Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

281–290 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#281
post #195
post #89

Earlier quoted context omitted.

I'm sorry but clearly the introduction of these apps with these requirements in the near past and near future represent regression over time rather than improvement. I think it was last year that there was a good presentation from them about how they were going to use ZKP and it was indeed very trust inspiring. But do you think the latest digital wallet solution from eg Danish government uses ZKP? Of course not! I ha…

I see your point about the disconnect between the rhetoric and what we actually see in production. Perhaps "regression" is a strong word, though, IMHO I tend to see it as a very slow and uneven evolution. Even if the pace is frustrating, there are still pockets of genuine open-source adoption in the European public sector. For example, we're seeing projects like Germany's OpenDesk or various municipalities moving tow…

What he's correctly saying is that if even one major country adopts an EUID Wallet implementation that only allows for Google and Apple, this on its own has a magnitudes bigger impact than the pockets you're talking about. That's a regression.

Re: European digital ID wallets rely on safety services of Google and Apple

#282

Earlier quoted context omitted.

Is any of that capable of replacing google and apple on mobile?

Clearly it isn’t. This is what techies forget: The mass amount of Europeans don’t give 2 shits about digital sovereignty or open source. Christ, people go to mobile operator shops and give their unlocked phones to consultants to install or remove software for them. You want them to install GrapheneOS or manage a rooted device? That ain’t even funny. The only short-term solution is more regulation and more EU-centrali…

> Clearly it isn’t. This is what techies forget: The mass amount of Europeans don’t give 2 shits about digital sovereignty or open source.

When Trump was invading Denmark, a huge % of Danes would've given a shit about sovereignty from the US. And that's the moment to pounce.

Re: European digital ID wallets rely on safety services of Google and Apple

#283
post #4

A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.

> Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support.

If the EU was trying to decouple they'd mandate at least including a hardware token option as an alternative. This is not new technology, it's existing and has been in use for decades.

They're not trying to decouple, so they haven't mandated it.

Re: European digital ID wallets rely on safety services of Google and Apple

#284

Earlier quoted context omitted.

Definitely not bad all the time. For instance, GrapheneOS provides the Auditor app, with which you can verify from another phone or from a server that the OS is not tampered with. It also uses remote attestation. So, there are certainly useful applications.

I question the usefulness of Auditor. It can flag if a modified version of GrapheneOS has been booted, for example. But flashing a modified version of GrapheneOS requires erasing userdata, which you'd notice the moment all your data isn't there. Unless someone uses an exploit, but Key Attestation cannot detect exploits. I suppose if you've bought a device with GrapheneOS already installed, you can use it to verify th…

Largely agreed. Though I think there are useful applications: 1. the one you mention; 2. to protect against installation of a malicious image (e.g. because your browser/certificate store compromised); 3. a sophisticated attack where an attacker knows your credentials at some point (e.g. PIN), extract your data when the phone is unattended, flashes a compromised image, and restores the data (with the goal to surveil your phone).

Admittedly, most of these are probably nation state-level attacks, but I think some GrapheneOS users are the target of such attacks. Also, it doesn't hurt to run Auditor after a fresh install to protect against the second scenario. It only takes a minute, better safe than sorry.

Re: European digital ID wallets rely on safety services of Google and Apple

#285
post #48

Earlier quoted context omitted.

Oh they sure do, because Google/Apple have to bend over backwards for the EU as they are not stupid enough to suddenly lose 500 million users.

Really? Google to this day refuses to do business in China, and Apple at this very moment excludes the EU from multiple new iOS 27 features that launch in the rest of the world. And with the current direction the EU is taking (e. g. even more regulation, more economic recession, even fewer competitive tech businesses), I wouldn’t bet on US companies getting "more favorable" towards the EU.

Looking forward to the Apple quarterly earnings call where Tim Cook (or soon the new guy) explains why they decided to let go of the EU, leading to a 30% fall in revenue and net profit. I'm sure investors will be delighted.

Re: European digital ID wallets rely on safety services of Google and Apple

#288
post #217

Earlier quoted context omitted.

I think there are two fights that are both worth fighting: 1. Completely outlawing remote attestation. 2. In a world where remote attestation is given, let it be controlled in a fair way and not just by Google and Apple. The risk is that only fighting for (1) leaves you in a world with remote attestation, where only Google and Apple can decide who gets to pass and who not. In fact, that is pretty much the world we ar…

Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?

Only acceptable use of attestation is when done on behalf of device owner. So if they let me submit list of keys allowed for my account, fine, but any other use is just evil restriction of what software I can run on my own devices.

Re: European digital ID wallets rely on safety services of Google and Apple

#289

Earlier quoted context omitted.

Can you elaborate?

On the tech side, we are working closely with (for instance) Google: https://github.com/openwallet-foundation/multipaz-wallet SPRIND: https://github.com/openwallet-foundation/eudiplo Animo: https://github.com/openwallet-foundation-labs/mdoc-ts and we do engage with NGOs and governments across the EU.

Thank you for the expanded explanation. But it doesn't really explain how we should help and what you hope to achieve with our help. A bit more targeted information would be appreciated. You seem to be doing important work, but it's difficult to understand what you want from us.

Re: European digital ID wallets rely on safety services of Google and Apple

#290

EU should have mandated a user-facing authentication scheme using a random string as the only authentication factor for everything. Pretty much like the API tokens for contemporary enterprise software, except that they would be used by ordinary people and not by application developers. And complement it with hardware tokens for highly sensitive applications. Passkeys could have been that, but they were quickly subver…

Tell me you’ve never supported a large userbase without telling me you’ve never supported a large userbase.

What’s the plan for supporting the 50,000 people a day who lost their random string? What’s the plan for supporting the other 50,000 a day who pasted it into a random website? Europe has a billion people.

Post reply on HN