Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

211–220 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#211

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

> That doesn't work without operating system support

Do you realize where this path is going?

Certain European governments would have greatly benefited from KYC/attestation in the late 1930s had it existed.

Re: German implementation of eIDAS will require an Apple/Google account to function

#212

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

It's insane to make yourselves US dependent from the very beginning, at least provide something like a crypto-key that you can get from an official, banks can do it, so can you.

Re: German implementation of eIDAS will require an Apple/Google account to function

#213
post #35

Earlier quoted context omitted.

Come September, there will be no side loaded apps on Android.

You're behind on your news! Google details new 24-hour process to sideload unverified Android apps (1196 points, 16 days ago, 1262 comments) https://news.ycombinator.com/item?id=47442690

Functionaly it's dubious if this will not cause further issues. Developer tools cause some security checks to fail. It's not yet known if the unknown apps setting will do the same

Re: German implementation of eIDAS will require an Apple/Google account to function

#214

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices?

Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Re: German implementation of eIDAS will require an Apple/Google account to function

#215
post #146

What if you „lose“ your google / apple account, like this sanctioned judge of the international criminal court? Crazy to imagine that we are still baking in dependency on US providers in european societies, even though there is clear indications we should be doing the opposite?

> Crazy to imagine that we are still baking in dependency on US providers in european societies As long as the capital city is in Washington, this is normal.

Not sure I‘m getting what you are saying - us providers‘ capital city is always in Washington DC, no?

Sorry if I’m misunderstanding something here

Re: German implementation of eIDAS will require an Apple/Google account to function

#217

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Just a quick question, and sorry if it might have been answered already... why preventing duplication is so important? I know it’s in the spec probably [1], but I can’t figure out the reason. And a suggestion: add external HSM support at least? (e.g. things like NitroKey/YubiKey) [1]: https://eudi.dev/latest/architecture-and-reference-framework... I suppose?

I’ve just had another, completely stupid but not implausible, idea:

> a local internal WSCD, which is a component within the User device, such as a SIM, e-SIM, or embedded Secure Element,

So you could issue SIM-cards / eSIM profiles that only do signatures and nothing else. The app then connects to such eSIM (and you keep your main SIM/eSIM in another slot).

The less stupid variant is, of course, to get mobile operators to issue SIM cards with e-sign capabilities. Estonia has that, for example: https://www.id.ee/en/mobile-id/

Re: German implementation of eIDAS will require an Apple/Google account to function

#218
post #55

Earlier quoted context omitted.

Germany is distracted with its version of “the gun debate” aka speed limits. Like every school shooting, every energy crisis brings opportunity to saturate the airwaves with shallow noise that gets people overly upset and they’ll ignore everything else. Every player on both sides is abusing this mechanic for all eternity.

Imagine we had real democracy where people vote on issues. Speed limits? Vote once every 7 years or so on it and be done with it. Same for abortion laws, drug laws, gambling laws. Have a debate, vote, come back to it in 7 years if there is public interest. Preferably vote locally on issues that can be applied locally (like speed limits/enforcement etc.). Public debate and assessing politicians and parties would be so…

As a Swiss all I can say is that this is not how that would work out. Some of the most polarising statements I have ever heard come from Swiss politicians.

Although it is a more recent development since a certain billionaire (what else) took up politics as a side hustle.

Re: German implementation of eIDAS will require an Apple/Google account to function

#219

Earlier quoted context omitted.

Why is a trusted device chain needed? It will put more trust in the potential Chinese device maker and American software companies than the user who's id is shown?

Simply because the law was written that way. But also the whole idea of identity verification becomes pretty useless, if there is no chain of trust. You could run a modified client that lets you assume any identity you choose, exactly the opposite of what eIDAS is trying to achieve.

Who wrote that law and why, this is the question.

I think we need some fingerpointing that EU officials strive to avoid.

Post reply on HN