Live data from Hacker News

European digital ID wallets rely on safety services of Google and Apple

waag.org

41–50 of 327 posts

Re: European digital ID wallets rely on safety services of Google and Apple

#42

Earlier quoted context omitted.

Aren't monopolies is what we end up by default if have no regulation at all? And yes, not every regulation destroys monopoly, but regulation is the only thing that could break one.

> Aren't monopolies is what we end up by default if have no regulation at all? No. Monopolies are only inevitable if the goods aren't elastic, if there is a large cost of entry into the market, or if its a market you can create a moat that is unsurmountable. Many markets don't have that even with 0 regulation, but might have second order problems like firms creating unsafe products for example. But in general regulat…

There is always imperfect information, there is no such thing as a perfect market and as a result regulation will always be needed to curb the excesses such as monopoly. Even if we had perfect information, humans remain irrational. This is a simple fact of life and the universe.

Re: European digital ID wallets rely on safety services of Google and Apple

#44
post #4

A European digital ID system that is entirely dependent on 2 US companies. Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

Not really. EU is actually trying to decouple. But in many cases there are not any homegrown alternatives to support. There is not a single company in EU that could replace, even a considerable part, of software stack provided by Google and Apple. And, unless the regulatory environment changes., there probably never will be.

> But in many cases there are not any homegrown alternatives to support

There shouldn't need to be. Realistically for something like this an EU backed highly-audited non-profit should be in place for permanent highly controlled services like this that do not rely on any non-EU entities for it to function.

Re: European digital ID wallets rely on safety services of Google and Apple

#45

Huh. This article lumps Apple in with Google when its only qualms seem to be with Google's terrible behavior. The entire article is about Google Play.

Yeah, what alternative is there for iOS except the framework that Apple supplies?

Re: European digital ID wallets rely on safety services of Google and Apple

#46
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

The lawsuits, sadly, won't matter. "Security" (or, rather, totalitarian control!) is more important than the 1% of nerds who care enough to tinker with their phone.

Re: European digital ID wallets rely on safety services of Google and Apple

#47
Here in Germany we had court rulings saying the german railway (DB) must offer offline tickets that do not require a computer or smartphone to purchase to not discriminate against the elderly. I am pretty sure we will see similar rulings for EUDI wallet requiring Google/Apple.

Re: European digital ID wallets rely on safety services of Google and Apple

#48

Working as intended. EU wants you to use a device and OS they can fully control. Don't comply with some new ridiculous regulation? Your app will be banned. > EU App Store: Apple Removes Thousands of Apps Due to Digital Services Act Requirements > Apple’s app removals follow the Digital Services Act, a European law requiring all app traders to display verified contact details, including address, email, and phone numbe…

The only problem is, EU does not control these devices, Google and Apple and by extension the US government does.

Oh they sure do, because Google/Apple have to bend over backwards for the EU as they are not stupid enough to suddenly lose 500 million users.

Re: European digital ID wallets rely on safety services of Google and Apple

#49

EU should have mandated a user-facing authentication scheme using a random string as the only authentication factor for everything. Pretty much like the API tokens for contemporary enterprise software, except that they would be used by ordinary people and not by application developers. And complement it with hardware tokens for highly sensitive applications. Passkeys could have been that, but they were quickly subver…

But this does not allow tracking nor marketing, so why would they do that?

Re: European digital ID wallets rely on safety services of Google and Apple

#50
post #36

The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…

Honestly, as long as the architectures is fatally flawed (Even if convenient) it's just bandaids over a larger issue.

These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks.

Germany was going in the right direction imho, they NFC enabled their ID cards (Sweden has info on them but no enablement procedures) that is then paired with the app, so the card acts as a 2nd factor that makes the app itself less of a security issue since a user will be required to physically enable it (sadly the NFC pairings are kinda fiddly.. but I'd take that as a security option for all non-trivial transfers).

Post reply on HN