Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

601–610 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#601
post #8
post #4

Earlier quoted context omitted.

EU digital identity law to make inter-EU signatures (And authentication) work. As an example, an EU citizen working in Sweden should be able to submit Swedish tax forms whilst living here by using a digital identity from the originating nation. There are also some standards in place like ETSI standardized extensions to PDF signatures so that you can verify that a signature inside the PDF was actually signed by a spec…

The gold standard for digital signatures today is - someone sends you a docusign link - you sign up with your email - you sign with your name in a cutesy font Theres a dispute? Well it was going to end up in court no matter how you signed it anyway. This has all the hallmarks of a design by committee project by people whose salary is paid regardless of demonstrating market fit, productivity, usage, plain sensibleness…

Funny part is that the real infra behind digital signatures is insanely serious compared to DocuSing "cutesy font"..

I did not know that root CA keys are generated in faraday cages?? Multiple custodians persent, then kept in tamper proof vaults.

I had no idea until I saw this visual breakdown - https://vectree.io/c/public-key-infrastructure-pki-and-certi...

Re: German implementation of eIDAS will require an Apple/Google account to function

#602

What if you „lose“ your google / apple account, like this sanctioned judge of the international criminal court? Crazy to imagine that we are still baking in dependency on US providers in european societies, even though there is clear indications we should be doing the opposite?

Maybe it will be time to have a critical device around, that does not rely on Apple/google and has stuff like eID and other critical digital documents. But this is going to be annoying, carrying two devices. Maybe easier to keep the paper version as backup for such a case.

It might not even have to be a smartphone, but much lighter yubikey style (pk/sk signature) devices.

I hate to say it but the form factor of those crypto hardware wallets might be a good compromise between smartphone and very low level tech. Non-tech folks should be able to use them too, a struggle that the crypto space is constantly working with

Re: German implementation of eIDAS will require an Apple/Google account to function

#603

Earlier quoted context omitted.

So cementing a dependency on paperclip-optimizing foreign megacorps to intermediate all your purchases and communications doesn't allow them to influence your behavior?

A dependency on a paperclip optimizing foregin megacorp is not remotely compara le to a "shock collar padlocked around your neck"

So getting shadow banned into a depression spiral that causes you to commit suicide because you think everyone in the world is ignoring you, or locking the account that all your other accounts at all other companies and even government services are tied to with no recourse, or constantly spying on everything you do with all of the corresponding chilling effects... is your point that it's actually worse than a shock collar?

Re: German implementation of eIDAS will require an Apple/Google account to function

#604

Earlier quoted context omitted.

Bootloader patching is just what you chose to use in your original false analogy. Letting apps verify the environment they run in is just as critical for the purposes of guaranteeing the digital identity. It’s all pieces of the puzzle.

It's not. I can guarantee my identity by e.g. scanning my ID card on a system with absolutely no secure boot chain. I can also guarantee a secure boot chain with my patched bootloader. Neither of these things require apps to verify the environment they run in.

> I can guarantee my identity by e.g. scanning my ID card on a system with absolutely no secure boot chain.

Your ID card is on your phone. Go ahead, guarantee you’re not using a duplicate of someone else’s ID card, that no one could duplicate your card, with a mainstream widely available consumer phone.

> I can also guarantee a secure boot chain with my patched bootloader.

Go ahead, show how your grandma automatically guarantees to interested parties that I or whoever else didn’t patch her bootloader to run a backdoored OS, while using a mainstream widely available consumer phone.

> Neither of these things require apps to verify the environment they run in.

Demonstrate a mainstream, widely available consumer phone that does these things without requiring apps to verify the environment they run it.

We can continue this infinitely, but if you keep making sweeping contrarian statements without contributing the proof required then it’s just not worth it.

Re: German implementation of eIDAS will require an Apple/Google account to function

#605

Earlier quoted context omitted.

> The reputation/trust damage self inflicted by the current US administration is triggering a pushback that will expand into the future. This barely even seems like the relevant part. If Google was founded in Japan and Apple in Brazil, it would still be foolish to entrench them as a dependency. It would barely even be better to do it with a local company. > They will move their data it the EU (where else? China?). Th…

Relying on open protocols to make all the difference is much more potent hopium than what GP wrote. Open protocols are kind of thing techies do when in cooperative mode, when industry isn't looking. But this is not this kind of problem - this is an economic, geopolitical problem. It's not about your local school moving off Windows to Linux, it's about the European corporations moving off Azure to some other cloud sol…

> It's not about your local school moving off Windows to Linux, it's about the European corporations moving off Azure to some other cloud solution offered by European corporations (do we even have any?).

But why is it about that? Why isn't it about e.g. governments in Europe funding the development of Linux virtualization so that it's simple to buy some hardware, put it in the back office and have an interface to it which is as easy for people to use as the incumbent cloud providers?

The vast majority of companies don't need "flexible scalability" etc. They have modest and finite loads and only ended up "in the cloud" because for ten seconds it seemed like having 100 VMs in the cloud was going to be a lot cheaper than having 100 physical servers, until it turns out that you can put those 100 VMs on two physical servers in your own possession and it costs less to do that than the cloud providers charge and then you keep control of your data and infrastructure.

