This is not safe.
European digital ID wallets rely on safety services of Google and Apple
221–230 of 327 posts
Re: European digital ID wallets rely on safety services of Google and Apple
#222Earlier quoted context omitted.
Oh and Sailfish OS [0], Postmarket OS [1], and whatever Purism runs [2]. [0] https://sailfishos.org/ [1] https://postmarketos.org/ [2] https://puri.sm/products/librem-5/
...and Debian, PureOS, Fedora, Arch, NixOS...
What makes Android and Apple devices special?
Re: European digital ID wallets rely on safety services of Google and Apple
#223Earlier quoted context omitted.
But ... the alternative is that the government actually pays a bit of money to fix the situation! To support their solutions. To actually develop them for enough devices. To secure them ... Plus the services the government made are way more invasive than the Google/Apple ones. In addition to the money, actually using them would be hundreds of times more complex, and they don't have the provisions Google has, for exam…
I just dont buy the argument that it would be that expensive for the governments to provide certified keychain fobs that provide hardware based identification.
Re: European digital ID wallets rely on safety services of Google and Apple
#224Earlier quoted context omitted.
I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…
Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?
It never „let`s check if the mobile user has purchased in-game content server side to prevent pirating it“, its „suspend any account that has signed in with a device that fails safetynet, permanently ban any account that has failed a jailbreak or root checks“
It never „let`s check and calculate statistically cheating probability and move damage calculation server-side so that player cannot godmode or modify their APK“, its „all non-stock phones are cheaters and fraudsters, ban all of them, use invasive anti-cheat, while continuing to have client sided damage and health and energy because it is easier“
Something else has to change first otherwise the only option for businsinses do will be, after 2 is implemented : „while yes it is now possible to allow a neutral third party to control attestation, someone higher-up such as legal has said ONLY google can and we will ban everyone else“
As long as it is easier to don't give a fuck, that is the option that will be taken. z.B. the only reason our publisher allow the removal of play services was finding out that chinese players on definitely not google certified phone spends the most by orders of magnitude and even then it is only relaxing the check for specific region, forcing all EU players to continue to have this checking.
I would be wholly unsurprised if the result was to continue to require attestation but allow GrapheneOS f.e. only in Motorola factory shiped phones and disallow it if the user was involved in any way in the installation of it.
Re: European digital ID wallets rely on safety services of Google and Apple
#225> Governments are cementing a monopoly they claim to oppose Duopoly but yea. Because there is no third alternative. Microsoft failed/gave up with Windows Phone. The people trying to fix secure government services can't really tackle that issue, but the systems needs to be built now anyway.
They can't tackle issue oft establishing a 3rd popular mobile operating system, true. But they could support Desktop Linux or AOSP.
Re: European digital ID wallets rely on safety services of Google and Apple
#226Earlier quoted context omitted.
This is simply untrue. The tech is there, the will (money) isn't.
The money can't all come from the state. If the EU wants to compete, it should create a common market worth its name where EU companies can raise billions like American ones. If that doesn't happen but we instead pat ourselves on the back for setting aside a pithy 5 million Euros in some EU budget to support open source, it's never going to happen.
Re: European digital ID wallets rely on safety services of Google and Apple
#227Earlier quoted context omitted.
150 million functionally illiterate people in Europe? Just how is that defined?
Why are you surprised? Europe has 700 million people. Think of the average construction worker you know, do you think they could read and correctly summarize any moderately complex article? Think an article about inflation or evolution or heat pumps or investment funds, etc. Fairly sure that in most countries the average person reads less than 1 book per year, so half of the population reads less than that. I know pe…
The Average Briton allegedly reads 15 books per year. I assume its self reported and poorly sampled. Otherwise its very hard to believe (and variance between countries seems way too high) but stats like this (especially more subjective ones like functional literacy) are usually not very useful on their own.
Re: European digital ID wallets rely on safety services of Google and Apple
#228Re: European digital ID wallets rely on safety services of Google and Apple
#229Earlier quoted context omitted.
I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…
Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?
I struggle to think of a useful use for it on the end-user client side, though.
Re: European digital ID wallets rely on safety services of Google and Apple
#230A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?
Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.
For this specifically EU could surely (only in theory since statistically the average EU bureaucrat is a pompous idiot to whom the word “accountability” is an entirely inconceivable concept) have something developed for a sane price in a reasonable amount of time.