Live data from Hacker News

EU age verification app not planning desktop support

github.com

211–220 of 437 posts

Re: EU age verification app not planning desktop support

#211
post #129

Earlier quoted context omitted.

> you can't run your bank's app I can log in to my bank account using my desktop PC > government eID apps I can sign into government websites using my desktop PC and its smart card reader and my government-issued eID smartcard. No smartphone needed.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

While everyone took the opportunity to reply to you with "Not in my bank/country/to-my-awareness" This is what's happening in Portugal:

https://old.reddit.com/r/portugal/comments/1msc886/obriga%C3...

Effectively, if the client doesn't download the App, they will never be able to log into the homebanking website again. The bank enforced this and now if you login normally it will redirect to a page where you can download the app or use up one of three remaining chances to login. I am down to two. From now on, I'm only able to use ATM's or go to an actual teller to make payments and such. The app requires that I have a Google account or an Apple account and I think that's just messed up, specially for a Portuguese bank.

The app on the google store is pt.novobanco.nbsmarter if anyone is curious. It has interesting permissions as well.

Edit: This is the landing page (one login left, oh dear...) https://files.catbox.moe/x117iy.png

rsync, here you go:

https://reports.exodus-privacy.eu.org/en/reports/652314/

Re: EU age verification app not planning desktop support

#213
post #129

Earlier quoted context omitted.

> you can't run your bank's app I can log in to my bank account using my desktop PC > government eID apps I can sign into government websites using my desktop PC and its smart card reader and my government-issued eID smartcard. No smartphone needed.

Not in EU. Many banks mandate you either have an iPhone or Google approved Android as 2FA. Those fucking idiots have killed their own competition options.

>Not in EU.

Please stop spreading disinformation. I live in the EU and my EU bank supports desktop browsers + Card reader matching everything the mobile app can do.

Re: EU age verification app not planning desktop support

#214

Well, in the end there may only be one thing left we can collectively do, but which we surely won't collectively do, because too many of us are way too comfortable to accept any discomforts: We can avoid using services implementing shit, so that any business that singles out desktop users or disadvantages them, doesn't have much of a customer base. Voting with out feet. I have very little hope, that the common user w…

Unless you can show a direct cause-and-effect relationship from clicking OK on some form to something negative happening in their real life that impacts them in actual physical real life, a real event at a particular time that they can observe with their eyes that relates to their real life (family, job, social life, going about their day), most people won't care. Otherwise it all blurs to some abstract words and theoretical tinfoil-like worries about the "government" and ufos and sovereign citizens.

Re: EU age verification app not planning desktop support

#215
post #164

I've posted this as a response but I'll post it again since it seems like a lot of people are confused about the project: This project is not THE digital wallet, it is an early prototype of the wallet (which can be criticized for what it is, but the issue is somewhat orthogonal). The actual infrastructure is not based on attenstation, if you read the guidelines (or the readme) they actually want to implement a double…

> a lot of people are confused about the project This is misleading. They are merely exploring options that may allow for issuer unlinkability, but they are actually implementing a linkable solution based on standard cryptography that allows issuers (member state governments) to collude with any verifier (a website requiring age verification) to de-anonymize users. The solution is linkable because both the issuer and…

> This is misleading. They are merely exploring options that may allow for issuer unlinkability, but they are actually implementing a linkable solution based on standard ECDSA..

The repository we're commenting on has the following in the spec[0]: "A next version of the Technical Specifications for Age Verification Solutions will include as an experimental feature the Zero-Knowledge Proof (ZKP)". So given that the current spec is not in use, this seems incorrect.

> It will also be trivial to circumvent

If you have a key with the attribute of course you can 'bypass' it, I don't think that's bug. The statement required should be scaled to the application it's used for; this is "over-asking" is considered in the law[1].

> The project is supposed to prove that age verification is viable, while it completely disregards privacy by design principles in its implementation. That the project intends to perhaps at some point implement privacy enhancing technologies doesn't make it any better.

I agree that in it's current state it is effectively unusable due to the ZKPs being omitted.

[0]: https://github.com/eu-digital-identity-wallet/av-doc-technic... [1]: https://youtu.be/PKtklN8mOo0?si=bbqtzMhIK7cFLh6S&t=375

Re: EU age verification app not planning desktop support

#216
post #5

This is hardware attestation in a nutshell: a double edged sword, and a sharp one at that. The biggest issue is that the attestation hardware and the application client is the same device with the same manufacturer, who also happens to have a slight conflict of interest between monetizing customers and preserving any sort of privacy. IMHO the pro-attestation forces are so overwhelming that we should all cherish the m…

The insane question here is, why would the EU mandate hardware attestation controlled by two private American companies in order to access services? That seems completely contrary to the spirit of EU laws and regulations, which tend to be about protecting the consumer, preventing monopolies, ensuring people can generally live their lives where all things that are mandatory are owned and ran by the state and foster a…

> The insane question here is, why would the EU mandate hardware attestation controlled by two private American companies in order to access services?

Please (kindly) ask Paolo De Rosa [1], Policy Officer at the European Commission and driver of many of the decisions behind the wallet and the ARF. His position is one of fatalism: that it's "too late"; the duopoly of Goople is entrenched, and it's therefore not a problem if the wallet project entrenches it even further. Regrettably quite a lot of member states agree, although representatives of France and Germany specifically are frequently standing up to the fatalism.

[1] https://github.com/paolo-de-rosa

Re: EU age verification app not planning desktop support

#218
post #208
post #185

Earlier quoted context omitted.

Of course in the EU - pretty much all Baltic and Nordic countries support id cards connected via usb

Well not in Germany. Some banks accept their branded authenticators, some of them don't. ING in Germany forces you to either have a single Google approved smartphone or a single authenticator, not both. DKB requires a paid Girocard to use the authenticator or a Google approved smartphone. N26 requires a single phone but they are a bit lenient. However they have way too many incidents reported where they closed people…

My German bank started to require an Android or IOS smartphone [0]. No dedicated HW, no desktop. I actually dumped my well working Xiaomi Phone because it was either security or banking.

[0] https://www.1822direkt.de/service/fragen-und-antworten/detai...

Re: EU age verification app not planning desktop support

#219

Earlier quoted context omitted.

It doesn't surprise me either, because I'd never be able to use a phrase like "the principles and know-how of the EU" with a straight face. (To be fair, you could replace "the EU" with almost any large bureaucracy.)

Sure. But the EU is not just your average bureaucracy. It's an entity that has as one of it's specific goals the following[1]: > combat social exclusion and discrimination [1] https://european-union.europa.eu/principles-countries-histor...

Any large bureaucracy has similarly lofty official goals

Re: EU age verification app not planning desktop support

#220

Earlier quoted context omitted.

Nope, Sweden requires Mobile BankID on iOS or Android for example.

BankID has a desktop version, and no site which requires Mobile BankID would not allow you to also use the desktop version.

But it doesn't support Linux.
Post reply on HN