Live data from Hacker News

German implementation of eIDAS will require an Apple/Google account to function

bmi.usercontent.opencode.de

661–670 of 674 posts

Re: German implementation of eIDAS will require an Apple/Google account to function

#661
post #214

Earlier quoted context omitted.

German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.

Do we have stats how many germans use something else than Google Android, Samsung Knox or Apple? I recon it should be less than 1% which quite honestly is in fact „all“ citizens.

And backup software should also remove the "restore" option because hardly anyone needs that, right?

Same here, the government shouldn't build a system where two American mega-corporations have the keys to everyone's lives.

Re: German implementation of eIDAS will require an Apple/Google account to function

#662
post #148

Self Sovereign Identity (aka SSI) is the only way out of those identity sovereignty issues. It shouldn't be acceptable that your identity depends on anything or anyone. It should just be your identity. A paper or certificate can prove an entity trusts your identity to be but that shouldn't be your identity. You just are. Not your google Id, not your Apple Id either of course. Governments are lame.

You are conflating the philosophical notion of identity with functional identification in the real world. There is no cryptographic escape hatch from the social contract. >You just are/I just am Is not an acceptable thing to say to a bar tender when being served an alcoholic drink when you're 22. You hand them government issued ID.

I agree, and that government ID isn't your identity, it's just a piece of it.

I'm not arguing against government ID, I'm saying identity doesn't have to be that piece of paper, or that Google ID.

Analogy: if google ID is your primary key in your User table, then you're cooked. Instead use a uuid for the PK, and add Google ID as just another id. But the identity is the PK.

Re: German implementation of eIDAS will require an Apple/Google account to function

#663
post #163

Self Sovereign Identity (aka SSI) is the only way out of those identity sovereignty issues. It shouldn't be acceptable that your identity depends on anything or anyone. It should just be your identity. A paper or certificate can prove an entity trusts your identity to be but that shouldn't be your identity. You just are. Not your google Id, not your Apple Id either of course. Governments are lame.

> Governments are lame In 2019, the EU created an eIDAS compatible European Self-Sovereign Identity Framework (ESSIF). How is the government lame, here? We've had the infrastructure for 7 years now.

eIDAS tends to hear "our European Sovereignty" when they hear Self-Sovereign.

You can't have a government issue a Self-Sovereign identity to you, it's an oxymoron. They can only issue credentials. But then they'd feel like they're losing control, so they pervert it. Now they call it SSI but it's just digital credentials.

The very title says it all: German implementation of eIDAS will require Google or Apple ID. That's not self-sovereign identity.

And that's why I find it lame.

Re: German implementation of eIDAS will require an Apple/Google account to function

#664

Earlier quoted context omitted.

To play the devil’s advocate here: MEETS_STRONG_INTEGRITY on Android doesn’t require a Google account AFAIK. But it might change, of course. Edit: but as pointed out elsewhere in the thread, Play Integrity is not the only way to do hardware attestation on Android. GrapheneOS devs have a guide: https://grapheneos.org/articles/attestation-compatibility-gu... So avoiding proprietary Google stuff altogether is possible a…

How do you propose running Google play checks on the phone without working Google play? :) I don't think it's possible. And indeed, avoiding is possible and better, but the companies choose lie of play store "integrity".

For Play Integrity, you do have to have the Play Services installed, but that doesn’t mean you need to sign into Google :-)

(By the way, microG, an open source Google Play Services reimplementation, can achieve BASIC_INTEGRITY now, too. Which unfortunately doesn’t help much as most applications that do use Play Integrity want DEVICE_INTEGRITY at least.)

> but the companies choose lie of play store "integrity"

Agreed, very unfortunate. Most apps don’t even need it, but the security theatre is easier to do than actual security.

Re: German implementation of eIDAS will require an Apple/Google account to function

#665
post #629

Earlier quoted context omitted.

