Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

551–560 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#551
post #397

Earlier quoted context omitted.

That seems like a weak argument to require attestation? What would attestation prevent that scenario, specifically?

Oh I see your confusion. It is not trying to prove it's not cheating with the UI (or remote control, or ...) to the owner of the phone. It's proving to the owner of the website (or app, or SIM, or ...) that it's really the user agreeing to the contract on the screen. Or, more to the point, it's proving it to courts after the fact so they'll convict the owner of the phone rather than the business or government. The sc…

The argument here is kind of hard to follow. Who is the "owner" of the phone, "the user" is also mentioned and it is not clear if these two are the same. Is the owner of the phone in the controlling-software sense, Google, or is it the end user? Both fits, and both are commonly used.

Because if it is the end user, the strong version of the argument would be as follows: The end user signs a document, baked in is an attestation that Google guarantees that this device is an approved Android device with a clean boot chain and a Chrome web browser. Then the end user contests the signature in court, either because they didn't understand what they signed, or they did not sign it at all, or did it under threat. How could the attestation help here?

I do not have experience with all EU countries, of course, but more than one, and nowhere is this an issue today. Countries use a wide variety of electronic identification, from soft certificates and mobile phones to smart cards. But as far as I know, all countries accept signatures made even with normal Windows PCs. You can contest a signed document in court for a multitude of reasons, but that's not specific to electronic signatures.

Re: German implementation of eIDAS will require an Apple/Google account to function

#552
post #64
post #43

Earlier quoted context omitted.

Source? You're linking to a bugtracker. I doubt they're inviting people to spam it with duplicate entries — valid as I think the concern is. But maybe it says somewhere that you can leave feedback here and I just haven't seen it?

There is a 8 months old open ticket, with an official answer, here: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

Yes, hence me saying duplicate above

Re: German implementation of eIDAS will require an Apple/Google account to function

#553

Earlier quoted context omitted.

> If the ID is just a password, you can tell other people your password, and it can be stolen, and it can be cloned. You can give your physical cards to other people or give them access to your computers, too. > Germany is a strict liability country, and you will be fined or imprisoned for anything that is done with your identity card that was cloned because your PC was infected by malware if you don't report it stol…

You don't see an issue with going to prison because you got a computer virus and didn't know you got a computer virus?

It would be unfortunate, but we are grown adults living in a society where computers have existed for decades. Ignorance is not an excuse, especially if we have various options to choose from.

If we are given the option to choose from doing everything in person in a government office or via a computer of our choosing, it would be up to each of us to decide the tradeoff between security and convenience, price, privacy, ethics and other factors.

I can use an old laptop I keep in a drawer only for things related to IDs, banking and taxes.

I can use my main desktop and choose to rely on the security provided by virtualization, not installing random crap and having a hardened system. I can choose to keep my desktop inside my building that has multiple security measures - a doorman, an alarm system, multiple cameras inside and outside and a kill switch for shutting off power if someone enters using brute force. That desktop may be booted up, but it will have a long random password on the lockscreen with timeouts for wrong guesses. Unless you're an extremely good social engineer and don't care about being recorded, or if you're a master ninja who can crawl the ceiling and somehow get in without being noticed, good luck. Even then, you'd have to manage not triggering any alarms or kill switches. You'd then have to use a cold boot attack to extract my LUKS keys.

I can also choose to use a XingDong smartphone with a Google account where I have TikTok, Meta apps, LinkedIn, Tinder, Grindr, 100s of random games and a whole lot of other shady weather apps, news apps and so on. I can choose to bring that smartphone with me everywhere I go and leave it on the table in a restaurant when I go to take a shit with a common pattern lock (I've unlocked 4 or 5 locked smartphones by just searching for "most common patterns lockscreen android") or with irrevocable easily-spoofed biometrics.

