Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

241–250 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#242

Earlier quoted context omitted.

...and Debian, PureOS, Fedora, Arch, NixOS...

Maybe they should just publish the spec, and then providers can offer ID as a service? I.e as a Proton user, Proton Pass currently supplies my ID everywhere, including for government services. What makes Android and Apple devices special?

Android and Apple devices let the remote server verify whether the local application and the system it runs on haven't been modified by the user and refuse providing services if they were. That's what makes them special, it's hard to imagine how a, say, generic installation of Debian could do that without severely restricting the user.

It's an ill-defined "security" measure that should be viciously opposed anywhere it shows up.

Re: European digital ID wallets rely on safety services of Google and Apple

#243
post #65

Earlier quoted context omitted.

Honestly, as long as the architectures is fatally flawed (Even if convenient) it's just bandaids over a larger issue. These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks. Germany was going in the right direction imho, they NFC enabled their ID cards (Sweden has info on…

> These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks. Many countries in the EU already have all of that just done though some national equilevant system (for example here in Finland mainly with bank credentials). And in fact additonal checks are done when enough money…

Again, it's all still tied to that one device, the phone, if it's hacked it's really game over and with a big enough hole in the Android or iOS ecosystem that could be wormable a lot of people could be exploited en-masse.

Sure a 24h delay or SMS code are 2 way but they fully fall into the bandaid category.

In the past we used to have disconnected dongles for banking, the bank issued a one-time challange and you entered the response along with your username. Now there are disadvantages with those also but at least it was fully airgapped.

Re: European digital ID wallets rely on safety services of Google and Apple

#244
post #112

There's a relatively simple and much more open and secure solution to this: Make physical EU ID cards the attestation source, and require users to tap them against their phone for critical operations (high-value signatures, login on a new device or after repeated authentication failures etc). That would solve the open hardware/OS "problem" on the device entirely, as there's no trusted hardware or OS signature require…

How can you have a secure enclave without hardware attestation? Processor root-key is the source for all.

Smartcards have attestation too.

Re: European digital ID wallets rely on safety services of Google and Apple

#245
It's honestly quite baffling that the EU would want to put any more power in the hands of any US controlled company at this point. The US is a borderline hostile state, only recently threatening to invade Greenland among numerous other examples. The situation with Anthropic has illustrated that the US government will not hesitate to leverage power over US companies when it feels its interests are advantaged by doing so. If anything, the EU should be banning use of Google or Apple dependent architectures, not pseudo mandating them.

Re: European digital ID wallets rely on safety services of Google and Apple

#247

Earlier quoted context omitted.

> I really don’t know what the fuck the Europeans are thinking by playing the US’s stupid games. As we see time and time again, it won’t be repaid in kind. I feel like the European relationship with the US can really be summed up by the 30 permanent military bases and 84,000 military personnel stationed in their borders and the underlying faith that it's for their own protection, except we better never ask them to le…

84 thousand personnel (of which maybe 20 per cent are actual combat troops, given the standard tooth-to-tail ratios of modern mechanized armies) could perhaps occupy Denmark on a good day. For a continent the size and population of Europe, this is not a dominant force by any means. Putin has about 700 000 personnel in Ukraine right now and isn't making any progress. Barbarossa took about 3 million personnel to start.

Speaking of, my favourite Denmark story was probably Greenland when the US abandoned their cold-war era bases they just buried all their highly toxic trash in the ice. That ice is now melting and Denmark has to clean it all up. In the agreement with the US they excluded the US from any responsibility so they have to pay for it themselves. They also got really mad when the Greenlanders went behind the back of Denmark to complain at the UN about it.

Then Trump threatened to invade Greenland. And now the US is in negotiation with NATO (yeah lol) to build 3 new bases there that would be designated as US territory (bwahaha). One thing I like about Trump he drags all the Europeans through the mud so publicly it makes the contradictions impossible to miss, that's why they all hate him but still have to kiss his feet it's awesome. Like Obama made their groveling seem less suspect.

But yeah people are fucking clueless about everything. At least our media is free and not state controlled propaganda right?

Re: European digital ID wallets rely on safety services of Google and Apple

#249
post #20

Earlier quoted context omitted.

They can't tackle issue oft establishing a 3rd popular mobile operating system, true. But they could support Desktop Linux or AOSP.

Last I checked Android was OSS and there's plenty of clones without any Google BS. Heck I'm using one now

Yeah but if the wallet requires Google Pay Services attestation the AOSP based clones won't be able to run it unless they can spoof it somehow.

Re: European digital ID wallets rely on safety services of Google and Apple

#250
Everytime EUID mentioned, people forget that EUID is not anonymous!

EUID has "provider/verifier" endpoint which communicates with your website to inform you are indeed 18+ age.

Link: https://github.com/eu-digital-identity-wallet/eudi-srv-verif...

The github page has graph how it works.

So Government can track your accounts via IP,Timestamps, Token (if website saves it).

Just incase you dont bother visiting the github page the simplified flow works like this:

1) You scan QR code 2) Verification 3) Provider/Verifier informs website +18 age

So if i verify my age then watch some material which doesn't agree with with my government values like females with male genitals. I'd be royally screwed if government wishes to pursue.

Post reply on HN