Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

211–220 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#211

Earlier quoted context omitted.

> Spoken like a true 120-year who trusts blindly everything he hears online from Rothbard This ad hominem stuff is genuinely worthless.

I don't think so. Because the theories about elastic markets and monopolies do have a high 'spherical frictionless cow` smell. And they are posed here as gospel. So while it might be a bit of an ad hominem to frame someone as a 120 year old it does succinctly point out a problem and hence adds information.

Things "having a smell" is not an argument, and they weren't posed as gospel.

I've yet to see anyone counter the basic points of that post, because they look pretty solid. Happy if you have a non-vibes based rebuttal.

Re: European digital ID wallets rely on safety services of Google and Apple

#212

I like how we quickly moved past the fact that the government wants to know who we are, what we visit, what we say, what we buy, and has explicitly said that they want to control what we buy, where we go, and what we are allowed to say. But we are focused on what specific mega-corporation those systems will use to function. I agree of course, Europe should not be using US services for critical infrastructure. But mor…

> I agree of course, Europe should not be using US services for critical infrastructure. But more importantly I think that we are private citizens.

The irony in this as a European is that in the US people don’t even need national ID in the sense we got in Europe. They travel using driving license or library card. We got mandatory passports with biometric data - refusal to provide that data is practically impossible.

Re: European digital ID wallets rely on safety services of Google and Apple

#213
post #197
post #65

Earlier quoted context omitted.

> These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks. Many countries in the EU already have all of that just done though some national equilevant system (for example here in Finland mainly with bank credentials). And in fact additonal checks are done when enough money…

It's great you do have a bank-bound system in Finland. I hope their implementation is not as bad as e.g. the Swedish BankID. BankID is _in theory_ a nice technology. However, it is only handed out to people registered with the Swedish tax authorities holding a Swedish bank account. All daily activities are nowadays bound to BankID: need a doctor's appointment? -> needs BankID; Want to buy something on Blocket? -> nee…

This is a problem I'm seeing a lot of countries rushing full steam ahead. The age of a single physical ID that's only rarely needed and ubiquitous cash payments seems to be coming to an end. For anyone who travels a lot, migrants first settling in a place, or citizens abroad, this makes things even harder than they already were.

Re: European digital ID wallets rely on safety services of Google and Apple

#214

Earlier quoted context omitted.

Hopefully not. This hate towards good technology and innovation because you don’t like the current president is ridiculous. He’ll be gone in two years or so and then we’ll get back to normal.

It isn't just Trump. The CLOUD Act basically gives Washington the power and ability to turn off any server operated by any US company at will/whim. The Wikipedia page only talks about stored data on (optionally foreign) servers without any sort of regard for the laws of the country where that server is located. It ignores the part of the statute where the feds can basically "turn off" that server. And that is the par…

And they already did that. The chief prosecutor of the International Criminal Court in The Hague was cut off Office 365 (and e-mail hosted through that), as well as credit cards and bank cards. This did send a shockwave through Europe.

Re: European digital ID wallets rely on safety services of Google and Apple

#215
Just a general rule of thumb:

If I am not able to use any digital service or product on a computer that I could have built entirely myself (or had anyone of my choice build for me), running code I could have written entirely myself (or had anyone of my choice write for me), then that is completely unacceptable.

Re: European digital ID wallets rely on safety services of Google and Apple

#216

Earlier quoted context omitted.

[flagged]

Every Android system support remote attestation. It's part of AOSP. Google just decided not to use it, because Play Integrity allows them to lock in phone manufacturers and force them (per leaked agreements) to preinstall a bunch of Google apps and require to run Play Services and some other components privileged on the system.

Something being in AOSP doesn't mean your distro has to retain it. Besides, the world doesn't end on Android systems.

Re: European digital ID wallets rely on safety services of Google and Apple

#217

Earlier quoted context omitted.

Special-casing support for GrapheneOS would be a band-aid, they should find a way to avoid requiring remote attestation in the first place, so anyone can use whatever OS they like on whatever hardware they like.

I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…

Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?

Re: European digital ID wallets rely on safety services of Google and Apple

#219
post #46
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

The lawsuits, sadly, won't matter. "Security" (or, rather, totalitarian control!) is more important than the 1% of nerds who care enough to tinker with their phone.

People keep framing these sorts of debates in terms of tinkering.

It's about ownership, not tinkering. It's about preventing megacorporations from having the last word about how government services can function and how people can interact with them.

Re: European digital ID wallets rely on safety services of Google and Apple

#220

Even relying on Android's hardware attestation API instead of Play Integrity is an attack on digital autonomy in my opinion. Any security feature which relies on remote attestation of the users entire platform is government overreach as it ultimately gives the government the power to choose what operating systems are acceptable. It is only a matter of time before this power will be misused to put pressure on OS devel…

> it just requires a few cryptographic primitives and a set of device-bound keys

Question: how do you make sure the keys are device-bound if you have no attestation about the hardware or operating environment?

Post reply on HN