Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

301–310 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#301
post #282

Earlier quoted context omitted.

Clearly it isn’t. This is what techies forget: The mass amount of Europeans don’t give 2 shits about digital sovereignty or open source. Christ, people go to mobile operator shops and give their unlocked phones to consultants to install or remove software for them. You want them to install GrapheneOS or manage a rooted device? That ain’t even funny. The only short-term solution is more regulation and more EU-centrali…

> Clearly it isn’t. This is what techies forget: The mass amount of Europeans don’t give 2 shits about digital sovereignty or open source. When Trump was invading Denmark, a huge % of Danes would've given a shit about sovereignty from the US. And that's the moment to pounce.

But that moment is gone.

Re: European digital ID wallets rely on safety services of Google and Apple

#302
post #244

Earlier quoted context omitted.

Smartcards have attestation too.

But how can you verify that the processor's own software, which ultimately runs the application, has not been compromised?

Processor's software becomes no different than a switch, a transfer medium in the network when you use the smartcard capabilities of the EU ID card. Digital signatures and cryptography happens purely inside the RFID/smartcard chip of the card.

This is how payments work for chip-and-pin system of EMV and login and signing systems of many businesses in the EU already. There is no need for third party attestation already.

Re: European digital ID wallets rely on safety services of Google and Apple

#303
post #131

Earlier quoted context omitted.

I'm ok with enforcing hardware security. Both for banks and governments. But it must not limit the ability of running custom software on a phone. And especially not enforcing every person to get a Google/Apple signed phone. Like if I get GrapheneOS on my phone. Banking/gov apps should work. But I believe this could be possible with enforcing hardware security as well.

The chain of trust always has a software layer. I don’t believe what you want is possible. I find the bank talking point strange, why are they special, are they even targeted more. It just feels like a boogeyman “think of your money!”

Have a look at Heads. It uses TPM with a hardware key to verify the boot integrity without proprietary blobs and with full control of the user. Works for me.

Re: European digital ID wallets rely on safety services of Google and Apple

#304

Earlier quoted context omitted.

Thr answer to US tech giants are not homegrown EU tech giants, but international free software (Free as in Freedom). We already have free operating systems: Linux, BSD. Office software: LibreOffice, etc. EU regulators have stop listening to tech company lobbyists.

We need competing (and competent) lobbyists. Unfortunately one side has all the money, so there is a clear disadvantage

Support https://edri.org if you want good lobbyists on your side.

Re: European digital ID wallets rely on safety services of Google and Apple

#305
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

Special-casing support for GrapheneOS would be a band-aid, they should find a way to avoid requiring remote attestation in the first place, so anyone can use whatever OS they like on whatever hardware they like.

Proposing that governments give up the fight for verifying government-issued identity papers online rather than proposing an alternate solution that’s not attestation-based seems like a missed opportunity to change their course. By what defensible-against-resale method should governments be authenticating the identities they issue and control online?

Re: European digital ID wallets rely on safety services of Google and Apple

#306

Earlier quoted context omitted.

Special-casing support for GrapheneOS would be a band-aid, they should find a way to avoid requiring remote attestation in the first place, so anyone can use whatever OS they like on whatever hardware they like.

I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…

Implementing #2 would be as simple as declaring that hardware vendors that issue attestation roots may not pre-install operating systems on them, nor make exclusivity or unfair pricing agreements that advantage or disadvantage other businesses unevenly; and, must provide a way for consumers to replace at will the operating system preinstalled by those third parties with one of their own choosing. If the EU has technical competence then they’ll work their way around to this realization and absolutely shatter the Apple/Google monopolies in a single edict, since those EU-sold devices will then be repurposeable worldwide (with valid attestation chains to the replacement OSes, if they choose to implement them). One can dream.

Re: European digital ID wallets rely on safety services of Google and Apple

#307

Earlier quoted context omitted.

I must be illiterate because this doesn’t make any sense to me Being kinda dumb and graduating school without reading a book is not a socioeconomic status

The point: you call them "functionally illiterate" when you don't like them. Otherwise, you call them something else.

I guess one could use it as an insult but I’ve only heard it as a practical descriptor for someone who can read the headlines but not the article

Re: European digital ID wallets rely on safety services of Google and Apple

#308

They should not make it mandatory for or expect people to have a smartphone.

It's not mandatory.

Use of the wallet is voluntary and, for natural persons, free of charge.[29]

https://en.wikipedia.org/wiki/EU_Digital_Identity_Wallet

Re: European digital ID wallets rely on safety services of Google and Apple

#309
post #249

Earlier quoted context omitted.

Last I checked Android was OSS and there's plenty of clones without any Google BS. Heck I'm using one now

Yeah but if the wallet requires Google Pay Services attestation the AOSP based clones won't be able to run it unless they can spoof it somehow.

Because that's the security posture systems like these needs.

Re: European digital ID wallets rely on safety services of Google and Apple

#310

Earlier quoted context omitted.

Aren't monopolies is what we end up by default if have no regulation at all? And yes, not every regulation destroys monopoly, but regulation is the only thing that could break one.

Are there any examples of monopolies being (successfully) broken up in Europe? Or do you posit that regulation stop them from forming?

[dead]
Post reply on HN