Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

461–470 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#461

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

> An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. and therefore the app cannot give a reasonable guarantee that it is not running in an adversarial environment that actively tries to break the app's integrity. Thus, the app cannot be used as a verified ID with governmental level of trust.

> governmental level of trust

For most governments that is a very low bar.

Re: German implementation of eIDAS will require an Apple/Google account to function

#462

Earlier quoted context omitted.

Users have the right to modify any app running on their own device. Software security should never depend on the user having no control over their own device. Smartphones are essentially just regular computers, and on them you can use a debugger and do whatever you want. Viewing smartphones as closed systems like game consoles where you need the manufacturer’s permission for everything only leads us into the dystopia…

To become dystopia people must be forced to use locked down smartphones. In reality you buy the one that suits your needs and do not enforce your design decisions on the smartphones other people use.

Where is that free choice that you see "in reality"? This post is about the opposite of that getting put in place. The actual reality is that almost every service provider is converging on supporting a few extremely restrictive options. From every private service you can think of, to key government services. They all are saying "to interact with us, you must use one of these two types of devices, with all the attestation and security measures intact". It's impossible for people to make their own design decisions or choose for themselves, because other options do not have the corporate/government blessing.

It's ridiculous that you look at all of us being forced into a government-protected duopoly, and then say "Don't you dare force your decisions on us!" to anyone suggesting that this should not be the default. Rules for us, but not them.

Re: German implementation of eIDAS will require an Apple/Google account to function

#463

Earlier quoted context omitted.

This is not a hypothetical problem and you don't need to be deliberately targeted. It actually happens to normal people. And if it does you have absolutely zero recourse. Source: I have a banned Google account (it's over 20 years old at this point). I know the password, but Google doesn't let me log into it. Every few years I try to unsuccessfully recover it. If you have a Google account and having it banned would be…

Can't you just create a new account?

You better hope that whatever is-this-the-same-user heuristics they have on their side never find out for the duration of your entire life.

Re: German implementation of eIDAS will require an Apple/Google account to function

#464

Earlier quoted context omitted.

[flagged]

So please tell us what the difference is.

With surveillance a person gets surveilled with telemetry a person doesn't. Telemetry is collecting information about the operation of the device. The goal of telemetry is to understand how the device is operating where with surveillance it is about seeing what a person is doing.

Re: German implementation of eIDAS will require an Apple/Google account to function

#465

Earlier quoted context omitted.

Thank you for chiming in. > We have to use some kind of attestation mechanism per the eIDAS implementing acts. What does this attestation need to prove? Is this only about ensuring that private keys are managed by a secure enclave or a TPM? > we have support for other OSs on our list (like, e.g., GrapheneOS) I appreciate that, even though I am really not enthusiastic of eIDAS. But time will tell. Thank you.

They won't implement alternatives later, they'll be no point if "most of out customers is using either of the major providers". Concerning secure enclave - what other device except iphones and Pixels have it actually safe?

> They won't implement alternatives later, they'll be no point if "most of out customers is using either of the major providers".

It's hard for me to assess the effort needed here, but I guess that the GrapheneOS implementation will be 99% like the regular Android implementation. Supporting both systems does not seem to be that unrealistic.

Re: German implementation of eIDAS will require an Apple/Google account to function

#466

Earlier quoted context omitted.

And force them into the Google surveillance, https://news.ycombinator.com/item?id=26639261

[flagged]

Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.

Re: German implementation of eIDAS will require an Apple/Google account to function

#467
post #214

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Because you can’t please all of the people. And before someone likens it to the ADA. Even with accommodations you have to make, car makers aren’t for instance required to make cars that blind people can drive.

You chose to use a non mainstream platform. Thats on you.

Re: German implementation of eIDAS will require an Apple/Google account to function

#468

Earlier quoted context omitted.

I think your analogy is flawed. I can be part of the losing 49% and still be entitled to receive the same services as the 51%, whereas people who chose a privacy-oriented OS are essentially going to be excluded from essential governmental services. That's a whole different kind of thing. I'm not going to replace my 1200 EUR smartphone with a device that forces me to have an account with Apple or Google. I've been iss…

> privacy-oriented OS Well, in all seriousness what examples could you give me here in terms of device hardware attestation? Even GrapheneOS does use Google root certificates to attest your device. There is indeed an option for EUDI to keep a list of keys and I bet this is probably the way they are going to go for Android in the future. We shouldn't forget this is still in the planing phase. > to have an account with…

> Nope. This is eID and verifies your identity, it does not attest the security of your hardware.

The reader and its firmware is already certified by the federal IT security agency BSI for use with eID and banking. Why shouldn’t I be allowed to use that for whatever digital identity wallet thing the EU is cooking up?

Re: German implementation of eIDAS will require an Apple/Google account to function

#469

Earlier quoted context omitted.

But things not in the launch can easily be deprioritized as budget issues indefinitely. “Oh why spend the money adding support for just a few people??” will be the line moving forward.

It would be cheaper to just buy all of the outliers a bottom of the barrel Android phone for them to use with the tax money.

Yes just like it’s cheaper to just provide people who can’t afford a phone in the US a phone by taxing other cell phone users - and I don’t have a problem with that.

Re: German implementation of eIDAS will require an Apple/Google account to function

#470

Earlier quoted context omitted.

[flagged]

Would you say the same if they refused to serve kosher/halal meals for Muslim/Jewish patients? UK law protects some philosophical beliefs equally to religions. (what qualifies is a bit of a mess as it's all case law) (On a practical note, I imagine it's easier for hospitals to just serve vegan food for anyone who is vegetarian/Muslim/Jewish rather than have specific kosher/halal meals)

Actual yes since I think all religions are illogical…
Post reply on HN