Earlier quoted context omitted.
Why not do it right from the beginning? https://grapheneos.org/articles/attestation-compatibility-gu...
They don't really want to.
German implementation of eIDAS will require an Apple/Google account to function
561–570 of 674 posts
Re: German implementation of eIDAS will require an Apple/Google account to function
#562Earlier quoted context omitted.
> You think you look good if you say “hey, the Poles had this really good idea, how about we do the same”? Yes. > You think if there was any will wouldn’t the whole EU use whatever the Estonians are doing very well? Using the Estonian system would be vastly preferable. If politics doesn’t allow that, the political environment is broken.
How is the Estonian system now? I remember when I visited around 2010 our host just had a quite simple smart card reader and could just use it to sign in to government services with their ID and as far as I remember even sign mails and documents. Germany of course could not use normal smart cards but had to use NFC cards with special readers and made the signing feature and additional service you had to pay for on a…
Hungary is also rolling out a "digital citizenship" app. (Also can be bootstrapped via newer plastic cards, so no need to visit the government office.)
Re: German implementation of eIDAS will require an Apple/Google account to function
#563German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
Have you considered Unified Attestation [1] which is an alternative to Google's? [1] https://uattest.net/
Re: German implementation of eIDAS will require an Apple/Google account to function
#564I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…
> An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. and therefore the app cannot give a reasonable guarantee that it is not running in an adversarial environment that actively tries to break the app's integrity. Thus, the app cannot be used as a verified ID with governmental level of trust.
> governmental level of trust
This made me laugh out loud. Not because it's a meaningless phrase (where does "governmental" rank on a scale of fully to least trusted?), but because it seems to imply that governments do not have a miserable track record when it comes to IT security.
Though I suppose considering a security model sound because it uses security through obscurity like a blackbox integrity check would be very... governmental.
Does that mean "govermental level of trust" ranks somewhere between "snake-oil" and "cope"?
Re: German implementation of eIDAS will require an Apple/Google account to function
#565Earlier quoted context omitted.
Tbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.
The German ID card (Personalausweis) supports certificates and communication via NFC. I really don’t understand what’s all this about?
Re: German implementation of eIDAS will require an Apple/Google account to function
#566Earlier quoted context omitted.
I agree, you should be able to run anything you want, root your device, etc., but you also have to accept the consequences of that. If an app can no longer verify its own integrity, certain features are simply impossible to implement securely. Think of it this way: A physical ID (which is what we're trying to replace here) also has limitations, it looks a certain way, has a certain size, etc. Just because somebody wa…
Well, in that case, if they want full control and attestation yadda yadda, I'm fine with them shipping me a device they fully control exclusively for use of this stuff. But if we're talking about my smartphone that I paid for with my money that I worked for, I will do whatever I damn please with it. So I guess that means eIDAS will be inaccessible to me.
Re: German implementation of eIDAS will require an Apple/Google account to function
#567German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
> The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). GrapheneOS uses standard Android APIs for hardware attestation (as opposed to Google-specific ones), so why don't you just use those from the get-go?
Re: German implementation of eIDAS will require an Apple/Google account to function
#568German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
Re: German implementation of eIDAS will require an Apple/Google account to function
#569Earlier quoted context omitted.
> in the real world all smartphones are either Apple or Android... So you're claiming that Mobian doesn't exist? PureOS doesn't exist? PostmarketOS doesn't exist? Ubuntu Touch doesn't exist? SailfishOS doesn't exist?
Don't be disingenuous. All of what you mention are rounding errors in term of market share. This discussion feels unreal, really.
Re: German implementation of eIDAS will require an Apple/Google account to function
#570Earlier quoted context omitted.
I really have to wonder where in the EU you live. In Vienna, I got to buy an apartment in my mid-twenties by just saving up, which was easy, as many apartments are rent-capped and there's lots of cheap social housing. I got to enjoy free university, allowing me to get a high paying job. I get to use very cheap all electric state-subsidized rental car offerings if I need them, which is rare since we have federally goo…
> apartments are rent-capped > cheap social housing > free university > high paying job > very cheap all electric state-subsidized rental car offerings > affordable meat, dairy and vegetables And here we can simply examine the tax structure and conclude that the problem isn't whether the country sucks, but whether the side you're on sucks. After all, how can housing be affordable for ordinary workers if they have to…
I'm okay with this, but don't try to tell me that I'm not paying for the privileges we all get to enjoy here.
High income earners are the net payers here who disproportionally pour taxes into the system, so everyone can take part in these subsidized schemes. How this basic concept eludes you is beyond me.