Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

431–440 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#431
post #388

Earlier quoted context omitted.

[flagged]

Vegetables, legumes, nuts, and grains are not expensive, and veganism is a protected class in the UK.

Yeah but when you're mad at a nation not force-feeding meat to vegans you have to come up with some reason why the vegans are bad.

Re: German implementation of eIDAS will require an Apple/Google account to function

#432

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

> We have to use some kind of attestation mechanism per the eIDAS implementing acts.

Translates to:

"We have to make sure citized accessing the public service have not control over the device per the eIDAS implementing acts"

Re: German implementation of eIDAS will require an Apple/Google account to function

#433
post #164

Earlier quoted context omitted.

I wonder if there will be a big enough market for a very compact smartphone equivalent device that can be used just for credentials? A device that is offline on standby except when you need it. Perhaps the size of a car key.

What if it was the size of a credit card and it had stuff like your name, date of birth and even a picture of your face. I want to name this invention an ID card…

And if you added a cryptographic layer to it, with your own private key baked into it, you could both sign the documents, confirm your identity and the government could confirm it's actually you....

....wow, that would be reinventing the existing model of the leading ID cards....

Crazy if you think about it :)

Re: German implementation of eIDAS will require an Apple/Google account to function

#434
post #325

Earlier quoted context omitted.

correction. in the real world all smartphones are either apple, android or none/other. in terms of legals, you really do have to cater to all three, which is why we don't have one world government.

This is about a digital wallet, so people who don't have a smartphone are out of scope. Now, "other" than Apple/Android is so small as to be negligible and governments also have a duty not to waste taxpayers' money, which means not spending hundreds of thousands to cater for an ultra small number of people who have an easy access to an alternative. To have government apps work only on iOS and Android is perfectly rea…

Why should I have to have a smartphone to have a digital wallet? Smart watches, tablets, laptops, portable game consoles, etc, are all perfectly cromulent hardware for running a digital wallet.

Re: German implementation of eIDAS will require an Apple/Google account to function

#435

Earlier quoted context omitted.

Can't you just make a new google account then?

That's crazy. Imagine cheering for the company that will block the criminal prosecutors investigating war crimes and genocide from having the ID at all (1) once the supporter of the investigated sanctions the law-abiding persons: https://www.whitehouse.gov/presidential-actions/2025/02/impo... But anyway - why the requirement in the first place? (1) because sanctioned person must not be allowed to create another accou…

It's puzzling how such sanctions are enforceable in the first place. If the person published their phone number then maybe, but if not then little can be done to identify them.

Re: German implementation of eIDAS will require an Apple/Google account to function

#436

Earlier quoted context omitted.

This is an unfair and a straw man argument, is it not? Are you also unhappy that in a democracy the 51% choose how the other 49% are going to be governed? Why device attestation is required is quite well explained by this github comment [0]. I am in the industry and I agree fully with it, because it is a fact a problem for most smart phone users in terms of security. 0 - https://github.com/eu-digital-identity-wallet/…

I think your analogy is flawed. I can be part of the losing 49% and still be entitled to receive the same services as the 51%, whereas people who chose a privacy-oriented OS are essentially going to be excluded from essential governmental services. That's a whole different kind of thing. I'm not going to replace my 1200 EUR smartphone with a device that forces me to have an account with Apple or Google. I've been iss…

> privacy-oriented OS

Well, in all seriousness what examples could you give me here in terms of device hardware attestation? Even GrapheneOS does use Google root certificates to attest your device. There is indeed an option for EUDI to keep a list of keys and I bet this is probably the way they are going to go for Android in the future. We shouldn't forget this is still in the planing phase.

> to have an account with Apple or Google.

True for Google, not true for Apple. Device attestation on iOS does not require you to have an iCloud account or sign into some Apple services. It works entirely using device hardware ids.

> I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need.

Nope. This is eID and verifies your identity, it does not attest the security of your hardware. These are two different problems we talk about here.

Re: German implementation of eIDAS will require an Apple/Google account to function

#437

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

> An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. and therefore the app cannot give a reasonable guarantee that it is not running in an adversarial environment that actively tries to break the app's integrity. Thus, the app cannot be used as a verified ID with governmental level of trust.

There's a difference between needing to lock down the whole OS and just the secure element. The secure hardware component can sign a challenge and prove possession of a private key without you being able to extract it. Smartcards have done this for decades (most people here will know an implementation under the name Yubikey).

Conveying authentic information across untrusted channels (your phone screen, say) has been a solved problem since asymmetric cryptography was invented back before I was born

Re: German implementation of eIDAS will require an Apple/Google account to function

#438
post #348

Earlier quoted context omitted.

