Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

321–327 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#321

Earlier quoted context omitted.

Ideally they should have also told all German banks distribute or offer non-App based accounts or 2FA? But they did not. Also people are dependent on Play or App store. DB does not offer the app for direct download.

Well for banks there is competition (and largeest german consumer bank - Deutsche Bank/Postbank offers a non-smartphone based authentication device [0]). Not so much for government run railway. [0]: https://www.postbank.de/privatkunden/services/online-banking...

Many useful features like verified by visa or Google Pay or Apple pay is not available.

If you are that anal then using railway does not need app. You can use a mobile browser or desktop. I have seen people show QR code from their computer too. For D-Ticket one can buy from one of the local transport associations - with Chip Card (I am using that).

Re: European digital ID wallets rely on safety services of Google and Apple

#322
post #48

Earlier quoted context omitted.

Oh they sure do, because Google/Apple have to bend over backwards for the EU as they are not stupid enough to suddenly lose 500 million users.

Really? Google to this day refuses to do business in China, and Apple at this very moment excludes the EU from multiple new iOS 27 features that launch in the rest of the world. And with the current direction the EU is taking (e. g. even more regulation, more economic recession, even fewer competitive tech businesses), I wouldn’t bet on US companies getting "more favorable" towards the EU.

...and the iOS 27 features are not anything actually important, while China never was an established market for Google since 2009. Things have changed.

Re: European digital ID wallets rely on safety services of Google and Apple

#323
post #219
post #46

Earlier quoted context omitted.

The lawsuits, sadly, won't matter. "Security" (or, rather, totalitarian control!) is more important than the 1% of nerds who care enough to tinker with their phone.

People keep framing these sorts of debates in terms of tinkering . It's about ownership, not tinkering. It's about preventing megacorporations from having the last word about how government services can function and how people can interact with them.

But it's how the people outside of our circles see it. We tinker with our devices, which is not understandable to them - their phone just works, why would they change anything about it?

Re: European digital ID wallets rely on safety services of Google and Apple

#324
post #316
post #182

Earlier quoted context omitted.

You can't have both. "Hardware security" means the manufacturer decides which OS can run and you can't override it.

Practically speaking, I can set up real hardware-enforced boot integrity on my Framework laptop today, both on Arch with sbctl and on NixOS with Lanzaboote or Limine. There are still many unsolved problems in hardware security, so this is definitely not solved today. But I don’t see why it should be impossible. The EU could push the industry toward attestation models that respect user ownership instead of locking eve…

I think Meneth was basically correct but a bit imprecise: Boot integrity itself is only user respectful as long as the user can freely decide and change the integrity reference values, without consequences to the latter usefulness of their system. But attestation (based on boot integrity) as a principle directly contradicts "respect user ownership". This is not a question of technical feasibility, but of principle. Attestation is directed against users. The main purpose of attestation is to make sure that the local user can be forced to use a specific software (and not run other software at the same time that could influence this specific software) to access a certain remote service. Remote attestation means by definition "vendor lock", in that the vendor and their contractual partners lock and control the device's software. Therefore an attestation model that fully respects the user simply cannot exist.

Re: European digital ID wallets rely on safety services of Google and Apple

#325
post #323
post #219

Earlier quoted context omitted.

People keep framing these sorts of debates in terms of tinkering . It's about ownership, not tinkering. It's about preventing megacorporations from having the last word about how government services can function and how people can interact with them.

But it's how the people outside of our circles see it. We tinker with our devices, which is not understandable to them - their phone just works, why would they change anything about it?

People keep talking about it that way inside our circles, and if we do that here, we will surely fail to do better with a broader audience.

Last year's example of ICEBlock makes the freedom/tinkering distinction clear to most people. ICEBlock was an iOS-only app for tracking immigration raids in the USA and alerting users when they're nearby. Apple caved to government pressure and banned it. Because iOS users don't have the freedom to install apps from other sources, that's the last word; the app is effectively dead.

I've found most people understand pretty well why that sort of thing is a problem even if it did not affect them.

Re: European digital ID wallets rely on safety services of Google and Apple

#326

Earlier quoted context omitted.

Well for banks there is competition (and largeest german consumer bank - Deutsche Bank/Postbank offers a non-smartphone based authentication device [0]). Not so much for government run railway. [0]: https://www.postbank.de/privatkunden/services/online-banking...

Many useful features like verified by visa or Google Pay or Apple pay is not available. If you are that anal then using railway does not need app. You can use a mobile browser or desktop. I have seen people show QR code from their computer too. For D-Ticket one can buy from one of the local transport associations - with Chip Card (I am using that).

What purpose does Apple Pay / Google Pay serve other than paying from your smasrtphone? You can use Credit Card NFC payments if you want tap to pay and enter your pin. That workflow is not much more difficult than using a smartphone. And if you prefer using a smartphone - well, don't complain that you have to use a smartphone to pay.

Re: European digital ID wallets rely on safety services of Google and Apple

#327

Earlier quoted context omitted.

Many useful features like verified by visa or Google Pay or Apple pay is not available. If you are that anal then using railway does not need app. You can use a mobile browser or desktop. I have seen people show QR code from their computer too. For D-Ticket one can buy from one of the local transport associations - with Chip Card (I am using that).

What purpose does Apple Pay / Google Pay serve other than paying from your smasrtphone? You can use Credit Card NFC payments if you want tap to pay and enter your pin. That workflow is not much more difficult than using a smartphone. And if you prefer using a smartphone - well, don't complain that you have to use a smartphone to pay.

Isnt the aim to remove dependency on Google/Apple? EU should have forced Google and Apple to allow people to use NFC pay without having Google or Apple accounts.

If you talk about using NFC card. Yes, that is available.

Nothing is difficult. Even cash is possible.

Post reply on HN