Earlier quoted context omitted.
Tbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.
Banks actually have high fraud rates today because of weak security mechanisms. If attackers steal your money, the bank will reimburse you. If attackers steal your identity, you are really screwed. Security requirements for banking and identity are simply different.
German implementation of eIDAS will require an Apple/Google account to function
301–310 of 674 posts
Re: German implementation of eIDAS will require an Apple/Google account to function
#302Earlier quoted context omitted.
Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...
Operate European tech infrastructure without a dependency on America challenge (Impossible) For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account. Why remove a dependency on Google, when you'll still be 100% dependent on Google? Anybody working on "Digital ID" has alre…
Plus, the net difference is that this gives Google and Apple the ability to kill the ability of individuals to make payments (and tax them) ... do you want that?
(And I would say, compared to having European banks tax them, the answer is not so obvious)
The real issue is, of course, that this moves the burden of keeping phones secure onto Google and Apple, who are very willing to take on that burden in trade for a percentage of all consumer payment traffic in Germany. It's yet another choice between "spend money now to build a government department to secure payments ... or have Apple/Google do that for you". And they're choosing to save a little bit of money in the short term in trade for what is effectively a new tax.
Re: German implementation of eIDAS will require an Apple/Google account to function
#303Earlier quoted context omitted.
Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-andro...
Why would this be? Bureaucracy / inability to change?
Either the government secures internet payments themselves, which means spending now to do so, coming up with a plan, ... or they can have Apple/Google do it.
Re: German implementation of eIDAS will require an Apple/Google account to function
#304German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
Re: German implementation of eIDAS will require an Apple/Google account to function
#305Earlier quoted context omitted.
Isn't the eIDAS 2 wallet approach a legal requirement of eIDAS 2 (which is an EU regulation, i.e. the law).
It is, mandated by the EU commission. Instead they could have mandated the use of eIDAS 1 to all countries + extend it with attribute/credential support, and let countries choose their implementation (cards, SIM, server-side). Instead we’re back to the drawing board with the big shortcomings highlighted in this thread.
Re: German implementation of eIDAS will require an Apple/Google account to function
#306Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.
Either governments can develop (and pay for) THAT technology, or they can use Apple/Google ...
Re: German implementation of eIDAS will require an Apple/Google account to function
#307German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
In light of all of these shortcomings with platform attestation, why go with the eIDAS 2 wallet approach at all? eIDAS 1 already solved this with Mobile-ID (SIM-based, no Google/Apple dependency) and Smart-ID (server-side key management with minimal platform reliance). What does the wallet model give you that justifies this level of dependency on two American corporations’ proprietary backends? Especially considering…
Smart-ID sucks. It's not truly hardware-backed, it's proprietary and has fundamental flaws like not having a direct link between the site being authenticated to and the authenticating device (auth can be proxied, just like if it were just plain TOTP).
Re: German implementation of eIDAS will require an Apple/Google account to function
#308German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
GrapheneOS uses standard Android APIs for hardware attestation (as opposed to Google-specific ones), so why don't you just use those from the get-go?
Re: German implementation of eIDAS will require an Apple/Google account to function
#309Sometimes I wish the Germans had an island of their own somewhere up north near the american continent.
Re: German implementation of eIDAS will require an Apple/Google account to function
#310Earlier quoted context omitted.
I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…
Comparing being able to run the hardware and software of your choice to "wanting a passport in a different color or whatever" is so completely fucked, and it's beyond insane as a justification for giving two American tech companies with a well established track record for doing evil control over your citizens' ID. The world has gone absolutely mad, what the fuck am I even witnessing? It is quite literally becoming 19…
Demanding full control over something like an ID will fundamentally not happen. The same way you won't have full control over the way passports or paper bills are made.
Take for example the expectation that some poor fool's ID can't be cloned and reused by malicious actors - full control directly contradicts that. It will not and must not be possible.