Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

521–530 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#521
post #488

Earlier quoted context omitted.

We don't need 'full control' over an ID. We need the status quo, where we have mostly have control over our devices, and where paper IDs are still the foundation of society. Things are fine the way they are. There are problems, sure, but no problems that are made better by an all-encompassing surveillance state. If I am lashing out, it is because this is perhaps the most dangerous thing I've ever seen proposed, and i…

How do you use your paper ID to to prove identity or age or citizenship to someone hundreds of kilometers away whom you are conducting an online transaction with?

It's not that important to be able to do that. You have been educated to trade your freedom for that kind of convenience, but it is not necessary.

Proof: things mostly work now without all the surveillance state shenanigans.

More proof: humans have lived full and fulfilling lives without "proving identity or age or citizenship to someone hundreds of kilometers away"

Re: German implementation of eIDAS will require an Apple/Google account to function

#522

This is about mass surveillance and control. https://en.wikipedia.org/wiki/Edward_Snowden#Revelations The existence of eIDAS itself is already a big problem. They're going to try to gradually push laws to make it so that you'll need a government issued signature to do anything . That's when they'll have total power over you because they can simply refuse to issue. Modern computing and communications technologies can…

> They're going to try to gradually push laws to make it so that you'll need a government issued signature to do anything. That's when they'll have total power over you because they can simply refuse to issue. The more this signature is necessary the harder it becomes to deny issueing it to somebody. I don't see how this changes much compared to nowadays. You can already require an ID for all kinds of these and the g…

It will matter a lot in the long run. I will outline one concrete way it will matter, which I think is the most critical, but there are other ways it will do damage besides this:

Right now, physical ID is only required for government services, for the most part. But digital signatures can be extended later to gate all services and purchases, both online and physical, including non-government ones. For example, you can't host a website without a gov approved signature for each website.

Under a system like that, you would rarely find out when the gov refuses to issue a signature, or when any kind of injustice happens, really. Websites where people can talk about bad things happening to them will simply be denied a signature to legally operate, so they're given the ultimatum to "voluntarily" censor posts, or be shut down. It becomes impossible to have this very conversation on a public platform with any kind of meaningful reach. And they already have this kind of system in China, since you brought it up. In fact, they have domestic surveillance systems that make the Snowden disclosures look cute.

Re: German implementation of eIDAS will require an Apple/Google account to function

#523

Earlier quoted context omitted.

A lot of other freedoms are being abused and always have been, but somehow we don't go and ban kitchen knives, as having them around is valuable. This is a false dichotomy. Systems can be secure and trusted by the user without having to cede control, and some risks are just not worth eliminating. Most importantly - it's the user who needs to know whether their system has been tampered with, not apps.

> but somehow we don't go and ban kitchen knives, as having them around is valuable Some countries do :) Though I think physical analogies are misleading in a lot of ways here. > Systems can be secure and trusted by the user without having to cede control, and some risks are just not worth eliminating. Secure, yes, trustworthy to a random developer looking at your device, no. They're entirely separate concepts. > Mos…

I never mentioned users having to know things (what you quoted was about the user getting informed whether their system is compromised, which is the job of a secure boot chain). The user being in control means that the user can decide who to trust. The user may end up choosing Google, Apple, Microsoft etc. and it's fine as long as they have a choice. Most users won't even be bothered to choose and that's fine too, but with remote attestation, it's not the user who decides even if they want to. And we don't need random developers looking at our devices to consider them trustworthy, it's none of their business and it's a big mistake to let them.

Re: German implementation of eIDAS will require an Apple/Google account to function

#524
post #476

Earlier quoted context omitted.

> The ability for us as users to lie to the apps is actually essential to preserving our agency. Without that we're screwed, as now to connect ourselves to the fabric of the society we'll need to find and exploit vulnerabilities that are going to be patched as soon as they become public. The same freedom is being abused by malicious actors. Even on Windows (like BlackLotus), but also on pre-infected phones emptying p…

How large is this preinfected phones problem? Is it large enough to sacrifice freedom?

We have had a large discovery of pre-installed malware every year for the past decade so far. Seems like a fairly big problem.

Re: German implementation of eIDAS will require an Apple/Google account to function

#525

Earlier quoted context omitted.

So please tell us what the difference is.

With surveillance a person gets surveilled with telemetry a person doesn't. Telemetry is collecting information about the operation of the device. The goal of telemetry is to understand how the device is operating where with surveillance it is about seeing what a person is doing.

Do you imply that it's not possible for the US intelligence agencies to request this data from google per person of interest and deliver some information from the metadata?

