Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

411–420 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#411

Earlier quoted context omitted.

What if I don’t have a smartphone?

You're screwed. This has been the way for a while now. You cannot exist in society without a smart phone and it's only going to get worse.

...without a smartphone that is surveilling you 24/7.

Private smartphones are excluded already.

Re: German implementation of eIDAS will require an Apple/Google account to function

#412

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

> An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system.

and therefore the app cannot give a reasonable guarantee that it is not running in an adversarial environment that actively tries to break the app's integrity. Thus, the app cannot be used as a verified ID with governmental level of trust.

Re: German implementation of eIDAS will require an Apple/Google account to function

#413
The solution is simple : https://www.europarl.europa.eu/petitions/en/artcl/I+want+to+...

Because you'll be stonewalled by devs because they can't really changer decisions made bu higher ups.

Edit: I'd sign it, but don't want manage and diffuse it.

Re: German implementation of eIDAS will require an Apple/Google account to function

#414
post #306

Earlier quoted context omitted.

So what can be used as an attestation API? WHAT will make sure that when a phone says "you're paying 10 euro to $coffee_place" that it isn't a bitmap being shown over "you're paying 10.000 euro to $scammer", above the pay button. Note: needs to be a real guarantee that isn't a permission question away from going away. Either governments can develop (and pay for) THAT technology, or they can use Apple/Google ...

I'm not sure I want my government to develop that technology. Government software is usually low-quality, expensive procurement crap, often riddled with security holes, and an exercise in checkbox checking. UX and user friction can't be expressed as a verifiable clause in a procurement contract, so they're ignored. Besides, every time EU governments tried to force smartphone manufacturers to pre-install government ap…

It's not that difficult, just `git pull lineage`.

Re: German implementation of eIDAS will require an Apple/Google account to function

#415

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

> An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. and therefore the app cannot give a reasonable guarantee that it is not running in an adversarial environment that actively tries to break the app's integrity. Thus, the app cannot be used as a verified ID with governmental level of trust.

If your app needs to be protected from harm, it cannot protect the user from said harm. I hoped software engineering culture was lucky to not have the same precepts that make lockpicking a crime in the real world, that we successfully make it into common knowledge that you can't grant any trust to the client, but it seems "trusted computing" is making some of us unlearn that lesson.

Re: German implementation of eIDAS will require an Apple/Google account to function

#416

Earlier quoted context omitted.

I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…

Users have the right to modify any app running on their own device. Software security should never depend on the user having no control over their own device. Smartphones are essentially just regular computers, and on them you can use a debugger and do whatever you want. Viewing smartphones as closed systems like game consoles where you need the manufacturer’s permission for everything only leads us into the dystopia…

To become dystopia people must be forced to use locked down smartphones. In reality you buy the one that suits your needs and do not enforce your design decisions on the smartphones other people use.

Re: German implementation of eIDAS will require an Apple/Google account to function

#417

Earlier quoted context omitted.

I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…

Comparing being able to run the hardware and software of your choice to "wanting a passport in a different color or whatever" is so completely fucked, and it's beyond insane as a justification for giving two American tech companies with a well established track record for doing evil control over your citizens' ID. The world has gone absolutely mad, what the fuck am I even witnessing? It is quite literally becoming 19…

> with a well established track record for doing evil control

Can you please elaborate on that record?

Re: German implementation of eIDAS will require an Apple/Google account to function

#418

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

What happens if someone is banned from both companies (even for a very legitimate reason such as hosting illegal content -- they still need to access government services)?

Re: German implementation of eIDAS will require an Apple/Google account to function

#419

Earlier quoted context omitted.

Comparing being able to run the hardware and software of your choice to "wanting a passport in a different color or whatever" is so completely fucked, and it's beyond insane as a justification for giving two American tech companies with a well established track record for doing evil control over your citizens' ID. The world has gone absolutely mad, what the fuck am I even witnessing? It is quite literally becoming 19…

> with a well established track record for doing evil control Can you please elaborate on that record?

The clauses are [with a well established track record for doing evil] [control over your citizens' ID], if that's not clear. I wonder from where your quote cut off if my sentence was misunderstood.

As to the well-established track record of doing evil... gestures broadly everything? Google in particular has built an empire on stripping away people's privacy, and they regularly ruin people's livelihood by eg. shutting down Youtube accounts incorrectly with automated systems and no way of ever reaching a human for support unless you're famous enough to make it a PR issue. Apple is the same, just recently with a thread on HN lamenting that Apple was destroying their business because they revoked their dev license, or in other words, a private company unilaterally revoked the ability of a business to create mobile software for billions of devices. And now we want to give them control over our IDs? ????????????????????????

Re: German implementation of eIDAS will require an Apple/Google account to function

#420
post #325

Earlier quoted context omitted.

correction. in the real world all smartphones are either apple, android or none/other. in terms of legals, you really do have to cater to all three, which is why we don't have one world government.

This is about a digital wallet, so people who don't have a smartphone are out of scope. Now, "other" than Apple/Android is so small as to be negligible and governments also have a duty not to waste taxpayers' money, which means not spending hundreds of thousands to cater for an ultra small number of people who have an easy access to an alternative. To have government apps work only on iOS and Android is perfectly rea…

> To have government apps work only on iOS and Android is perfectly reasonable in the current state of the world where this covers 99% of smartphones.

the fundamental flaw with that approach is that it is totally unreasonable to have government apps in anything other than open source and fully public systems. nothing else can really be trusted, and any private/closed source option should be disqualified from the get go.

the reason is simple: you can't trust private entities or opaque systems, and you can't trust government either, thus the solution has to be fully transparent or you're doing nothing.

the problem with that is that it is hard, expensive and/or inconvenient.

Post reply on HN