Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

591–600 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#591

Earlier quoted context omitted.

Essential EU government services cannot be devised on the hope that US companies will invent something that - contrary to current US legislation - will somehow provide the attestation services needed in a GDPR-compliant way without forcing EU citizens to provide personal data to US companies. If it's not possible to create such a system for mobile phones because of legal issues (as you seem to acknowledge and judges…

> Essential EU government services cannot be devised on the hope that US companies... I don't disagree. I am just pointing out that this is wishful thinking right now. As said, Europe has zero footprint in hardware or software so the choice is either not to develop any digital services or to accept that they will run of foreign hardware/software because everything is either Android or Apple and runs on hardware that…

EU can build token-generation hardware and that's the solution to the perceived problem. Such approaches have been used by banks for decades. It's not a "20 years project" to issue similar hardware to what my German bank issued 10+ years ago. I've explicitly stated in my post that the EU should not build a software solution for smartphones with US operating systems since this approach violates the GDPR and other laws because of a fundamental incompatibility of EU law with the US CLOUD Act that has been recognized by judges already. The proposed solution you seem to favor is illegal.

If I'm right, you're the person ignoring reality and basing their judgment on wishful thinking, not me. I understand why you want to have a smartphone solution ("practicality") but AFAIK that's currently not a viable approach. I might be wrong about the legal situation but that's what I've claimed. Just repeating your talking point is not a reasonable reply to these legal concerns. In addition to this, there are also serious national security concerns, of course.

Re: German implementation of eIDAS will require an Apple/Google account to function

#592
post #428

Earlier quoted context omitted.

A 10% goal would be a good first step. Now excuse me while I read some tea leaves to find out if my trains will be on time tomorrow ( spoiler: they wont).

surely 10% of DB digital offerings work as expected, just not the 10% that is essential for train travel.

I love how just ordering a ticket is already a minefield for anyone not aware of how crappy german services are integrated. Pick one route, you will get a list of fully customized tickets that cover everything you need, pick another and you will get a list of tickets that will get you fined unless you carefully read through each and pick both a ticket that comes close to what you need and buy more tickets to cover any additional options.

The only thing near 100% perfection when it comes to german services is the full assery with which they are implemented.

Re: German implementation of eIDAS will require an Apple/Google account to function

#593

Earlier quoted context omitted.

Yes (well, kinda - attested systems can be and are vulnerable too), and remote attestation is completely orthogonal to that threat anyway. Securing the boot chain does not involve letting apps verify the environment they run in, it's an extra (anti-)feature that's built on top of secure boot chains. It's also really incredible how people can see "user being in control" and just immediately jump to "user having to be…

Bootloader patching is just what you chose to use in your original false analogy. Letting apps verify the environment they run in is just as critical for the purposes of guaranteeing the digital identity. It’s all pieces of the puzzle.

It's not. I can guarantee my identity by e.g. scanning my ID card on a system with absolutely no secure boot chain. I can also guarantee a secure boot chain with my patched bootloader. Neither of these things require apps to verify the environment they run in.

Re: German implementation of eIDAS will require an Apple/Google account to function

#594

Earlier quoted context omitted.

I never mentioned users having to know things (what you quoted was about the user getting informed whether their system is compromised, which is the job of a secure boot chain). The user being in control means that the user can decide who to trust. The user may end up choosing Google, Apple, Microsoft etc. and it's fine as long as they have a choice. Most users won't even be bothered to choose and that's fine too, bu…

> what you quoted was about the user getting informed whether their system is compromised, which is the job of a secure boot chain User being informed means they have to know what a compromised system would entail. That alone is a huge and frankly impossible thing to expect from regular people. > Most users won't even be bothered to choose and that's fine too, but with remote attestation, it's not the user who decide…

> That alone is a huge and frankly impossible thing to expect from regular people.

The systems used by regular people could just refuse to boot further when detecting a compromise, so I'm not sure where this comes from. We have prior art for that too. This is still orthogonal to letting users who want to patch things patch them, and not letting the apps verify what environment they run in. It's all compatible with each other, and with both regular and power users.

> Then you can't demand those developers trust your device.

Somehow we could for decades. Whether we'll still be able to in the future depends only on how much noise and friction we'll make about it now.

