Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

631–640 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#631
post #598

Earlier quoted context omitted.

Custom ROMs tell you that this is not true at all.

Custom ROMs no longer pass SafetyNet attestation, which apps such as banking ones (or streaming service ones) check.

I hope you mean Play Integrity, since there is no SafetyNet attestation anymore. And for that: https://github.com/osm0sis/PlayIntegrityFork

But there were similar things for SafetyNet attestation until it existed.

Re: German implementation of eIDAS will require an Apple/Google account to function

#632
post #170

Earlier quoted context omitted.

Google has banned many accounts of genuine users. What is your fallback for such an important vital service?

To play the devil’s advocate here: MEETS_STRONG_INTEGRITY on Android doesn’t require a Google account AFAIK. But it might change, of course. Edit: but as pointed out elsewhere in the thread, Play Integrity is not the only way to do hardware attestation on Android. GrapheneOS devs have a guide: https://grapheneos.org/articles/attestation-compatibility-gu... So avoiding proprietary Google stuff altogether is possible a…

How do you propose running Google play checks on the phone without working Google play? :)

I don't think it's possible. And indeed, avoiding is possible and better, but the companies choose lie of play store "integrity".

Re: German implementation of eIDAS will require an Apple/Google account to function

#633

Earlier quoted context omitted.

> This is still orthogonal to letting users who want to patch things patch them, and not letting the apps verify what environment they run in. It's all compatible with each other, and with both regular and power users. No, they're fundamentally opposed to each other. The entire point is that developers don't want their apps patched by just anyone, especially not malicious actors. Small minority of power users will in…

> The entire point is that developers don't want their apps patched That's exactly what I'm trying to say. The entire point is not to secure the user, it's to secure the apps. It's working against the user's interest, as letting the user lie to apps is essential to user's agency. The technical means used to achieve this could also be used to work for the user and ensure their security without compromising their agenc…

> as letting the user lie to apps is essential to user's agency.

You do understand that in this case the user's agency has a very clear line?

Tampering with an electronic identity software is not a fundamental right the same way as tampering with your ID-card or passport isn't.

> [...] and in other cases they just had no choice.

QED. Not that they wouldn't or didn't want to.

Re: German implementation of eIDAS will require an Apple/Google account to function

#634
post #631

Earlier quoted context omitted.

Custom ROMs no longer pass SafetyNet attestation, which apps such as banking ones (or streaming service ones) check.

I hope you mean Play Integrity, since there is no SafetyNet attestation anymore. And for that: https://github.com/osm0sis/PlayIntegrityFork But there were similar things for SafetyNet attestation until it existed.

Product rebrandings are kinda irrelevant.

Your link nicely says "as a general rule you can't use values from recent devices due to them only being allowed with full hardware backed attestation". These attestation workarounds have been rendered increasingly obsolete.

Re: German implementation of eIDAS will require an Apple/Google account to function

#635

Earlier quoted context omitted.

> The entire point is that developers don't want their apps patched That's exactly what I'm trying to say. The entire point is not to secure the user, it's to secure the apps. It's working against the user's interest, as letting the user lie to apps is essential to user's agency. The technical means used to achieve this could also be used to work for the user and ensure their security without compromising their agenc…

> as letting the user lie to apps is essential to user's agency. You do understand that in this case the user's agency has a very clear line? Tampering with an electronic identity software is not a fundamental right the same way as tampering with your ID-card or passport isn't. > [...] and in other cases they just had no choice. QED. Not that they wouldn't or didn't want to.

App attestation does not stop at legally binding identity software, and legally binding identity software can be serviced without app attestation. I accept not being able to tamper with my ID card, I may say it's "mine" but it ultimately belongs to the government; I don't accept not being able to tamper with my computers, they wouldn't belong to me anymore if that was the case.

> Not that they wouldn't or didn't want to.

