Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

191–200 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#193
post #4

A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

Yes, and there is an open source spec [0] that doesn’t require Google/iOS Attestation but “preferably” providers will make their wallet app available on App Stores [1]:

> To ensure that the User can trust the Wallet Solution, Wallet Providers preferably make their certified Wallet Solutions available for installation via the official app store of the relevant operating system (e.g., Android, iOS). This allows the operating system of the device to perform relevant checks regarding the authenticity of the app.

Of course the chances of any important business implementing a side channel option is effectively zero. Maybe some government agencies will offer the option though.

[0] https://github.com/eu-digital-identity-wallet

[1] https://eudi.dev/latest/architecture-and-reference-framework...

Re: European digital ID wallets rely on safety services of Google and Apple

#194

Earlier quoted context omitted.

Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.

Thr answer to US tech giants are not homegrown EU tech giants, but international free software (Free as in Freedom). We already have free operating systems: Linux, BSD. Office software: LibreOffice, etc. EU regulators have stop listening to tech company lobbyists.

Is any of that capable of replacing google and apple on mobile?

Re: European digital ID wallets rely on safety services of Google and Apple

#195
post #89
post #69

Earlier quoted context omitted.

> Wasn't there some talk about the pressing need for European digital sovereignty recently? At FOSDEM, we discuss this at great length. There has been some movement, and I am optimistic that it is improving year on year.

I'm sorry but clearly the introduction of these apps with these requirements in the near past and near future represent regression over time rather than improvement. I think it was last year that there was a good presentation from them about how they were going to use ZKP and it was indeed very trust inspiring. But do you think the latest digital wallet solution from eg Danish government uses ZKP? Of course not! I ha…

I see your point about the disconnect between the rhetoric and what we actually see in production. Perhaps "regression" is a strong word, though, IMHO I tend to see it as a very slow and uneven evolution.

Even if the pace is frustrating, there are still pockets of genuine open-source adoption in the European public sector. For example, we're seeing projects like Germany's OpenDesk or various municipalities moving toward Nextcloud and other sovereign cloud solutions.

The EU Open Source Strategy[0] was announced just under a month ago and it specifically mentions the EU Digital Identity ecosystem, including the European Digital Identity Wallet (EUDI Wallet) mentioned in the article. I agree with OOP that the requirement of an Apple or Google phone goes against these ambitions, and I will contact my elected representatives.

[0]: https://digital-strategy.ec.europa.eu/en/policies/open-sourc...

Re: European digital ID wallets rely on safety services of Google and Apple

#196
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

Also, as the article says, Play Integrity is most likely a violation of the DMA. Send a message to the EU DMA Team if you live in the EU and are affected by this (or affected by this in the future, if you plan to switch to an alternative):

https://digital-markets-act.ec.europa.eu/contact-us-eu-citiz...

The more examples they get of actual citizens that get hit by this, the better. I have recently sent messages when Google introduced their new device-based recaptcha and when Volkswagen started blocking GrapheneOS. Of course, do not yell, explain patiently and with good argumentation why you are affected by Play Integrity and how you believe Play Integrity is used to enforce the duopoly + goes counter EU sovereignty.

Also, for apps that use Play Integrity, e-mail the company. React to their boilerplate replies with follow-ups (this slowly seems to get some headway with VW). Also leave a one-star review on their app, explaining in the review that they broke support for your system.

I know that this can all seem hopeless. But especially GrapheneOS is getting a lot of momentum now, rapidly gaining more users. It feels like it is a moment in time where we can seriously influence things for the better. There are ~500,000s users now. If everyone actively participates, we can move the needle.

Re: European digital ID wallets rely on safety services of Google and Apple

#197
post #65

Earlier quoted context omitted.

Honestly, as long as the architectures is fatally flawed (Even if convenient) it's just bandaids over a larger issue. These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks. Germany was going in the right direction imho, they NFC enabled their ID cards (Sweden has info on…

> These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks. Many countries in the EU already have all of that just done though some national equilevant system (for example here in Finland mainly with bank credentials). And in fact additonal checks are done when enough money…

It's great you do have a bank-bound system in Finland. I hope their implementation is not as bad as e.g. the Swedish BankID.

BankID is _in theory_ a nice technology. However, it is only handed out to people registered with the Swedish tax authorities holding a Swedish bank account.

All daily activities are nowadays bound to BankID: need a doctor's appointment? -> needs BankID; Want to buy something on Blocket? -> needs BankID.

As an European frequently spending some time in Sweden not in possession of a Swedish tax #, I feel very much excluded from online and partially offline activities in this country.

Re: European digital ID wallets rely on safety services of Google and Apple

#198

Earlier quoted context omitted.

Fairphone/e/OS is Dutch and French respectively. It'd be funny if the EU forgot to permit the use of a pure european system.

Prepare to laugh then. Most EU politicians don't have a clue that these systems exist.

Sounds like an outreach opportunity!

Re: European digital ID wallets rely on safety services of Google and Apple

#199
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

Special-casing support for GrapheneOS would be a band-aid, they should find a way to avoid requiring remote attestation in the first place, so anyone can use whatever OS they like on whatever hardware they like.

I think there are two fights that are both worth fighting:

1. Completely outlawing remote attestation.

2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple.

The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we are in already.

I agree that they are both worth fighting for, but I think (2) is much easier to accomplish, simply because Play Integrity is probably a DMA violation. (IANAL blah blah)

Re: European digital ID wallets rely on safety services of Google and Apple

#200
post #37

Earlier quoted context omitted.

> building a worse version of AWS just so that it is "European" makes no financial sense Unless it becomes necessary because of EU regulation?

Hopefully not. This hate towards good technology and innovation because you don’t like the current president is ridiculous. He’ll be gone in two years or so and then we’ll get back to normal.

It isn't just Trump. The CLOUD Act basically gives Washington the power and ability to turn off any server operated by any US company at will/whim.

The Wikipedia page only talks about stored data on (optionally foreign) servers without any sort of regard for the laws of the country where that server is located. It ignores the part of the statute where the feds can basically "turn off" that server. And that is the part that the EU is panicking over.

https://en.wikipedia.org/wiki/CLOUD_Act

Post reply on HN