Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

621–630 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#621

Earlier quoted context omitted.

Exactly. It's my own device, I can do whatever I please with it. There shouldn't be an automated way for apps to check if my device has been blessed by the US tech giants or not.

It’s my own device so I should be allowed to let the manufacturer make it secure so I don’t need to worry about security. I don’t want _all_ my devices to behave like that but I definitely want my phone to be more trustworthy for banking and government service purposes.

> I should be allowed to let the manufacturer make it secure so I don’t need to worry about security.

You can still do this by simply not rooting your phone, or replacing the manufacturer's cryptographic key with your own, or altering whatever other 'security' measures are in place. What you're asking for is to have no other choice but to give the manufacturer control over your devices.

Re: German implementation of eIDAS will require an Apple/Google account to function

#622
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

You are assuming it will not be possible to add support to other OS. Why? What would be “knowing it can work on grapheneOS” for example, in your view?

It will be possible but simply won't be done.

And as of now it won't work on GrapheneOS, it doesn't pass anything except MEETS_BASIC_INTEGRITY

Re: German implementation of eIDAS will require an Apple/Google account to function

#623

Earlier quoted context omitted.

Exactly. It's my own device, I can do whatever I please with it. There shouldn't be an automated way for apps to check if my device has been blessed by the US tech giants or not.

It’s my own device so I should be allowed to let the manufacturer make it secure so I don’t need to worry about security. I don’t want _all_ my devices to behave like that but I definitely want my phone to be more trustworthy for banking and government service purposes.

That's not the problem at all.

The problem is that manufacturers are forcing everyone into this scheme for the express purpose of mass surveillance and control.

It has nothing to do with making your device "secure"

Re: German implementation of eIDAS will require an Apple/Google account to function

#624
post #485

Earlier quoted context omitted.

Okay, but Google certifies phones which are not updates for the last several years. They can be trivially rooted, then they spoof the signature and get a pass in Integrity while being wide open for malware (or cooying the ID, ID presume).

The documentation clearly outlines that there are multiple signals being analysed. Relying on play integrity alone is definitely not sufficient as you state.

Okay, I meant that Google issuing a "pass" is worthless, yet it's being used as a mandatory signal.

Re: German implementation of eIDAS will require an Apple/Google account to function

#625
post #466

Earlier quoted context omitted.

Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.

I am not a lobbyist, but I do recognize the great value the adtech industry provides to society and I am familiar with the common arguments and strategies people try and use to undermine it and sow distrust.

>but I do recognize the great value the adtech industry provides to society

Ok, so you're trolling then.

Re: German implementation of eIDAS will require an Apple/Google account to function

#626
post #567

Earlier quoted context omitted.

> The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). GrapheneOS uses standard Android APIs for hardware attestation (as opposed to Google-specific ones), so why don't you just use those from the get-go?

They did. This is why Graphene works.

They said they have GOS support in the roadmap, meaning they know it doesn't work but pinky promise to work on it in some undisclosed future.

Re: German implementation of eIDAS will require an Apple/Google account to function

#627

Earlier quoted context omitted.

I bet £50 that the alternative (eg GrapheneOS attestation (based on the standard AOSP attestation)) will be delayed, then delayed, then scrapped since almost everyone is using Google Plag integrity anyway. Yes, I assume malicious intent, sorry, seen this happen enough tines recently.

I'm in the US, not facing a mandate, but I want an open-source alternative to Play Integrity to use in the financial sector. There should be no excuse for anyone not supporting GrapheneOS. I've asked on Google's issue tracker and they are not interested in opening the program to non-OHA ("Google Play Approved") participants.

Indeed. Goggle is very hostile to anyone not wanting Google deep in their OS, running undisclosed code with the superuser privileges.

I think we all collectively should try the compliance / regulatory ways to force enough companies to have to adkit they know Google lies about security when talking about attestation, then force them into supporting alternative attestation methods.

Re: German implementation of eIDAS will require an Apple/Google account to function

#628

Earlier quoted context omitted.

They won't implement alternatives later, they'll be no point if "most of out customers is using either of the major providers". Concerning secure enclave - what other device except iphones and Pixels have it actually safe?

> They won't implement alternatives later, they'll be no point if "most of out customers is using either of the major providers". It's hard for me to assess the effort needed here, but I guess that the GrapheneOS implementation will be 99% like the regular Android implementation. Supporting both systems does not seem to be that unrealistic.

But the "regular android implementation" they decided to choose now is not the regular android implementation (AOSP), they're relying on the signal from Google running play store integrity checks.

Re: German implementation of eIDAS will require an Apple/Google account to function

#629
post #397

Earlier quoted context omitted.

Oh I see your confusion. It is not trying to prove it's not cheating with the UI (or remote control, or ...) to the owner of the phone. It's proving to the owner of the website (or app, or SIM, or ...) that it's really the user agreeing to the contract on the screen. Or, more to the point, it's proving it to courts after the fact so they'll convict the owner of the phone rather than the business or government. The sc…

The argument here is kind of hard to follow. Who is the "owner" of the phone, "the user" is also mentioned and it is not clear if these two are the same. Is the owner of the phone in the controlling-software sense, Google, or is it the end user? Both fits, and both are commonly used. Because if it is the end user, the strong version of the argument would be as follows: The end user signs a document, baked in is an at…

> How could the attestation help here?

By proving that when the user clicked "Yes, I want this loan, $X deposited on amount Y" that is actually what was on the screen then the user clicked approve. In other words, that the agreement is actually what the REMOTE party believes it is, even if the owner installed "Free coins in the bunny casino v7.0.apk" from a website.

(meaning that is not currently very provable, and exploited by scammers quite a bit. Courts have a nasty irritating habit of holding the more powerful party (ie. the bank/government) responsible for the consequences of scammers' actions. Well, at least from the viewpoint of banks/governments that is a nasty habit)

Re: German implementation of eIDAS will require an Apple/Google account to function

#630
post #407
post #382

Earlier quoted context omitted.

It is about supporting "online cross-border transactions", in other words for providing a legally binding way for agreements to be made. This will be the basis for VISAs, proving you hold credentials (initially driving license, but will extend further), proving you've signed a contract. This MAY include a central-bank wallet with "digital Euro", or it may not, but even without, it's about money. You can smell where t…

Btw a visa is a document allowing entry into a country, while VISA is a word mark used by Visa, inc. for their payment cards and network. I think you're referring to the travel document, but since the context also includes payment networks, I'm not 100% sure.

It's about contracts and official government documents, so it definitely includes payment networks, but it's certainly not limited to that.
Post reply on HN