Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

581–590 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#581
post #214

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

You are assuming it will not be possible to add support to other OS. Why?

What would be “knowing it can work on grapheneOS” for example, in your view?

Re: German implementation of eIDAS will require an Apple/Google account to function

#582

What if you „lose“ your google / apple account, like this sanctioned judge of the international criminal court? Crazy to imagine that we are still baking in dependency on US providers in european societies, even though there is clear indications we should be doing the opposite?

Maybe it will be time to have a critical device around, that does not rely on Apple/google and has stuff like eID and other critical digital documents. But this is going to be annoying, carrying two devices. Maybe easier to keep the paper version as backup for such a case.

Re: German implementation of eIDAS will require an Apple/Google account to function

#583
post #30

I am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.

Isn’t eIDAS about voluntarily authenticating rather than being controlled/monitored? Or am I mixing up?

Re: German implementation of eIDAS will require an Apple/Google account to function

#584

Earlier quoted context omitted.

I think your analogy is flawed. I can be part of the losing 49% and still be entitled to receive the same services as the 51%, whereas people who chose a privacy-oriented OS are essentially going to be excluded from essential governmental services. That's a whole different kind of thing. I'm not going to replace my 1200 EUR smartphone with a device that forces me to have an account with Apple or Google. I've been iss…

>I' ve been issued a German identity card, which is its own computer that includes a digital identity already. Then keep using it, instead of the not-mandatory app? > I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need. Sure. In the mean time, do we tell the other few dozen millions that don't have an expensive card reader to go…

Government services are going to drop support for the old scheme the minute they start supporting the new one.

Re: German implementation of eIDAS will require an Apple/Google account to function

#585
post #477

Earlier quoted context omitted.

> somehow we don't go and ban kitchen knives False analogy. You can’t have your kitchen knife exploited by a hacker team in North Korea, who shotgun attacks half of the public Internet infrastructure and uses the proceeds to fund the national nuclear program, can you? (I somewhat exaggerate, but you get the idea.) > Systems can be secure and trusted by the user without having to cede control In an ideal world where u…

> You can’t have your kitchen knife exploited by a hacker team in North Korea, who shotgun attacks half of the public Internet infrastructure and uses the proceeds to fund the national nuclear program, can you? (I somewhat exaggerate, but you get the idea.) Isn’t the status quo, that you need to intentionally choose to allow this?

On iOS, the worst you can do is not update your OS and thus be vulnerable to exploits. There is no setting that a casual user could be social engineered into enabling that would allow the OS to be patched.

Re: German implementation of eIDAS will require an Apple/Google account to function

#586
post #477

Earlier quoted context omitted.

> You can’t have your kitchen knife exploited by a hacker team in North Korea, who shotgun attacks half of the public Internet infrastructure and uses the proceeds to fund the national nuclear program, can you? (I somewhat exaggerate, but you get the idea.) Isn’t the status quo, that you need to intentionally choose to allow this?

Yes (well, kinda - attested systems can be and are vulnerable too), and remote attestation is completely orthogonal to that threat anyway. Securing the boot chain does not involve letting apps verify the environment they run in, it's an extra (anti-)feature that's built on top of secure boot chains. It's also really incredible how people can see "user being in control" and just immediately jump to "user having to be…

Bootloader patching is just what you chose to use in your original false analogy. Letting apps verify the environment they run in is just as critical for the purposes of guaranteeing the digital identity. It’s all pieces of the puzzle.

Re: German implementation of eIDAS will require an Apple/Google account to function

#587

German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.

With a view on current geopolitics I find it absolutely irresponsible to use two US companies for attestation. The sanctions on ICC judges/prosecutors at the latest should have shown that it is a matter of national security to avoid a possibility of being completely shut down by an unstable US government. How do you propose to deal with people who get sanctioned or banned by Google/Apple for whatever reason? What measures do you have in place so these people can still access their ID?

Re: German implementation of eIDAS will require an Apple/Google account to function

#588
post #466

Earlier quoted context omitted.

Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.

I am not a lobbyist, but I do recognize the great value the adtech industry provides to society and I am familiar with the common arguments and strategies people try and use to undermine it and sow distrust.

Any articles highlighting the great value?

Re: German implementation of eIDAS will require an Apple/Google account to function

#589

Earlier quoted context omitted.

Where is that free choice that you see "in reality"? This post is about the opposite of that getting put in place. The actual reality is that almost every service provider is converging on supporting a few extremely restrictive options. From every private service you can think of, to key government services. They all are saying "to interact with us, you must use one of these two types of devices, with all the attesta…

> They all are saying "to interact with us, you must use one of these two types of devices, with all the attestation and security measures intact" Are you claiming that this is the only way of interacting with particular government services, with the other ways that existed before the app no longer being available? To make situation „dystopian“ this must be the case.

That is clearly the direction, yes.

First it's new and optional, then it's mature but equal, then as adoption grows further, the old way of doing things gets deprioritized and neglected, then you're a 2nd tier citizen until they finally remove it altogether.

See: Essential businesses like grocery stores going cashless

Re: German implementation of eIDAS will require an Apple/Google account to function

#590
post #377

Earlier quoted context omitted.

You can maybe, trust the user to handle it's own certificate in their own devices? Though I admit requiring attestation is probably a good default.

One important feature of a legal ID is that it's hard to copy, so attestation from the hardware storage would have to be basically mandatory. But yeah, the user could have a choice to this extent.

You can attest that cryptographic key material is safely stored without attesting that their operating system and software running on it is all government-approved.

That's what smartcards like Yubikey do, my government certificate is on it and it can't be exported. They could attest that but beyond that, the operating system of the host device is none of their business.

Post reply on HN