Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

221–230 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#222

Earlier quoted context omitted.

Oh and Sailfish OS [0], Postmarket OS [1], and whatever Purism runs [2]. [0] https://sailfishos.org/ [1] https://postmarketos.org/ [2] https://puri.sm/products/librem-5/

...and Debian, PureOS, Fedora, Arch, NixOS...

Maybe they should just publish the spec, and then providers can offer ID as a service? I.e as a Proton user, Proton Pass currently supplies my ID everywhere, including for government services.

What makes Android and Apple devices special?

Re: European digital ID wallets rely on safety services of Google and Apple

#223
post #129

Earlier quoted context omitted.

But ... the alternative is that the government actually pays a bit of money to fix the situation! To support their solutions. To actually develop them for enough devices. To secure them ... Plus the services the government made are way more invasive than the Google/Apple ones. In addition to the money, actually using them would be hundreds of times more complex, and they don't have the provisions Google has, for exam…

I just dont buy the argument that it would be that expensive for the governments to provide certified keychain fobs that provide hardware based identification.

That was an option for the past 15+ tears at least in some EU countries. Its just not very convenient (garbage tier software they bought didn’t help either).

Re: European digital ID wallets rely on safety services of Google and Apple

#224
post #217

Earlier quoted context omitted.

I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…

Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?

I cannot think of any company that has appropriately used attestation as a trust/risk calculation. I work in major game studio; there is never calculation only a binary.

It never „let`s check if the mobile user has purchased in-game content server side to prevent pirating it“, its „suspend any account that has signed in with a device that fails safetynet, permanently ban any account that has failed a jailbreak or root checks“

It never „let`s check and calculate statistically cheating probability and move damage calculation server-side so that player cannot godmode or modify their APK“, its „all non-stock phones are cheaters and fraudsters, ban all of them, use invasive anti-cheat, while continuing to have client sided damage and health and energy because it is easier“

Something else has to change first otherwise the only option for businsinses do will be, after 2 is implemented : „while yes it is now possible to allow a neutral third party to control attestation, someone higher-up such as legal has said ONLY google can and we will ban everyone else“

As long as it is easier to don't give a fuck, that is the option that will be taken. z.B. the only reason our publisher allow the removal of play services was finding out that chinese players on definitely not google certified phone spends the most by orders of magnitude and even then it is only relaxing the check for specific region, forcing all EU players to continue to have this checking.

I would be wholly unsurprised if the result was to continue to require attestation but allow GrapheneOS f.e. only in Motorola factory shiped phones and disallow it if the user was involved in any way in the installation of it.

Re: European digital ID wallets rely on safety services of Google and Apple

#225
post #20
post #3

> Governments are cementing a monopoly they claim to oppose Duopoly but yea. Because there is no third alternative. Microsoft failed/gave up with Windows Phone. The people trying to fix secure government services can't really tackle that issue, but the systems needs to be built now anyway.

They can't tackle issue oft establishing a 3rd popular mobile operating system, true. But they could support Desktop Linux or AOSP.

Last I checked Android was OSS and there's plenty of clones without any Google BS. Heck I'm using one now

Re: European digital ID wallets rely on safety services of Google and Apple

#226
post #155

Earlier quoted context omitted.

This is simply untrue. The tech is there, the will (money) isn't.

The money can't all come from the state. If the EU wants to compete, it should create a common market worth its name where EU companies can raise billions like American ones. If that doesn't happen but we instead pat ourselves on the back for setting aside a pithy 5 million Euros in some EU budget to support open source, it's never going to happen.

Already in flight with EU-INC

https://www.youtube.com/shorts/DgUXH14By0w

Re: European digital ID wallets rely on safety services of Google and Apple

#227
post #124

Earlier quoted context omitted.

150 million functionally illiterate people in Europe? Just how is that defined?

Why are you surprised? Europe has 700 million people. Think of the average construction worker you know, do you think they could read and correctly summarize any moderately complex article? Think an article about inflation or evolution or heat pumps or investment funds, etc. Fairly sure that in most countries the average person reads less than 1 book per year, so half of the population reads less than that. I know pe…

https://worldpopulationreview.com/country-rankings/average-b...

The Average Briton allegedly reads 15 books per year. I assume its self reported and poorly sampled. Otherwise its very hard to believe (and variance between countries seems way too high) but stats like this (especially more subjective ones like functional literacy) are usually not very useful on their own.

Re: European digital ID wallets rely on safety services of Google and Apple

#228
post #37

Earlier quoted context omitted.

> building a worse version of AWS just so that it is "European" makes no financial sense Unless it becomes necessary because of EU regulation?

Can you mention a single decent product that came out "because of EU regulation"?

iPhone with USB-C

Re: European digital ID wallets rely on safety services of Google and Apple

#229
post #217

Earlier quoted context omitted.

I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…

Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?

A hypothetical useful use of attestation is that a company promising to process personal data securely could actually prove it to end-users, by open-sourcing their server-side code and using reproducible builds combined with remote attestation, to prove to the client that the server-side is running unmodified within a secure enclave.

I struggle to think of a useful use for it on the end-user client side, though.

Re: European digital ID wallets rely on safety services of Google and Apple

#230
post #4

A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.

Understandable. However every new solution should be built from the ground up and be fully decoupled even if the migration of old services might take a while.

For this specifically EU could surely (only in theory since statistically the average EU bureaucrat is a pompous idiot to whom the word “accountability” is an entirely inconceivable concept) have something developed for a sane price in a reasonable amount of time.

Post reply on HN