Re: German implementation of eIDAS will require an Apple/Google account to function

#595
post #592

Earlier quoted context omitted.

surely 10% of DB digital offerings work as expected, just not the 10% that is essential for train travel.

I love how just ordering a ticket is already a minefield for anyone not aware of how crappy german services are integrated. Pick one route, you will get a list of fully customized tickets that cover everything you need, pick another and you will get a list of tickets that will get you fined unless you carefully read through each and pick both a ticket that comes close to what you need and buy more tickets to cover an…

So much hate.

Some time ago my "25% DB Card" ran out and was not active anymore, but the app did not display a warning. Even when buying a ticket from the app, it still had the "25% off" option activated by default.

Result: huge fine (something like 200 euros) on the train + I had to buy a completely new ticket (another 100+ euros) because the ticket I had bought ( which was 75% of original price) was considered completely invalid. I tried in all possible ways to get this fine reduced, as it was an honest mistake and arguably caused by their UX, but they did not budge.

I hate hate hate Deutsche Bahn with a passion, yet I still use it cause I'm an idiot who doesn't want to fly for short routes.

Re: German implementation of eIDAS will require an Apple/Google account to function

#596
post #286

Earlier quoted context omitted.

Belgium has had exactly this for decades. But now they want to get on the hype train for smartphone based ID, because card reader support is still shit in browsers in 2026. Adding to this: anyone older than 12 years old is required by law to have their government issued ID on them at all times when in public. If your ID is suddenly your smartphone, you're essentially required to have that on you 24/7. Dystopian spywa…

because card reader support is still shit in browsers in 2026 Around a decade ago I was working at a company that used smartcard login for authenticating to internal sites. I've heard of many others doing the same. USB card reader worked fine in both IE and Firefox at the time, so I take your statement to mean that we've somehow regressed since then (not surprising) or this was an isolated instance of success (less l…

There are two parts to this. The basic standards based auth stuff "sort of" works. Everything else requires a browser plugin. One of the Debian dudes (of grep.be fame) maintains a Linux version that works in many cases, but for some reason many non-government organisations require the use of a different plugin, one that only works on Windows and mac.

As an aside: signing things has a particularly awful UX. I never know what I'm signing, I have no way to verify that what's on the screen is what's being signed. And then there are orgs that use eID based PDF signing, which again requires different plugins. In short: a shitshow.

Re: German implementation of eIDAS will require an Apple/Google account to function

#597
post #283

Earlier quoted context omitted.

Sure, let's just arbitrarily exclude ~1million people because they're not running the government's preferred American spyware.

This is an unfair and a straw man argument, is it not? Are you also unhappy that in a democracy the 51% choose how the other 49% are going to be governed? Why device attestation is required is quite well explained by this github comment [0]. I am in the industry and I agree fully with it, because it is a fact a problem for most smart phone users in terms of security. 0 - https://github.com/eu-digital-identity-wallet/…

That's a silly argument, not only because many important changes require a 2/3 majority.

My point was that the government and its services (German or otherwise) should be available to all citizens/residents, regardless of their choice (or lack) mobile device.

Re: German implementation of eIDAS will require an Apple/Google account to function

#598

Earlier quoted context omitted.

And how exactly did attestation help there? Securing apps from the user does not secure the user from malware.

Now you can't bundle malware deep within the system "ROM" unless you want to break SafetyNet's attestation. It's a big change in that aspect.

Custom ROMs tell you that this is not true at all.

Re: German implementation of eIDAS will require an Apple/Google account to function

#599

Earlier quoted context omitted.

I'm pretty sure electronic IDs are a good starting point for exactly this. Hopefully they get wider use inside the EU.

why do you hope that?

Because there are many interesting uses for having a personal electronic token that's also recognized by your own government. My own interest is in using it as a base for establishing an identity for electronic ballots.

Re: German implementation of eIDAS will require an Apple/Google account to function

#600

Earlier quoted context omitted.

why do you hope that?

Because there are many interesting uses for having a personal electronic token that's also recognized by your own government. My own interest is in using it as a base for establishing an identity for electronic ballots.

sure but I don't understand how electronic IDs are a good starting point for having QR TAN or some other hardwarde device. I think OS-agnostic hardware should be the default starting point, not the other way around.
Post reply on HN