There is mothing to be gained politically by doing this. You think you look good if you say “hey, the Poles had this really good idea, how about we do the same”? Plus, the process is something like: - we want to do $something - hire consultants to help us define $something and produce a document - hire other consultants to write the specs for the project - launch an RFP - select a winner - wait for the implementation…

> You think you look good if you say “hey, the Poles had this really good idea, how about we do the same”? Yes. > You think if there was any will wouldn’t the whole EU use whatever the Estonians are doing very well? Using the Estonian system would be vastly preferable. If politics doesn’t allow that, the political environment is broken.

How is the Estonian system now? I remember when I visited around 2010 our host just had a quite simple smart card reader and could just use it to sign in to government services with their ID and as far as I remember even sign mails and documents. Germany of course could not use normal smart cards but had to use NFC cards with special readers and made the signing feature and additional service you had to pay for on a yearly basis. Of course the Germans system did not went anywhere for years. I do have a reader now and can use it for some governmental services and have very limited appetite to bind the ID to my phone.

Re: German implementation of eIDAS will require an Apple/Google account to function

#439
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Do all German hospitals serve vegan food? If you were averse to carrots (without any health restrictions on eating them), would every government institution in Germany be required to serve you carrot-free food? If not, why should they be forced to accommodate every smartphone brand in existence, even if there's only 3 people in Germany using it? THe list has to end somewhere.

While the example your provide is reasonable fair, the comparison is not.

For it to be fair comparison, the carrots would have to be grown by a foreign company, known for using unsafe growing practices, causing contamination. Eg, poison carrots. This same company would have to be under the control of a very hostile, very actively aggressive and threatening nation.

Such as one currently threatening to annex allies, among other things.

With the US literally tapping and spying on heads of foreign states:

https://en.wikipedia.org/wiki/German_Parliamentary_Committee...

and there being lots of ways to spy, such as push notifications:

https://www.reuters.com/technology/cybersecurity/governments...

Only insane people would objectively decide to use Google or Apple anything for any form of ID. Those platforms should literally be outlawed. Any use of push notifications or identity attention should be looked at as utter fantasy.

Here's a secret for you. There really isn't any urgent requirement to have an electronic identification method. It can wait. Supporting legislation can be passed first. There are lots of ways to do so.

For example, the entire EU could pass legislation stating that all cell phones have open source code available, including all binary blobs for drivers. And that all phones are unlockable, and that (for example) the phone has a version of the rom you can download without any Google services.

(If Apple isn't able to compete here, well... too bad)

The phones would not be legal to sell, unless the open source firmware was compiled in front of regulators. The point of this is another pet-peeve of mine, it would allow people to support their own phones, for that source code would be released the day that phone was no longer supported.

And yes, it's trivial to have open source firmware blobs. There just isn't a market for it. Pass a law, and sellers of SoC and other ICs will capitulate, or maybe more punitive laws will be passed against them. As someone once said, yes companies can have a lot of sway.

But governments have police, courts, and armies.

Right now, Android and Apple devices are a literal arm of the US government's spying apparatus, even if those two companies actively work against it.

Do not trust Google Play. Do not trust Firebase. Do not trust Google. At all.

Are Germans just too trusting? I remember 15 years ago, when nuclear power plants were closing, concerns were raised about the reliance on Russian natural gas. These were waved away. Russia? What's wrong with Russia! They're almost allies, they're capitalists now!

Don't do this again.

Do NOT trust Google. Don't. Don't make it a core part of any identity management.

Imagine, needing an active Google account to even bank! Or to file your taxes, or even to prove who you are!? Google cancels accounts with no recourse, no reason why, won't help anyone, and this is to be the core of identity management for Germany?

The average person won't even be able to install any German Government designed apps, unless they are on the Play store! Are you going to teach Grandma how to use ADB to install an app? Without an active Google Account, will you even be able to use push notifications?

Why would a government even allow ID to be blocked by the requirement that a company with terrible, horrible, inane customer service, which just kills accounts without recourse, be a gatekeeper?

No Google account, no ID! Wha!?

It's literally not sane.

Re: German implementation of eIDAS will require an Apple/Google account to function

#440
post #30

I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.

What percentage of people have a phone that is not apple or google?

Are you saying there's a threshold percentage somewhere below which you're happy to

A: exclude these people from society or force them to switch to big tech, and

B: accept the consequence where a single other country holds access to everyone's identity information for convenience reasons (because it works for the 99% that are too tech-illiterate to install software that they control instead of the other way around)

Post reply on HN