Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

221–230 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#221

Earlier quoted context omitted.

Why is a trusted device chain needed? It will put more trust in the potential Chinese device maker and American software companies than the user who's id is shown?

Simply because the law was written that way. But also the whole idea of identity verification becomes pretty useless, if there is no chain of trust. You could run a modified client that lets you assume any identity you choose, exactly the opposite of what eIDAS is trying to achieve.

It will likely display something like a QR Code with signature anyways, otherwise it's just a glorified passport picture?

Authorities/anyone could verify that it's not counterfeit. And photo should be checked anyways to match the person.

So I also don't see the need for attestation. For ID check it should be ok without. For signing stuff ofc it is not resistant to copying. But EID smartcard function already exists.

Re: German implementation of eIDAS will require an Apple/Google account to function

#222
post #67

The Danish MitId also only runs on Google and Apple devices. No alternative phone platforms are supported including open source Android. If you don’t have an iPhone or an android, you can get a physical one time password device.

You can get that, even if you have a phone with the app on it. MitID is perfectly okay with that. At login time you will be prompted for your token code, but there is an option to switch to the app ("Skift til MitID app" in the bottom of the box).

The MitID design is strange, but in this regard it is well done.

Re: German implementation of eIDAS will require an Apple/Google account to function

#223

Earlier quoted context omitted.

You should think about how easy it is to permanently lose access to your Google account for very trivial issues and Google doesn't offer any form of recovery. That in addition to the current geopolitical situation should be reason enough not to rely on that for any justification. And personally as a software developer myself i know that nothing is more permanent than a temporary solution. No one will prioritize or gi…

What? They should freaking think of sanctions, not about "how easy is to lose Google account". Both Google and Apple are American companies. If someone lands on a sanctions list, they close your account without further notice [1]. Let me get this straight: you can be a defender of human rights, aligned with the country you live in, but if you fall in disgrace with the American government, _you can't even do transacti…

Sanctions are a bonus point argument, but shouldn't be a factor either. No citizen should be subjected to this, whether the company running it is American or German. Can you imagine if the Nazis had this level of control in the 1930s? Imagine having your ID digitally revoked, effectively cutting you out of society completely, without so much as an attic to hide in before it can happen. This is a completely dystopian legislation from start to finish. There is no possible way this can ever provide a benefit to the German people, it exists only to control them.

Re: German implementation of eIDAS will require an Apple/Google account to function

#224
post #110

Earlier quoted context omitted.

I believe the idea is that friction and resistance is proportional to the square of the speed. After a certain speed, every 10 mph extra starts to really count in your mileage.

The idea is that some green ideologists think that when they don't need to drive a car because they don't leave their city, no one needs to drive a car. Because car driving creates CO2 which means car driving is bad. And they search for ways to implement that or make driving a car as bad as possible. Because they can't make the Deutsche Bahn better, they have to make driving your own car worse.

An EV is the superior vehicle in every aspect. Cheap fuel, reliable, nice to drive, less maintenance costs, less noisy and yes, no local emissions.

Re: German implementation of eIDAS will require an Apple/Google account to function

#225

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Perhaps look at the Spanish Cl@ve, it works with Linux. It's just a simple digital certificate that allows you to identify yourself.

You can even run it on OpenBSD or TempleOS if you want to.

Re: German implementation of eIDAS will require an Apple/Google account to function

#226

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

[dead]

Re: German implementation of eIDAS will require an Apple/Google account to function

#227
As someone living in Germany, the alternative would be snail mail, which is used to send a pre-authentication code, username and then another code. This is pretty common with insurance providers, German traditional banks, etc. However, the annoying part is that if you ever forget or lose the code, then you would have to request a new one via mail that would arrive like 2 weeks after.

Re: German implementation of eIDAS will require an Apple/Google account to function

#228

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Just a quick question, and sorry if it might have been answered already... why preventing duplication is so important? I know it’s in the spec probably [1], but I can’t figure out the reason. And a suggestion: add external HSM support at least? (e.g. things like NitroKey/YubiKey) [1]: https://eudi.dev/latest/architecture-and-reference-framework... I suppose?

Preventing credential duplication is a requirement to achieve high level of assurance. One of its purpose is to limit the potential damage that can be done by attacks. If credentials are bound to hardware-bound keys, attackers will always need access to this key store to make any miss-use. If you don't prevent duplication, attackers may extract credentials and miss-use them at a 1000 places simultaneously.

Re: German implementation of eIDAS will require an Apple/Google account to function

#229
post #90

I'm not quite sure if the German implementation is possible without mobile devices (couldn't find anything on that at first glance). the Austrian implementation on the other hand does not require a mobile device, if you want to do it on a pc you just need a fido2 token

I havent looked into the details of either, but what would prevent Germans from using the Austrian implementation?

Re: German implementation of eIDAS will require an Apple/Google account to function

#230

ISO7816 (smartcard) has existed for nearly 4 decades as the standard secure identity card, widely used by the banking industry among others. Very unintrusive and not hostile beyond needing to carry a little chip. If governments want a national ID, they could just give everyone one of those.

This is exactly how we implemented eIDAS in Spain. The government-issued national ID (DNIe) is an ISO 7816-compliant smart card. Latest versions are also ISO 14443-compliant for contactless reading. To use it, you just need a simple smart card reader or an NFC-enabled phone. https://www.dnielectronico.es/PortalDNIe/PRF1_Cons02.action?...

[dead]
Post reply on HN