In both cases (and in the infinite other cases) it's my responsibility. If I'm unsure of my security posture, I can buy a security dongle or rely on Google's attestation mechanisms for Android or decide that I don't understand enough - in which case I'd have to drive an hour to my government office once in a while to file my taxes or to the bank once in a while to move around some money.

In the ideal scenario, nothing would prevent the uneducated people from using their smartphone. They might even get prompted by the government or banks - "You're using/downloading this app on a smartphone. Would you like to use whatever attestation is available to be more secure?".

Citizens are not brain dead morons. They're not cats or dogs. They're not mentally retarded (those who are can receive assistance). They're not 13. We have education. We've had computers for decades. Computer security is not a novel idea. If a citizen wants the convenience of online banking or online tax filing or of any other online participation with the government, they should be able to do so on a computer of their choice. If they install Windows XP and random spyware, it should be on them if and when they get hacked. It's a choice they made. Even the proverbial grandma should be aware of computer security by now. It's not 1990.

To say Android or iOS can't get viruses is plain wrong. They do and will continue to do so. Even if you restrict the smartphones to the latest models with the latest OSes, you'll still get viruses.

About 2FA/MFA - I can setup TOTP on another VM or physical computer. It's prone to phishing, but I am an educated adult who can accept the risk of being phished. Put me in jail if I get phished. I most likely won't. I'm the one who knocks. It's more likely someone will come to you with a gun and make you wire them money from your own smartphone.

I don't need a smartphone. I have enough desktops and laptops much more powerful than any smartphone on the market. If I have a smartphone, it won't be with a Google or Apple account. It might not even be with iOS or Android. There are many options and they will hopefully grow in the future.

I'm getting tired from editing this comment, but finally - I have a few friends who are completely illiterate wrt computers. They somehow manage to install Temu and other crap. They don't know what an "app" is, what a "browser" is, what an "OS" is and so on. They've been scammed a few times. They know they don't know anything, though. Or even if they haven't considered it before, if they do, they'd admit they don't know anything. They are not mentally retarded otherwise. An analogy would be that I'm offered to go to the moon for free so I can file my taxes there if I can pilot the rocket. I am 100% illiterate about rockets. I haven't even flown a drone. I don't know the first thing about yaw and pitch and whatnot. I am not retarded otherwise so I'll say "I don't know enough about flying rockets so I won't risk going to the moon on my own. Can I achieve the same things by coming to your office or by riding in a rocket piloted by someone else?".

Re: German implementation of eIDAS will require an Apple/Google account to function

#554
post #444
post #254

Earlier quoted context omitted.

This is necessary because the wallets contain an identity proofing functionality called PID(Person Identification Data). Showing these credentials basically approves you are you. There are high requirements for identity proofing that even pre-date wallets and that makes sense, because the potentially blast radius of identity theft is huge. Historically, these have been secured in smartcards, like eID cards or passpor…

What do you mean "shifting to smartphone"? It's not a natural process - it's a technical decision to shift them to the smartphone, and a really bad one. We already have smart cards, they work and do not depend on any corporations, even less foreign corporations.

We even have smartcards with e-ink displays and I'd personally want them to succeed here instead of moving security-critical apps to smartphones..

Because Google then abuses its position to inject unremovable spyware with elevated privileges into the phone which the user then can't defent against without making the phone "unsecure" and thus unsuitable for these apps.

If these apps really need a smartphone, I'd at least want it to be free of ad-related garbage in the system. I'm fine with not being able to flash a custom ROM on the smartcard as it doesn't contain hostile software.

Now if even Apple starts showing ads, there's no other choice but to restist this..

Re: German implementation of eIDAS will require an Apple/Google account to function

#555

Earlier quoted context omitted.

We have had a large discovery of pre-installed malware every year for the past decade so far. Seems like a fairly big problem.

And how exactly did attestation help there? Securing apps from the user does not secure the user from malware.

Now you can't bundle malware deep within the system "ROM" unless you want to break SafetyNet's attestation. It's a big change in that aspect.

