Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

111–120 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#111

Even relying on Android's hardware attestation API instead of Play Integrity is an attack on digital autonomy in my opinion. Any security feature which relies on remote attestation of the users entire platform is government overreach as it ultimately gives the government the power to choose what operating systems are acceptable. It is only a matter of time before this power will be misused to put pressure on OS devel…

Exactly, I'm not sure what benefits hardware attestation offers to the government. Sure, it's potentially useful for the customer that they can trust their keys are secure on their device, but it kind of misses the point.

It should really be an open-source specification that defines a standard protocol, but where the device just signs a request that it knows has come from a trusted source (so maybe signed by the government's key) with a key that the government's API knows that represents you.

So, I'd envisage something like government portal lets you add a bunch of public keys, one for each device, and shares a public key of its own that can be used to verify any requests. Something that wants to verify your identity can request your public key, and ask the government API for a challenge token which it passed back to you. You can verify the challenge token is signed by the key you trust, you can sign the challenge and return it to the app, which can pass it back to the government API which can then grant access to whatever subset of information they requested (and the challenge key can include enough information for the signing app to present a meaningful request).

Very simple in terms of protocol. Only the government needs to store any of your private data. If an application just needs to know if you are of a sufficient age or not, that's all the information it gets. If you lose your device you can easily revoke your keys and add new ones.

Sure, a specific implementation on a phone might want to use hardware attestation in order to keep its keys safe, but there's no reason that it has to be mandated. A well designed public key system should be sufficient leaving the implementation to safeguard its keys, while providing a simple way to replace keys if needed.

Re: European digital ID wallets rely on safety services of Google and Apple

#112
There's a relatively simple and much more open and secure solution to this: Make physical EU ID cards the attestation source, and require users to tap them against their phone for critical operations (high-value signatures, login on a new device or after repeated authentication failures etc).

That would solve the open hardware/OS "problem" on the device entirely, as there's no trusted hardware or OS signature required anymore. You could argue that this adds the possibility of a MITM attack on the phone (since you don't know what you sign anymore or who you are providing with your PIN, as the card has no display and no PIN pad), but I wonder if mitigating this is worth all the lock-in concerns that phone attestation goes hand in hand with.

As it is, all EU ID cards already have mandatory strong cryptographic authentication, but in a form that's usable only for in-person ID checks (under the corresponding ICAO biometric identity document standards), not for remote ID attestation. This is frustratingly close, but not what's needed.

Re: European digital ID wallets rely on safety services of Google and Apple

#113
post #82

Earlier quoted context omitted.

There is too much corruption, nothing can be done at this point. Atleast CIE app works on graphene for now so I can do everything else on the web. If they block that idk what I would even do.

Don't assume corruption for something that can be attributed to not giving a fuck.

Corruption to push it through, not giving a fuck to keep it that way.

Re: European digital ID wallets rely on safety services of Google and Apple

#114
post #57

Sarcastic view: Doesn't matter - the EU wont listen, then pull a surprised pikachu and make laws to force googles play integrity to attest that other devices are genuine, because obviously, the problem is google, not stupid design decisions made while creating the app.

I think EU is warming up to the possibility that relying on US tech is has strategic consequences.

Re: European digital ID wallets rely on safety services of Google and Apple

#115
post #100

Earlier quoted context omitted.

Don't assume corruption for something that can be attributed to not giving a fuck.

I do occasionally suspect corruption, but neither Google nor Apple have any incentive to pay off officials to get this passed. They can't beat each other, and the rest of the mobile OS'es is no threat to their revenue.

Google and Apple's odds of being caught are too high to expect they would risk it. They have more to lose if caught than they have to gain.

Obviously some companies do despite the risks, I wouldn't expect this of any individual company, but as a whole some company will once in a while anyway. So stay vigilant.

Re: European digital ID wallets rely on safety services of Google and Apple

#116
Why cant EU have something like Adhar (ID-verification for Indians) https://uidai.gov.in/en/

It captures biometrics and is used across India to easily verify identification using OTP on mobile. Used across almost every sphere - bank accounts, passport, financial services like stocks/mutual funds etc.

You get a unique adhar-id (or can generate virtual IDs if sharing temporarily) to verify your identity across any service.

Re: European digital ID wallets rely on safety services of Google and Apple

#118

Earlier quoted context omitted.

>150 million functionally illiterate people in Europe 1/3 of the population functionally illiterate in Europe seems beyond wild to me. Are you talking about technical illiteracy? security illiteracy? Or do you mean they can't read english, which is a very different thing.

Functionally illiterate means that they can read in their own language, but they cannot understand the meaning, a part from very simple things.

And we're heading to giving better quality feedback loops to AI models than people. Put this together with ignorance being the mother of evil and...

How good this can become?

Re: European digital ID wallets rely on safety services of Google and Apple

#119
post #97

Earlier quoted context omitted.

How much money did the EU finance towards alternatives last year then? I hear them complaining but for now, the alternatives are mostly run by hobbyists. We're starting from so low that even a few dozen millions would help a lot.

> €2 billion over seven years to fund alternatives to proprietary software

I'll believe it when I'll see it, for now I haven't seen any of the Android forks (LineageOS, EOS, GrapheneOS...) or Linux OS (Phosh, Plasma mobile, Ubports, ...) get any funds from the EU.

Re: European digital ID wallets rely on safety services of Google and Apple

#120

Earlier quoted context omitted.

Went from nice to rude in no time. 4chan greentext style over substance is cute, but its outdated and wasnt that funny a decade ago if you have nothing to add, then why reply?

I have never been nice, but I admit I have no better literary device to concisely express my sentiment towards your flawed position, to put it nicely. I am pro-regulation, where regulation for me is busting monopolies, preventing tragedy of commons, setting necessary quality checks, forbidding forced labor. I am against regulation, when it's chat control, 100% tarrifs on whatever, forbidding working on Friday past 17…

> I have never been nice,

first comment was both cheeky and had a "i agree" at the end. Those are both niceties. Not sure why I would have to explain tone from mild critique to being a wee cu nt in back to back messages

> I am pro-regulation, where regulation for me is busting monopolies, preventing tragedy of commons, setting necessary quality checks, forbidding forced labor. I am against regulation

What does any of this nonsense have anything to do with me replying to someone who had a basic question about the non existance of monopolies in unregulated markets?

I explained the basic mechanisms for monopoly creation which are all easy math formulas that happen in bacteria growth too because "if nothing stops me I eat everything" is equally valid in any env where there is growth

> There's no nuance remaining in this world

coming from anti-intellectual "oh you know chesterton fence" responses is pretty ironic.

Btw if you are going to call people out for using big words maybe dont come out with the most 17 year old "people arent as smart as me as they emotionally attach themselves to sophistry while I am a nuanced rational ubermench". It reeks of intellectual insecurity.

i asked for empirical evidence against the mechanisms of monopoly creation because moats, regulation and inelastic markets are the most studied and reproducible mechanisms in anture, economics and any growth env. The formula just converges to infinity

> In short - fuck America.

its like 3am there, everyone here is asian and european rn... you are fighting windmills

Post reply on HN