German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
German implementation of eIDAS will require an Apple/Google account to function
541–550 of 674 posts
Re: German implementation of eIDAS will require an Apple/Google account to function
#542Earlier quoted context omitted.
[flagged]
Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.
Re: German implementation of eIDAS will require an Apple/Google account to function
#543Earlier quoted context omitted.
With surveillance a person gets surveilled with telemetry a person doesn't. Telemetry is collecting information about the operation of the device. The goal of telemetry is to understand how the device is operating where with surveillance it is about seeing what a person is doing.
What does it matter in practice? Do you seriously think Google, the targeted advertisement company, does not use that Telemetry for targeted advertisements?
Re: German implementation of eIDAS will require an Apple/Google account to function
#544Earlier quoted context omitted.
Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.
Save your keystrokes. I think I've seen that nickname express anti-consumer, pro-corporate, freedom-violating viewpoints in dozens of different threads on a pretty wide variety of topics at this point. Not once have I seen them take the pro-consumer stance.
Re: German implementation of eIDAS will require an Apple/Google account to function
#545Earlier quoted context omitted.
> An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. and therefore the app cannot give a reasonable guarantee that it is not running in an adversarial environment that actively tries to break the app's integrity. Thus, the app cannot be used as a verified ID with governmental level of trust.
> an adversarial environment that actively tries to break the app's integrity Can you elaborate on what this means? Who is the adversary? What kind of 'integrity'? This sounds like the kind of vague language DRM uses to try to obscure the fact that it sees the users as the enemy. An XBox is 'compromised' when it obeys its owner, not Microsoft.
Re: German implementation of eIDAS will require an Apple/Google account to function
#546Earlier quoted context omitted.
Yes all that you wrote is true. But that does not magically change anything to what I previously stated: in the real world all smartphones are either Apple or Android... I don't know what the eIDAS 2.0 requires in term of security but it may make the choice the implementers made here unavoidable in practice, as hinted by @webhamster. If so, it seems that a solution, if technically possible, might be to mandate that O…
> in the real world all smartphones are either Apple or Android... So you're claiming that Mobian doesn't exist? PureOS doesn't exist? PostmarketOS doesn't exist? Ubuntu Touch doesn't exist? SailfishOS doesn't exist?
This discussion feels unreal, really.
Re: German implementation of eIDAS will require an Apple/Google account to function
#547Earlier quoted context omitted.
European Citizen here, and indeed lots of people in IT turn a blind eye onto the collateral damage their work may create. I know someone who happily codes "verifiable credentials" in Elixir, disregarding all externalities.
What's wrong with verifiable credentials? It's an important thing to have it seems? Your passport or a bank card are verifiable credentials, or at least are designed to be.
https://ec.europa.eu/digital-building-blocks/sites/spaces/EB...
Re: German implementation of eIDAS will require an Apple/Google account to function
#548Earlier quoted context omitted.
Your disdain isn't helpinh you here either as you're just as wrong as parent. Such public utilities ought to always prioritize privacy, platform-independence, and empowering market competion long- and short-term. And to achieve that you need to start at the design level. In this case, clearly, you either have to avoid relying on app attestation or lay the foundation for an unrestricted number of independent chain of…
You have the right starting point, but the wrong conclusion. Government services need to be inclusive of everybody. But you simply cannot build technical solutions that put technical requirements on devices owned by the users in a way that the service is sufficiently inclusive. That is just a fact. If you want to be critical of the outcome on compatibility grounds, forcing a grind to increase technical compatibility…
Re: German implementation of eIDAS will require an Apple/Google account to function
#549Earlier quoted context omitted.
[flagged]
Would you say the same if they refused to serve kosher/halal meals for Muslim/Jewish patients? UK law protects some philosophical beliefs equally to religions. (what qualifies is a bit of a mess as it's all case law) (On a practical note, I imagine it's easier for hospitals to just serve vegan food for anyone who is vegetarian/Muslim/Jewish rather than have specific kosher/halal meals)
Re: German implementation of eIDAS will require an Apple/Google account to function
#550German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
So with a Jolla phone and Linux laptop, I am left in the cold.