Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

311–320 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#311
post #129

Earlier quoted context omitted.

But ... the alternative is that the government actually pays a bit of money to fix the situation! To support their solutions. To actually develop them for enough devices. To secure them ... Plus the services the government made are way more invasive than the Google/Apple ones. In addition to the money, actually using them would be hundreds of times more complex, and they don't have the provisions Google has, for exam…

I just dont buy the argument that it would be that expensive for the governments to provide certified keychain fobs that provide hardware based identification.

Here in Germany everyone who has an ID card, which is basically everyone, already has a secure chip for this purpose.

Re: European digital ID wallets rely on safety services of Google and Apple

#312
post #308

They should not make it mandatory for or expect people to have a smartphone.

It's not mandatory. Use of the wallet is voluntary and, for natural persons, free of charge.[29] https://en.wikipedia.org/wiki/EU_Digital_Identity_Wallet

for the moment

Re: European digital ID wallets rely on safety services of Google and Apple

#313
post #4

A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.

> But in many cases there are not any homegrown alternatives to support.

Everyone who says something like this should be forced to use one of the alternatives for at least a couple of months and then reassess why people don't use them.

Personally I'm using a Volla Quintus with Ubuntu Touch (ubports is a German foundation) because I'm a masochist.

Re: European digital ID wallets rely on safety services of Google and Apple

#314

Earlier quoted context omitted.

Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.

How much money did the EU finance towards alternatives last year then? I hear them complaining but for now, the alternatives are mostly run by hobbyists. We're starting from so low that even a few dozen millions would help a lot.

The EU's NGI Zero in cooperation with NLNet has been funding quite a bit of postmarketOS

https://nlnet.nl/project/postmarketOS/

https://nlnet.nl/project/MobileSettings

https://nlnet.nl/project/pmOS-23-24

https://nlnet.nl/project/postmarketOS-daemons

https://nlnet.nl/project/pmOS-25-26

I think if NGI Zero had been around when Meego was killed, we might be in a better situation now.

I also get the feeling, that the fact that there is so little reported and discussed about this funding reflects the actual level of interest in alternatives.

Re: European digital ID wallets rely on safety services of Google and Apple

#316
post #182
post #131

Earlier quoted context omitted.

I'm ok with enforcing hardware security. Both for banks and governments. But it must not limit the ability of running custom software on a phone. And especially not enforcing every person to get a Google/Apple signed phone. Like if I get GrapheneOS on my phone. Banking/gov apps should work. But I believe this could be possible with enforcing hardware security as well.

You can't have both. "Hardware security" means the manufacturer decides which OS can run and you can't override it.

Practically speaking, I can set up real hardware-enforced boot integrity on my Framework laptop today, both on Arch with sbctl and on NixOS with Lanzaboote or Limine.

There are still many unsolved problems in hardware security, so this is definitely not solved today. But I don’t see why it should be impossible. The EU could push the industry toward attestation models that respect user ownership instead of locking everything behind vendor-controlled software.

Re: European digital ID wallets rely on safety services of Google and Apple

#317
post #273

Earlier quoted context omitted.

For all practical purposes it's possible to do this. The boot ROM only boots a vendor-signed bootloader, the bootloader verifies the OS kernel, etc., until you have a fully verified boot chain. A secure enclave, which is completely separated from the main CPU and OS performs the attestation using a private key in its tamper-resistant storage and embeds the results of verification by the bootloader. There may be some…

Nope. It is still not possible to give someone else (the government, or the bank) control over your phone while at the same time run software that you alone control with higher privileges. Please don't mix that up with "is practically hard to implement because of sloppy code. Also your attacker model is still "occasional evil government agency or evil private corporation wants to crack and read your messages", while…

I want governments and banks to allow open-source software, not control my phone.

For example, I essentially trust the ROM I download from the GrapheneOS website. What I want is for governments, banks, or some independent open foundation to be able to approve that ROM too, so attestation can work with it.

More like how CA certificates work: not perfect, but not locked to one vendor either.

Re: European digital ID wallets rely on safety services of Google and Apple

#318
post #8
post #4

A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

The US can call Austria in 5 minutes and with no burden of proof get the airspace permit for a head of sovereign state revoked and the plane swatted instantly upon landing, because someone might have been on board (he wasn’t) whose only real crime was embarrassing the USA by exposing their fundamentally unconstitutional lawbreaking. Same goes with the prosecutors in Sweden; a phone call and the US got, not charges (a…

I might have bought the stuff about Austria, if it weren't for the tinfoil-hattery about Sweden. The authorities there were investigating Assange not because of any American phone calls, but because some of his Swedish sex partners reported him to the police.

But since that's your level of accuracy on Sweden, it's hard to see any reason to trust you on Austria either.

Re: European digital ID wallets rely on safety services of Google and Apple

#319
post #37

Earlier quoted context omitted.

> building a worse version of AWS just so that it is "European" makes no financial sense Unless it becomes necessary because of EU regulation?

Hopefully not. This hate towards good technology and innovation because you don’t like the current president is ridiculous. He’ll be gone in two years or so and then we’ll get back to normal.

Well, if the technology were even all that good, maybe. (Also, "innovation" just for "innovation's" sake is stupid. Lots of new shit is just that: shit.)

And no, him being gone in two years isn't all that much comfort. The problem is not just him, but the American people that elected him: The first time one could think it was a temporary aberration — 2016 was weird, what Brexit and all; maybe there was something in the water? Solar flares...? — but then they (you?) went and did it again in '24. It's not temporary any more.

Re: European digital ID wallets rely on safety services of Google and Apple

#320
post #317
post #273

Earlier quoted context omitted.

Nope. It is still not possible to give someone else (the government, or the bank) control over your phone while at the same time run software that you alone control with higher privileges. Please don't mix that up with "is practically hard to implement because of sloppy code. Also your attacker model is still "occasional evil government agency or evil private corporation wants to crack and read your messages", while…

I want governments and banks to allow open-source software, not control my phone. For example, I essentially trust the ROM I download from the GrapheneOS website. What I want is for governments, banks, or some independent open foundation to be able to approve that ROM too, so attestation can work with it. More like how CA certificates work: not perfect, but not locked to one vendor either.

So now you have the choice between two approved ROMs. Not a lot of improvement? And as soon as GrapheneOS implements something beneficial to the users that the government does not like, the approval will be taken back. That's also why GrapheneOS will probably not even think about doing that. So you want some OS functionality neither Google nor Graphene offer, you're, again, out of luck. CA is something completely different, and much more limited in what can be centrally controlled. Everybody can go to a CA, get a certificate for their domain, and use it with any server software, even with software they compiled themselves.
Post reply on HN