infrastructure. But more importantly I think that we are private citizens. The government should know as least as possible about us. We on the other hand should know every single move, decision, and discussion they have while they sit on the chairs we paid for.

Re: European digital ID wallets rely on safety services of Google and Apple

#189
post #129

Earlier quoted context omitted.

The issue isn't just the technical dependency. It's also the fact that it forces each citizen to pay a few hundred Euros to companies which then campaign against their very rights. Citizens get no support of any kind in case of issues, and has to enter a contractual agreement which is ridiculously asymmetrical, where the company has little to no responsibility of any kind, but has very ample rights to track the other…

But ... the alternative is that the government actually pays a bit of money to fix the situation! To support their solutions. To actually develop them for enough devices. To secure them ... Plus the services the government made are way more invasive than the Google/Apple ones. In addition to the money, actually using them would be hundreds of times more complex, and they don't have the provisions Google has, for exam…

I just dont buy the argument that it would be that expensive for the governments to provide certified keychain fobs that provide hardware based identification.

Re: European digital ID wallets rely on safety services of Google and Apple

#190

Earlier quoted context omitted.

Yes

Oh and Sailfish OS [0], Postmarket OS [1], and whatever Purism runs [2]. [0] https://sailfishos.org/ [1] https://postmarketos.org/ [2] https://puri.sm/products/librem-5/

...and Debian, PureOS, Fedora, Arch, NixOS...
Post reply on HN