Re: German implementation of eIDAS will require an Apple/Google account to function

#556

Earlier quoted context omitted.

Would you say the same if they refused to serve kosher/halal meals for Muslim/Jewish patients? UK law protects some philosophical beliefs equally to religions. (what qualifies is a bit of a mess as it's all case law) (On a practical note, I imagine it's easier for hospitals to just serve vegan food for anyone who is vegetarian/Muslim/Jewish rather than have specific kosher/halal meals)

Religion tends to be more constitutive to a person's self-identity than purity signalling dietary trends.

Setting aside the fact that there are multiple very old, very large religions that are nearly or actually vegan (e.g., Jainism), or that people raised vegan can't easily digest meat or animal products, why on earth do you feel that you or a hospital worker are qualified to determine the beliefs making up someone's identity, when you know absolutely nothing about them?

Re: German implementation of eIDAS will require an Apple/Google account to function

#557

Earlier quoted context omitted.

> but somehow we don't go and ban kitchen knives, as having them around is valuable Some countries do :) Though I think physical analogies are misleading in a lot of ways here. > Systems can be secure and trusted by the user without having to cede control, and some risks are just not worth eliminating. Secure, yes, trustworthy to a random developer looking at your device, no. They're entirely separate concepts. > Mos…

I never mentioned users having to know things (what you quoted was about the user getting informed whether their system is compromised, which is the job of a secure boot chain). The user being in control means that the user can decide who to trust. The user may end up choosing Google, Apple, Microsoft etc. and it's fine as long as they have a choice. Most users won't even be bothered to choose and that's fine too, bu…

> what you quoted was about the user getting informed whether their system is compromised, which is the job of a secure boot chain

User being informed means they have to know what a compromised system would entail. That alone is a huge and frankly impossible thing to expect from regular people.

> Most users won't even be bothered to choose and that's fine too, but with remote attestation, it's not the user who decides even if they want to.

> And we don't need random developers looking at our devices to consider them trustworthy, it's none of their business and it's a big mistake to let them.

Then you can't demand those developers trust your device.

Re: German implementation of eIDAS will require an Apple/Google account to function

#558
post #460

Earlier quoted context omitted.

What's wrong with verifiable credentials? It's an important thing to have it seems? Your passport or a bank card are verifiable credentials, or at least are designed to be.

It's an EU thing, overcomplicated an not sovereign: https://ec.europa.eu/digital-building-blocks/sites/spaces/EB...

Oh dear, web 3.0, blockchain. Do we get our sovereign monkey NFT too?

Re: German implementation of eIDAS will require an Apple/Google account to function

#559

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

Are you interested in a community-maintained alternative to Play Integrity? I work in the finance sector and it's increasingly likely I'll have to implement attestation at some point. Graphene's examples are adaptable, but we need a DB of open Android distribution keys and effective admin to support adding and revoking, possibly something like the LVFS system for Linux firmware.

Re: German implementation of eIDAS will require an Apple/Google account to function

#560

Earlier quoted context omitted.

This is simply unacceptable. You are not making an innocent pragmatic compromise here, you are launching digital infrastructure which initially will tie everyone to Google/Apple and give alternatives a huge disadvantage for an unknown amount of time. Nobody knows when, or even if ever, support for open platforms will arrive. You should be ashamed of being involved in this monopoly handover to American big tech.

I bet £50 that the alternative (eg GrapheneOS attestation (based on the standard AOSP attestation)) will be delayed, then delayed, then scrapped since almost everyone is using Google Plag integrity anyway. Yes, I assume malicious intent, sorry, seen this happen enough tines recently.

I'm in the US, not facing a mandate, but I want an open-source alternative to Play Integrity to use in the financial sector. There should be no excuse for anyone not supporting GrapheneOS. I've asked on Google's issue tracker and they are not interested in opening the program to non-OHA ("Google Play Approved") participants.
Post reply on HN