Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

531–540 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#531
post #96

What if you „lose“ your google / apple account, like this sanctioned judge of the international criminal court? Crazy to imagine that we are still baking in dependency on US providers in european societies, even though there is clear indications we should be doing the opposite?

Then you can't take a Waymo any more.

Amusingly, the points on this posting have been going up and down quite a bit. Range is -1 to 2 so far.

The point here is that Waymo requires either an Android account or an Apple account to log into their phone app. Lose that and you cannot take a Waymo. This may be worth a formal complaint to the California Public Utilities Commission, because Waymo is regulated as a common carrier.

California civil code section 2170:

"A common carrier must, if able to do so, accept and carry whatever is offered to him, at a reasonable time and place, of a kind that he undertakes or is accustomed to carry. A common carrier must not give preference in time, price, or otherwise, to one person over another."[1]

This is the core of what it is to be a common carrier. An airline can't require that you join their frequent flyer plan to fly.

[1] https://codes.findlaw.com/ca/civil-code/civ-sect-2169/

Re: German implementation of eIDAS will require an Apple/Google account to function

#532
post #276

Earlier quoted context omitted.

No, what you're saying is nonsense. I can burn a key into efuses of this phone to make it only boot things signed by me and make the whole boot path verified, OS image immutable etc. and all of this can provide me some value, but it's absolutely not in my interest to let applications be picky on what can or can't happen in the OS (even if they would accept my key being there rather than Google's, which they won't). T…

I agree about the part where apps shouldn't be able to see whether the OS is trusted. But to remove that incentive you first need to stop punishing app companies for compromised user OSes from legal perspective. Are you willing to absolve Google, Apple and Deutsche Bank from responsibility of damage that happens on compromised user OSes?

The attested systems have vulnerabilities too, so how do they deal with that responsibility?

Re: German implementation of eIDAS will require an Apple/Google account to function

#533
post #466

Earlier quoted context omitted.

[flagged]

Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.

Save your keystrokes. I think I've seen that nickname express anti-consumer, pro-corporate, freedom-violating viewpoints in dozens of different threads on a pretty wide variety of topics at this point. Not once have I seen them take the pro-consumer stance.

Re: German implementation of eIDAS will require an Apple/Google account to function

#534

Earlier quoted context omitted.

We don't need 'full control' over an ID. We need the status quo, where we have mostly have control over our devices, and where paper IDs are still the foundation of society. Things are fine the way they are. There are problems, sure, but no problems that are made better by an all-encompassing surveillance state. If I am lashing out, it is because this is perhaps the most dangerous thing I've ever seen proposed, and i…

>To be honest, if I were German, I would probably just kill myself the day I was legally mandated by my government to register my identity with Google. That might sound hyperbolic, but I'm really not kidding. This is honestly not a good argument - it makes you sound desperate and puts in doubt your mental stability. I don't think you actually have mental problems, I just mean this this kind of argument comes off bad.…

> You don't have to own a digital ID.

For now. In 5 years you will, there is not one doubt in my mind about that. We've been on a slippery slope for (at least) 40 years straight, every year is a loss of privacy rights compared to the last, there is not a single year that reversed the trend, not a single year where we paused and stayed where we were. Once digital ID is implemented everywhere, alternatives will be quickly phased out. It's straight downhill as governments and corporations take more and more advantage of technology to build a degree of surveillance that even dystopian science fiction writers couldn't imagine.

The government, the corporations, the data brokers each individual corp sells your data to to compile a unified profile, and anyone the data brokers are willing to sell to have an unbelievable amount of information on the average citizen. They know where you live, where you are at all times, where you work, every website you visit, every Google search you've ever made, everything you purchase, all of your acquaintances, when and for how long you call those acquaintances, the full contents of any conversations you have with those acquaintances, your interests, your hobbies, your political beliefs.

