Earlier quoted context omitted.
I'm sorry but clearly the introduction of these apps with these requirements in the near past and near future represent regression over time rather than improvement. I think it was last year that there was a good presentation from them about how they were going to use ZKP and it was indeed very trust inspiring. But do you think the latest digital wallet solution from eg Danish government uses ZKP? Of course not! I ha…
I see your point about the disconnect between the rhetoric and what we actually see in production. Perhaps "regression" is a strong word, though, IMHO I tend to see it as a very slow and uneven evolution. Even if the pace is frustrating, there are still pockets of genuine open-source adoption in the European public sector. For example, we're seeing projects like Germany's OpenDesk or various municipalities moving tow…
European digital ID wallets rely on safety services of Google and Apple
281–290 of 327 posts
Re: European digital ID wallets rely on safety services of Google and Apple
#282Earlier quoted context omitted.
Is any of that capable of replacing google and apple on mobile?
Clearly it isn’t. This is what techies forget: The mass amount of Europeans don’t give 2 shits about digital sovereignty or open source. Christ, people go to mobile operator shops and give their unlocked phones to consultants to install or remove software for them. You want them to install GrapheneOS or manage a rooted device? That ain’t even funny. The only short-term solution is more regulation and more EU-centrali…
When Trump was invading Denmark, a huge % of Danes would've given a shit about sovereignty from the US. And that's the moment to pounce.
Re: European digital ID wallets rely on safety services of Google and Apple
#283A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?
Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.
If the EU was trying to decouple they'd mandate at least including a hardware token option as an alternative. This is not new technology, it's existing and has been in use for decades.
They're not trying to decouple, so they haven't mandated it.
Re: European digital ID wallets rely on safety services of Google and Apple
#284Earlier quoted context omitted.
Definitely not bad all the time. For instance, GrapheneOS provides the Auditor app, with which you can verify from another phone or from a server that the OS is not tampered with. It also uses remote attestation. So, there are certainly useful applications.
I question the usefulness of Auditor. It can flag if a modified version of GrapheneOS has been booted, for example. But flashing a modified version of GrapheneOS requires erasing userdata, which you'd notice the moment all your data isn't there. Unless someone uses an exploit, but Key Attestation cannot detect exploits. I suppose if you've bought a device with GrapheneOS already installed, you can use it to verify th…
Admittedly, most of these are probably nation state-level attacks, but I think some GrapheneOS users are the target of such attacks. Also, it doesn't hurt to run Auditor after a fresh install to protect against the second scenario. It only takes a minute, better safe than sorry.
Re: European digital ID wallets rely on safety services of Google and Apple
#285Earlier quoted context omitted.
Oh they sure do, because Google/Apple have to bend over backwards for the EU as they are not stupid enough to suddenly lose 500 million users.
Really? Google to this day refuses to do business in China, and Apple at this very moment excludes the EU from multiple new iOS 27 features that launch in the rest of the world. And with the current direction the EU is taking (e. g. even more regulation, more economic recession, even fewer competitive tech businesses), I wouldn’t bet on US companies getting "more favorable" towards the EU.
Re: European digital ID wallets rely on safety services of Google and Apple
#286Re: European digital ID wallets rely on safety services of Google and Apple
#287Re: European digital ID wallets rely on safety services of Google and Apple
#288Earlier quoted context omitted.
I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…
Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?
Re: European digital ID wallets rely on safety services of Google and Apple
#289Earlier quoted context omitted.
Can you elaborate?
On the tech side, we are working closely with (for instance) Google: https://github.com/openwallet-foundation/multipaz-wallet SPRIND: https://github.com/openwallet-foundation/eudiplo Animo: https://github.com/openwallet-foundation-labs/mdoc-ts and we do engage with NGOs and governments across the EU.
Re: European digital ID wallets rely on safety services of Google and Apple
#290EU should have mandated a user-facing authentication scheme using a random string as the only authentication factor for everything. Pretty much like the API tokens for contemporary enterprise software, except that they would be used by ordinary people and not by application developers. And complement it with hardware tokens for highly sensitive applications. Passkeys could have been that, but they were quickly subver…
What’s the plan for supporting the 50,000 people a day who lost their random string? What’s the plan for supporting the other 50,000 a day who pasted it into a random website? Europe has a billion people.