Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

371–380 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#371

Earlier quoted context omitted.

This is not a hypothetical problem and you don't need to be deliberately targeted. It actually happens to normal people. And if it does you have absolutely zero recourse. Source: I have a banned Google account (it's over 20 years old at this point). I know the password, but Google doesn't let me log into it. Every few years I try to unsuccessfully recover it. If you have a Google account and having it banned would be…

Can't you just create a new account?

You can, but you lose access to anything that was associated with your old account.

Another fun thing Google did is to automatically (without my consent) add a required second-factor authentication to my current Google account. I have this old, e-waste tier phone that I use mostly only as a glorified alarm clock, and at one point I used it to log into my current Google account.

Imagine my surprise when I tried to log in to my Google account from somewhere else, and it asked me for an authentication code from this phone. Again, I have never explicitly set it up as such - Google did this automatically! So if I were to lose this phone I'd be screwed yet again, with yet another inaccessible Google account that I will have no way of recovering.

At this point I don't depend on any Big Tech services; my Google account has nothing of value associated with it (only my YouTube subscription list, which is easy enough to backup and restore), and I pay for my own email on my own domain, etc. So if I get screwed over yet again by a big, soulless corporation that just sees me as a number on their bottom-line, well, I just won't care.

Re: German implementation of eIDAS will require an Apple/Google account to function

#372

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…

True, but its really hard to name a family of commercial devices with security features in hardware, including serious security features, which were not eventually hacked.

Worse still, for new mainstream devices that are believed to be safe the state sponsored actors will likely operate unpublished exploits, and will exploit the misplaced faith people and judiciary will put in device attestation. I dont think the very likeable people who worked on Pegasus found themselves respectable jobs - they are likely still selling that sophisticated crap to all authoritarian regimes.

Re: German implementation of eIDAS will require an Apple/Google account to function

#373

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

This is simply unacceptable. You are not making an innocent pragmatic compromise here, you are launching digital infrastructure which initially will tie everyone to Google/Apple and give alternatives a huge disadvantage for an unknown amount of time. Nobody knows when, or even if ever, support for open platforms will arrive. You should be ashamed of being involved in this monopoly handover to American big tech.

I bet £50 that the alternative (eg GrapheneOS attestation (based on the standard AOSP attestation)) will be delayed, then delayed, then scrapped since almost everyone is using Google Plag integrity anyway.

Yes, I assume malicious intent, sorry, seen this happen enough tines recently.

Re: German implementation of eIDAS will require an Apple/Google account to function

#374
post #91

Earlier quoted context omitted.

Simple, provide a simple API, let the community build the clients for the machines they have.

That's antithetical to the goal of a secure ID. It has to be really impossible to get stolen, or as difficult as a physical card. If the ID is just a password, you can tell other people your password, and it can be stolen, and it can be cloned. Germany is a strict liability country, and you will be fined or imprisoned for anything that is done with your identity card that was cloned because your PC was infected by ma…

> If the ID is just a password, you can tell other people your password, and it can be stolen, and it can be cloned.

You can give your physical cards to other people or give them access to your computers, too.

> Germany is a strict liability country, and you will be fined or imprisoned for anything that is done with your identity card that was cloned because your PC was infected by malware if you don't report it stolen.

I don't see an issue with this.

Re: German implementation of eIDAS will require an Apple/Google account to function

#375

Earlier quoted context omitted.

Do all German hospitals serve vegan food? If you were averse to carrots (without any health restrictions on eating them), would every government institution in Germany be required to serve you carrot-free food? If not, why should they be forced to accommodate every smartphone brand in existence, even if there's only 3 people in Germany using it? THe list has to end somewhere.

> Do all German hospitals serve vegan food? Can't speak for Germany, but they do in the UK. It would be illegal discrimination against a belief for them not to.

[flagged]

Re: German implementation of eIDAS will require an Apple/Google account to function

#377

Earlier quoted context omitted.

Users have the right to modify any app running on their own device. Software security should never depend on the user having no control over their own device. Smartphones are essentially just regular computers, and on them you can use a debugger and do whatever you want. Viewing smartphones as closed systems like game consoles where you need the manufacturer’s permission for everything only leads us into the dystopia…

Once SafetyNet was brought to Android a decade ago the tendency has been clear - these freedoms are going to be restricted heavily. Because how do you make sure it's the user who does those modifications, willingly and well-informed? That it's not a malicious actor, not an user getting socially engineered or phished? Incredibly difficult compared to the current alternative. If it's not a software root of trust that p…

You can maybe, trust the user to handle it's own certificate in their own devices? Though I admit requiring attestation is probably a good default.

Re: German implementation of eIDAS will require an Apple/Google account to function

#378
post #302

Earlier quoted context omitted.

You can just as well say "the correct reaction to having a guns aimed at your head is NOT to give the guy another gun ... you know, in case the first one fails to fire when he starts pulling triggers". Plus, the net difference is that this gives Google and Apple the ability to kill the ability of individuals to make payments (and tax them) ... do you want that? (And I would say, compared to having European banks tax…

Oh, but Google doesn't really excel in making phones "secure". Sure, their researchers are great, but Google itself claims that several years old phones running Oreo are safe and secure. They also extended the time for vendors to bring patches to the new vulnerabilities, they themselves slowed down - compare timeframe between patches released by GrapheneOS and patches released by Google - the latest GOS release provi…

Compared to EU governments' security for their citizens Google has absolutely perfect, world-class, bullet-proof, iron-clad ultimate security.

I do get that that's not exactly impressive. It isn't.

Re: German implementation of eIDAS will require an Apple/Google account to function

#379

Knowing the German, how much of a fiasco will this be? Many Germans despise having to go online with specific services due to "Datenschutz". Now you are telling them that they need an external (American) service in order to use this? What I don't understand is: ELSTER (taxes) already uses electronic signatures, don't these signature already fulfil the requirements of eIDAS? Why do we even need Google/Apple?

Germans are likely going to try and hang the public servants for high treason via their constitutional court.

Re: German implementation of eIDAS will require an Apple/Google account to function

#380
post #283

Earlier quoted context omitted.

Do we have stats how many germans use something else than Google Android, Samsung Knox or Apple? I recon it should be less than 1% which quite honestly is in fact „all“ citizens.

Sure, let's just arbitrarily exclude ~1million people because they're not running the government's preferred American spyware.

This is an unfair and a straw man argument, is it not? Are you also unhappy that in a democracy the 51% choose how the other 49% are going to be governed?

Why device attestation is required is quite well explained by this github comment [0]. I am in the industry and I agree fully with it, because it is a fact a problem for most smart phone users in terms of security.

0 - https://github.com/eu-digital-identity-wallet/eudi-app-andro...

Post reply on HN