I have thus far managed, I believe, to avoid the worst of the surveillance, with a tremendous amount of effort and the sacrifice of an unbelievable amount of personal convenience. But every year I find myself losing access to more and more things that I am unable to do without compromising my privacy. If it gets as far as government-mandated Google ID in my country, I think it's completely rational to kill oneself rather than live like cattle. If there were a resistance movement, I would participate in that instead, but this is happening completely voluntarily. You people want this. There is no resistance. Fine, you can have your dystopia. But there is no reason I need to be part of it, and I don't think it's a sign of mental illness to opt out. I don't much believe in living for the sake of living, you should live if it brings you happiness/satisfaction/whatever and don't if it doesn't.

Re: German implementation of eIDAS will require an Apple/Google account to function

#535

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Is this implementation related to the AusweissApp I've seen mentioned before (that reads the cert via NFC from a physical card) or another implementation?

Re: German implementation of eIDAS will require an Apple/Google account to function

#536
post #476

Earlier quoted context omitted.

How large is this preinfected phones problem? Is it large enough to sacrifice freedom?

We have had a large discovery of pre-installed malware every year for the past decade so far. Seems like a fairly big problem.

And how exactly did attestation help there?

Securing apps from the user does not secure the user from malware.

Re: German implementation of eIDAS will require an Apple/Google account to function

#537
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

because then it will never get done. There are still people using old Nokia phones, for those there will never be a solution. The usual 80/20 rule applies here as well. And if you really are a German citizen, you know how slow the wheels of government already turn in Germany, I assume next week you would be the one complaining that "Germany is so far behind" and that "other countries are so much faster at implementin…

We are not talking about old Nokia phones, but perfectly modern phones like those with GrapheneOS, that can be run on cutting-edge hardware, with a secure enclave, does not use Google Play Services by default, and has a high probability of being more secure than iPhone or any Android phone.

It is exactly the kind of alternative that European countries should embrace to become less dependent on US tech.

I am not sure if you are European, but why people are still supporting the GMS Android/iOS duopoly after the US revoked the Google accounts, Office 365 accounts, credit cards, Amazon accounts, etc. of ICC judges is beyond me. Supporting only iOS/Google GMS Android in a government app basically gives the US all the means to blackmail you and/or disrupt your digital infrastructure.

It seems there are still people working for European governments (including developers) who seem to have missed 2025 and the first few months 2026?

We are repeating the same mistakes as depending on Russian oil/gas again.

Re: German implementation of eIDAS will require an Apple/Google account to function

#538

Earlier quoted context omitted.

Attestation of what? It's none of your business how I secure and configure my phone. I use a smart card on my Librem 5 btw. See also: https://news.ycombinator.com/item?id=47647047

My business, no. Your government however, has a few reasons to want to ensure that the ID you're going to use to vote, to prove your identity to any service, etc, etc, does not get passed from device to device. Configure your phone however you want, then use your physical ID because your phone isn't supported. They're not taking it away. In the same way that you can file your taxes. Having an online filing service do…

I second the question, attestation of what? I have a Solo key that I use with webauthn for several services already. Is that not good enough and even if not, there surely are sufficient alternatives, least of all the actual electronic id on the national id card via nfc?

Re: German implementation of eIDAS will require an Apple/Google account to function

#539

Earlier quoted context omitted.

To become dystopia people must be forced to use locked down smartphones. In reality you buy the one that suits your needs and do not enforce your design decisions on the smartphones other people use.

Where is that free choice that you see "in reality"? This post is about the opposite of that getting put in place. The actual reality is that almost every service provider is converging on supporting a few extremely restrictive options. From every private service you can think of, to key government services. They all are saying "to interact with us, you must use one of these two types of devices, with all the attesta…

> They all are saying "to interact with us, you must use one of these two types of devices, with all the attestation and security measures intact"

Are you claiming that this is the only way of interacting with particular government services, with the other ways that existed before the app no longer being available? To make situation „dystopian“ this must be the case.

Re: German implementation of eIDAS will require an Apple/Google account to function

#540
post #480

Earlier quoted context omitted.

> An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. and therefore the app cannot give a reasonable guarantee that it is not running in an adversarial environment that actively tries to break the app's integrity. Thus, the app cannot be used as a verified ID with governmental level of trust.

All the more reason to not be requiring such things in the first place.

And that it is not required. Physical ID is still accepted
Post reply on HN