Of course, but my devices' purpose isn't to grant wishes to corporations. In the ideal world they would still have no other choice. Unfortunately the more people use platforms that let them attest the execution environment the less leverage we have against them.

Re: German implementation of eIDAS will require an Apple/Google account to function

#636
post #440

Earlier quoted context omitted.

What percentage of people have a phone that is not apple or google?

Are you saying there's a threshold percentage somewhere below which you're happy to A: exclude these people from society or force them to switch to big tech, and B: accept the consequence where a single other country holds access to everyone's identity information for convenience reasons (because it works for the 99% that are too tech-illiterate to install software that they control instead of the other way around)

No, I’m not saying either of those things.

I’m simply saying people don’t have the bandwidth to object to things that don’t impact them personally

Re: German implementation of eIDAS will require an Apple/Google account to function

#637

Earlier quoted context omitted.

> as letting the user lie to apps is essential to user's agency. You do understand that in this case the user's agency has a very clear line? Tampering with an electronic identity software is not a fundamental right the same way as tampering with your ID-card or passport isn't. > [...] and in other cases they just had no choice. QED. Not that they wouldn't or didn't want to.

App attestation does not stop at legally binding identity software, and legally binding identity software can be serviced without app attestation. I accept not being able to tamper with my ID card, I may say it's "mine" but it ultimately belongs to the government; I don't accept not being able to tamper with my computers, they wouldn't belong to me anymore if that was the case. > Not that they wouldn't or didn't want…

> I accept not being able to tamper with my ID card, I may say it's "mine" but it ultimately belongs to the government; I don't accept not being able to tamper with my computers, they wouldn't belong to me anymore if that was the case.

So where does a digital ID card fit in your model? It's the government's but on your computer.

Re: German implementation of eIDAS will require an Apple/Google account to function

#638

Earlier quoted context omitted.

App attestation does not stop at legally binding identity software, and legally binding identity software can be serviced without app attestation. I accept not being able to tamper with my ID card, I may say it's "mine" but it ultimately belongs to the government; I don't accept not being able to tamper with my computers, they wouldn't belong to me anymore if that was the case. > Not that they wouldn't or didn't want…

> I accept not being able to tamper with my ID card, I may say it's "mine" but it ultimately belongs to the government; I don't accept not being able to tamper with my computers, they wouldn't belong to me anymore if that was the case. So where does a digital ID card fit in your model? It's the government's but on your computer.

I have a digital ID card on my desk right now. It does not need to be stored on the phone which has all the means necessary to communicate with the card. In fact, if it was in a slightly different form factor I could even put it physically into my phone as it happens to have a built-in smartcard reader, which would still be a more reasonable solution than apps since then it wouldn't be strongly coupled with a complex device that can break or be compromised in various ways (some of which can't be solved with attestation) and would maintain a clear separation between what's mine and what's government's. What exactly would I, as a user, gain by muddling that distinction?

Re: German implementation of eIDAS will require an Apple/Google account to function

#639

Earlier quoted context omitted.

What does it matter in practice? Do you seriously think Google, the targeted advertisement company, does not use that Telemetry for targeted advertisements?

Yes, I do seriously think that Google does not use anonymous telemetry for ad targeting.

Do you have any reason to think this? Why would Google refuse to earn more money?

Re: German implementation of eIDAS will require an Apple/Google account to function

#640

Earlier quoted context omitted.

>I' ve been issued a German identity card, which is its own computer that includes a digital identity already. Then keep using it, instead of the not-mandatory app? > I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need. Sure. In the mean time, do we tell the other few dozen millions that don't have an expensive card reader to go…

Government services are going to drop support for the old scheme the minute they start supporting the new one.

Sure, that's why they stopped receiving paper letters for tax declarations once they setup Elster.

Oh, wait, they didn't, my bad. You can still declare your taxes with good old paper. The only people that can't are self employed, and that's because they have a different set of obligations with higher demands

Post reply on HN