I heavily doubt that.

Re: German implementation of eIDAS will require an Apple/Google account to function

#526
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

also German here, we have to get rid of the 100% perfection at launch expectation its crippling this country

This is not about 100% perfection at launch, this is about civil equality. Launching without broad support for use cases creates a two-tier society.

Re: German implementation of eIDAS will require an Apple/Google account to function

#527
post #477

Earlier quoted context omitted.

> somehow we don't go and ban kitchen knives False analogy. You can’t have your kitchen knife exploited by a hacker team in North Korea, who shotgun attacks half of the public Internet infrastructure and uses the proceeds to fund the national nuclear program, can you? (I somewhat exaggerate, but you get the idea.) > Systems can be secure and trusted by the user without having to cede control In an ideal world where u…

> You can’t have your kitchen knife exploited by a hacker team in North Korea, who shotgun attacks half of the public Internet infrastructure and uses the proceeds to fund the national nuclear program, can you? (I somewhat exaggerate, but you get the idea.) Isn’t the status quo, that you need to intentionally choose to allow this?

Yes (well, kinda - attested systems can be and are vulnerable too), and remote attestation is completely orthogonal to that threat anyway. Securing the boot chain does not involve letting apps verify the environment they run in, it's an extra (anti-)feature that's built on top of secure boot chains.

It's also really incredible how people can see "user being in control" and just immediately jump to "user having to be an infosec expert", as if one implied the other. You can't really discuss things in good faith in such climate :(

Re: German implementation of eIDAS will require an Apple/Google account to function

#528
post #521
post #488

Earlier quoted context omitted.

How do you use your paper ID to to prove identity or age or citizenship to someone hundreds of kilometers away whom you are conducting an online transaction with?

It's not that important to be able to do that. You have been educated to trade your freedom for that kind of convenience, but it is not necessary. Proof: things mostly work now without all the surveillance state shenanigans. More proof: humans have lived full and fulfilling lives without "proving identity or age or citizenship to someone hundreds of kilometers away"

> It's not that important to be able to do that. You have been educated to trade your freedom for that kind of convenience, but it is not necessary.

It's important enough that people do so without any eID, using methods both more invasive and less reliable. Gas bills, document photos, having to take videos and pictures of yourself.

Humans have lived in caves and died of preventable diseases, it doesn't mean it's a better way of living.

Re: German implementation of eIDAS will require an Apple/Google account to function

#529

Earlier quoted context omitted.

And what attestation services does your web app use? Do we lock that web app behind having Secure boot enabled, along with a Java applet for the fun of it? If your answer is "none", you missed the point.

Attestation of what? It's none of your business how I secure and configure my phone. I use a smart card on my Librem 5 btw. See also: https://news.ycombinator.com/item?id=47647047

My business, no. Your government however, has a few reasons to want to ensure that the ID you're going to use to vote, to prove your identity to any service, etc, etc, does not get passed from device to device.

Configure your phone however you want, then use your physical ID because your phone isn't supported. They're not taking it away. In the same way that you can file your taxes. Having an online filing service doesn't mean you're being "excluded" because your i386 running BeOS isn't part of the supported hardware. Send a letter. It'll still work.

Re: German implementation of eIDAS will require an Apple/Google account to function

#530

Earlier quoted context omitted.

You have the totally wrong expectations here. Some service that requires citizens to buy and bring their own devices in order to use a service will by definition always be exclusive. Whining about lacking compatibility with some niche sbowflake devices is just inappropriate in this context. The only solutiin is to require an actually convenient fallback for those otherwise excluded from that service. The limited sele…

Your disdain isn't helpinh you here either as you're just as wrong as parent. Such public utilities ought to always prioritize privacy, platform-independence, and empowering market competion long- and short-term. And to achieve that you need to start at the design level. In this case, clearly, you either have to avoid relying on app attestation or lay the foundation for an unrestricted number of independent chain of…

You have the right starting point, but the wrong conclusion. Government services need to be inclusive of everybody. But you simply cannot build technical solutions that put technical requirements on devices owned by the users in a way that the service is sufficiently inclusive. That is just a fact.

If you want to be critical of the outcome on compatibility grounds, forcing a grind to increase technical compatibility is the wrong thing to ask for. That must necessarily always leave some people behind. The only honest alternative positions on that front are (a) the government issues the tech to everybody itself or (b) the government doesn't build advanced systems at all.

The German government offices rely on a lot of quaint-looking paper based processes, but they have one thing going for them: working through them can be done with pen and paper - tools that are available for cheap and broadly compatible. It's probably not such a bad thing after all?

Post reply on HN