> everything else in the real world - including computing hardware and supporting power and network infrastructure - plays by rules of market economy, with proprietary solutions and clear structures of ownership.

This is pretty wrong. Hardware companies sell hardware. A lot of them will try to lock you into their shitty software if you let them, but that is neither required nor desired. And some of the better ones don't, e.g. there isn't that much lock-in happening with AMD or Intel servers. We just need that to be happening for phones. And smart hardware companies can fully understand "commoditize your complement" as being in their own interest while still making a profit selling the hardware that isn't locked to any particular software.

> It makes no sense to try and fight this here

It's not clear what you're even suggesting.

Suppose you want Europeans to have access to a phone platform that isn't controlled by an American megacorp.

If they release a domestic proprietary one then other countries won't want any part of it. They don't want to be under the heel of a European megacorp any more than an American one, and indeed many will be suspicious of it and actively try to thwart adoption. And then you lose the network effect and can't get traction.

Whereas if you do something like require phone hardware to allow the user to replace the OS, and then fund development of open source phone operating systems and make sure they're required to be supported within your jurisdiction, then they can easily spread outside of your jurisdiction because people aren't nearly as suspicious and oppositional to something where you've precommitted to not putting people on the enshittification treadmill. And then everybody gets out from under the thumb of those corporations.

Re: German implementation of eIDAS will require an Apple/Google account to function

#606
post #466

Earlier quoted context omitted.

Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.

I am not a lobbyist, but I do recognize the great value the adtech industry provides to society and I am familiar with the common arguments and strategies people try and use to undermine it and sow distrust.

Genuinely curious to hear what great value you think is being delivered to society by adtech.

Re: German implementation of eIDAS will require an Apple/Google account to function

#607

Earlier quoted context omitted.

But then why not just make car driving not create CO2?

Because that doesn't play to Germany's industrial and economic strengths (precision machining, metallurgy, basically the whole ICE automobile supply chain). EVs are just mechanically much simpler, with a shorter BOM that largely centers around Asian (particularly Chinese) battery, REE, and semiconductor supply chains, so hundreds of thousands of good jobs that supported Germany's industrial model are now economically…

That's the Kodak business model: New thing arrives that will disrupt the old thing, so don't build it. Problem is then someone else will build it anyway and instead of losing 2 jobs making ICE cars and getting 1.5 jobs making batteries and solar panels, you just lose the 2 jobs and get nothing, which is how Kodak went bankrupt.

Also, LFP batteries don't contain rare earths.

Re: German implementation of eIDAS will require an Apple/Google account to function

#608

Earlier quoted context omitted.

It's not. I can guarantee my identity by e.g. scanning my ID card on a system with absolutely no secure boot chain. I can also guarantee a secure boot chain with my patched bootloader. Neither of these things require apps to verify the environment they run in.

> I can guarantee my identity by e.g. scanning my ID card on a system with absolutely no secure boot chain. Your ID card is on your phone. Go ahead, guarantee you’re not using a duplicate of someone else’s ID card, that no one could duplicate your card, with a mainstream widely available consumer phone. > I can also guarantee a secure boot chain with my patched bootloader. Go ahead, show how your grandma automaticall…

> Your ID card is on your phone.

No, it's not. It lays on the desk next to me right now. I can communicate with it over NFC and I can't duplicate it. There's a debit card next to it and the same applies there - though it can also be communicated with by using a smartcard reader, which can't be done with my ID.

> guarantees to interested parties

The only interested party is my grandma, and she'll come to me to help her because her phone will stop working when the boot chain gets compromised (as it should).

> Demonstrate a mainstream, widely available consumer phone that does these things without requiring apps to verify the environment they run it.

Pretty much all of them today? Letting apps verify the environment is an extra feature built on top of secure boot chains, not the other way around. We're only having this discussion because having secure boot chains enables app attestation to work in the first place, and letting the user patch things is just a matter of key management policies. If you think these are "sweeping contrarian statements", you may want to spend some time learning how these things work.

This is not a technical problem, technical aspects have been already solved a long time ago. This is a social/political problem of who holds power over whom.

Re: German implementation of eIDAS will require an Apple/Google account to function

#609

I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulat…

Exactly. It's my own device, I can do whatever I please with it. There shouldn't be an automated way for apps to check if my device has been blessed by the US tech giants or not.

It’s my own device so I should be allowed to let the manufacturer make it secure so I don’t need to worry about security.

I don’t want _all_ my devices to behave like that but I definitely want my phone to be more trustworthy for banking and government service purposes.

Re: German implementation of eIDAS will require an Apple/Google account to function

#610

Earlier quoted context omitted.

Because there are many interesting uses for having a personal electronic token that's also recognized by your own government. My own interest is in using it as a base for establishing an identity for electronic ballots.

sure but I don't understand how electronic IDs are a good starting point for having QR TAN or some other hardwarde device. I think OS-agnostic hardware should be the default starting point, not the other way around.

The electronic ID hosts a cryptographic key that can be used through some sort of hardware device in order to generate QR codes, or whatever that are linked to the user's official identity...

The public part of the identity (which in our example it was enrolled at bank account opening) can be used by the server that checks the QR code to see if it actually belongs to the correct account owner.

Post reply on HN