Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

21–30 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#21
post #11
post #4

Earlier quoted context omitted.

EU digital identity law to make inter-EU signatures (And authentication) work. As an example, an EU citizen working in Sweden should be able to submit Swedish tax forms whilst living here by using a digital identity from the originating nation. There are also some standards in place like ETSI standardized extensions to PDF signatures so that you can verify that a signature inside the PDF was actually signed by a spec…

Is there a reason this user-hostile mess is preferred over an X.509 certificate (besides big tech lobbying)? Slovenia hands out certificates for online government services, including document signing, and it seems to be going fine, with the added benefit that Google can't take away my access.

eIDAS is about making the electronic IDs emitted by the different EU governments intercompatible, so you can use a Slovenian certificate to authenticate into the German tax system, if you want to.

Re: German implementation of eIDAS will require an Apple/Google account to function

#22
post #8
post #4

Earlier quoted context omitted.

EU digital identity law to make inter-EU signatures (And authentication) work. As an example, an EU citizen working in Sweden should be able to submit Swedish tax forms whilst living here by using a digital identity from the originating nation. There are also some standards in place like ETSI standardized extensions to PDF signatures so that you can verify that a signature inside the PDF was actually signed by a spec…

The gold standard for digital signatures today is - someone sends you a docusign link - you sign up with your email - you sign with your name in a cutesy font Theres a dispute? Well it was going to end up in court no matter how you signed it anyway. This has all the hallmarks of a design by committee project by people whose salary is paid regardless of demonstrating market fit, productivity, usage, plain sensibleness…

> Theres a dispute? Well it was going to end up in court no matter how you signed it anyway.

The fact that it's ALWAYS a docusign is the ridiculous part. It is just a glorified where you enter your name and email. No need to pretend otherwise. Any other service would be just as good. This is basic human sheep-like behavior?

Re: German implementation of eIDAS will require an Apple/Google account to function

#23

The title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used. An alternative option, would be to use the Hardware Attestation API directly, GrapheneOS would be thanking you. I've spent a good amount of time implementing exactly this type of system for a backup ser…

> App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed. To me, there is no difference between your sentences. You require the blessing of an American company to be able use eIDAS. Google has the power to disable eIDAS at a national scale by making the attestation services treat all devices as not certified…

I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work.

But in pure technical & UX terms, you don't need to be logged in.

Re: German implementation of eIDAS will require an Apple/Google account to function

#24
post #8
post #4

Earlier quoted context omitted.

EU digital identity law to make inter-EU signatures (And authentication) work. As an example, an EU citizen working in Sweden should be able to submit Swedish tax forms whilst living here by using a digital identity from the originating nation. There are also some standards in place like ETSI standardized extensions to PDF signatures so that you can verify that a signature inside the PDF was actually signed by a spec…

The gold standard for digital signatures today is - someone sends you a docusign link - you sign up with your email - you sign with your name in a cutesy font Theres a dispute? Well it was going to end up in court no matter how you signed it anyway. This has all the hallmarks of a design by committee project by people whose salary is paid regardless of demonstrating market fit, productivity, usage, plain sensibleness…

Can I use Docusign to provide my identity in Estonia online via my phone when I move there to buy a SIM card or open a bank account or file a document with the local authority?

Can I also send the Docusign document via Signal without Docusign knowing the person who signs it?

Because that is what the eIDAS is supposed to deliver on top of cryptographic validation of signatures.

Re: German implementation of eIDAS will require an Apple/Google account to function

#25
All these requirements for specific hardware and software are ridiculous. Let every citizen use whatever computer they want. It should be up to the user to secure themselves. Authentication should only require a password or a key pair. If the user wants more security, they can set up TOTP or buy a security dongle or something.

It's also ridiculous how it seems we've forgotten computers other than smartphones exist and that not everyone even has a smartphone, let alone with an Apple or Google account.

Re: German implementation of eIDAS will require an Apple/Google account to function

#26

The title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used. An alternative option, would be to use the Hardware Attestation API directly, GrapheneOS would be thanking you. I've spent a good amount of time implementing exactly this type of system for a backup ser…

> App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed. To me, there is no difference between your sentences. You require the blessing of an American company to be able use eIDAS. Google has the power to disable eIDAS at a national scale by making the attestation services treat all devices as not certified…

I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service.

App attestation can fail on simulators, Graphene OS, dev builds, I've seen it all. There is one check you can do to see if an app was side loaded, so indirectly, can require Google account.

Title is still misleading though, as it explicitly mentions accounts.

Re: German implementation of eIDAS will require an Apple/Google account to function

#27

Earlier quoted context omitted.

> App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed. To me, there is no difference between your sentences. You require the blessing of an American company to be able use eIDAS. Google has the power to disable eIDAS at a national scale by making the attestation services treat all devices as not certified…

I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in pure technical & UX terms, you don't need to be logged in.

[flagged]

Re: German implementation of eIDAS will require an Apple/Google account to function

#28
post #11
post #4

Earlier quoted context omitted.

EU digital identity law to make inter-EU signatures (And authentication) work. As an example, an EU citizen working in Sweden should be able to submit Swedish tax forms whilst living here by using a digital identity from the originating nation. There are also some standards in place like ETSI standardized extensions to PDF signatures so that you can verify that a signature inside the PDF was actually signed by a spec…

Is there a reason this user-hostile mess is preferred over an X.509 certificate (besides big tech lobbying)? Slovenia hands out certificates for online government services, including document signing, and it seems to be going fine, with the added benefit that Google can't take away my access.

Most people wouldn't know what to do with a certificate, so governments build some stuff on top (like an official mobile app) which makes auth easier. It's usually just certificates underneath (not exposed to the user).

Eidas tries to harmonize these implementations across EU member states.

Re: German implementation of eIDAS will require an Apple/Google account to function

#29

Earlier quoted context omitted.

Not in software. German software is awful. Think german cars, banks, telecoms etc

While I agree, it'd be hard to say that SAP is not good

SAP software is the bane of most people, who have to use it, except for expensive consultants, who make bank preying on hapless clueless companies opting to use SAP software.

Re: German implementation of eIDAS will require an Apple/Google account to function

#30
I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.
Post reply on HN