Earlier quoted context omitted.
I'm ok with enforcing hardware security. Both for banks and governments. But it must not limit the ability of running custom software on a phone. And especially not enforcing every person to get a Google/Apple signed phone. Like if I get GrapheneOS on my phone. Banking/gov apps should work. But I believe this could be possible with enforcing hardware security as well.
The chain of trust always has a software layer. I don’t believe what you want is possible. I find the bank talking point strange, why are they special, are they even targeted more. It just feels like a boogeyman “think of your money!”
European digital ID wallets rely on safety services of Google and Apple
181–190 of 327 posts
Re: European digital ID wallets rely on safety services of Google and Apple
#182Even relying on Android's hardware attestation API instead of Play Integrity is an attack on digital autonomy in my opinion. Any security feature which relies on remote attestation of the users entire platform is government overreach as it ultimately gives the government the power to choose what operating systems are acceptable. It is only a matter of time before this power will be misused to put pressure on OS devel…
I'm ok with enforcing hardware security. Both for banks and governments. But it must not limit the ability of running custom software on a phone. And especially not enforcing every person to get a Google/Apple signed phone. Like if I get GrapheneOS on my phone. Banking/gov apps should work. But I believe this could be possible with enforcing hardware security as well.
Re: European digital ID wallets rely on safety services of Google and Apple
#183The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…
Re: European digital ID wallets rely on safety services of Google and Apple
#184The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…
1. Smart Cards (for example The Current National ID)
2. Standalone Hardware Tokens & USB Keys
Re: European digital ID wallets rely on safety services of Google and Apple
#185Re: European digital ID wallets rely on safety services of Google and Apple
#186Earlier quoted context omitted.
The only problem is, EU does not control these devices, Google and Apple and by extension the US government does.
Oh they sure do, because Google/Apple have to bend over backwards for the EU as they are not stupid enough to suddenly lose 500 million users.
Re: European digital ID wallets rely on safety services of Google and Apple
#187Earlier quoted context omitted.
Motorola/GrapheneOS, and FairPhone/e/OS.
Fairphone/e/OS is Dutch and French respectively. It'd be funny if the EU forgot to permit the use of a pure european system.
Re: European digital ID wallets rely on safety services of Google and Apple
#188I agree of course, Europe should not be using US services for critical infrastructure. But more importantly I think that we are private citizens. The government should know as least as possible about us. We on the other hand should know every single move, decision, and discussion they have while they sit on the chairs we paid for.
Re: European digital ID wallets rely on safety services of Google and Apple
#189Earlier quoted context omitted.
The issue isn't just the technical dependency. It's also the fact that it forces each citizen to pay a few hundred Euros to companies which then campaign against their very rights. Citizens get no support of any kind in case of issues, and has to enter a contractual agreement which is ridiculously asymmetrical, where the company has little to no responsibility of any kind, but has very ample rights to track the other…
But ... the alternative is that the government actually pays a bit of money to fix the situation! To support their solutions. To actually develop them for enough devices. To secure them ... Plus the services the government made are way more invasive than the Google/Apple ones. In addition to the money, actually using them would be hundreds of times more complex, and they don't have the provisions Google has, for exam…