The argument here is kind of hard to follow. Who is the "owner" of the phone, "the user" is also mentioned and it is not clear if these two are the same. Is the owner of the phone in the controlling-software sense, Google, or is it the end user? Both fits, and both are commonly used. Because if it is the end user, the strong version of the argument would be as follows: The end user signs a document, baked in is an at…

> How could the attestation help here? By proving that when the user clicked "Yes, I want this loan, $X deposited on amount Y" that is actually what was on the screen then the user clicked approve. In other words, that the agreement is actually what the REMOTE party believes it is, even if the owner installed "Free coins in the bunny casino v7.0.apk" from a website. (meaning that is not currently very provable, and e…

That is indeed the question: How does attestation help with proving that?

From my limited understanding, I can immediately think of a dozen ways to implement such an attack, and none would be helped by Google attesting that the device is indeed a legitimate Android(tm) device.

It is very hard to understand how this would make any difference juridically. The technical difficulties of avoiding phishing aside, contracts can be contested for a multitude of reasons, including contracts being signed involuntarily.

Re: German implementation of eIDAS will require an Apple/Google account to function

#666
post #567

Earlier quoted context omitted.

They did. This is why Graphene works.

Call me confused. The comment I was responding to is saying something different: > The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS).

Yes, they still need to audit and whitelist the builds of GrapheneOS. That's what "standard APIs" are - they identify a build of OS, but someone still needs to make sure it's secure.

If you don't want Google to do that for you, then the app developer has to.

Re: German implementation of eIDAS will require an Apple/Google account to function

#667

Earlier quoted context omitted.

> They all are saying "to interact with us, you must use one of these two types of devices, with all the attestation and security measures intact" Are you claiming that this is the only way of interacting with particular government services, with the other ways that existed before the app no longer being available? To make situation „dystopian“ this must be the case.

That is clearly the direction, yes. First it's new and optional, then it's mature but equal, then as adoption grows further, the old way of doing things gets deprioritized and neglected, then you're a 2nd tier citizen until they finally remove it altogether. See: Essential businesses like grocery stores going cashless

Businesses are not government services and free to do whatever allowed by the law. For a country to be dystopian the government in your example must prohibit businesses to take cash.

Re: German implementation of eIDAS will require an Apple/Google account to function

#668

Earlier quoted context omitted.

Because that doesn't play to Germany's industrial and economic strengths (precision machining, metallurgy, basically the whole ICE automobile supply chain). EVs are just mechanically much simpler, with a shorter BOM that largely centers around Asian (particularly Chinese) battery, REE, and semiconductor supply chains, so hundreds of thousands of good jobs that supported Germany's industrial model are now economically…

That's the Kodak business model: New thing arrives that will disrupt the old thing, so don't build it. Problem is then someone else will build it anyway and instead of losing 2 jobs making ICE cars and getting 1.5 jobs making batteries and solar panels, you just lose the 2 jobs and get nothing, which is how Kodak went bankrupt. Also, LFP batteries don't contain rare earths.

I agree with you, generally speaking. I was being descriptive, not prescriptive.

> LFP batteries don't contain rare earths.

No, but good motors do. And probably GaN FETs to handle megawatt-class charging currents.

Re: German implementation of eIDAS will require an Apple/Google account to function

#669
post #259

Earlier quoted context omitted.

because then it will never get done. There are still people using old Nokia phones, for those there will never be a solution. The usual 80/20 rule applies here as well. And if you really are a German citizen, you know how slow the wheels of government already turn in Germany, I assume next week you would be the one complaining that "Germany is so far behind" and that "other countries are so much faster at implementin…

Nah, I'm that one idiot who uses alternative open software and just accepts when services aren't offered to me. The older I get, the easier it feels to not give a fuck anymore. Can't buy any single fare public transport tickets online here in Stuttgart? Sure, I'll use the DeutschlandTicket NFC card. Can't view the EPA? Fine then I don't. Can't pay with Wero? Fine, I don't actually need to use shops that don't offer S…

You are not alone.

Re: German implementation of eIDAS will require an Apple/Google account to function

#670

Earlier quoted context omitted.

It will be possible but simply won't be done. And as of now it won't work on GrapheneOS, it doesn't pass anything except MEETS_BASIC_INTEGRITY

That’s not what the parent wrote though. And why is it so bad that they start with a smaller subset of feature and target the 99% of the population using either google or apple?

This is a misleading way to put it.

Re: Android.

Goggle can supports AOSP attestation like any other vendor who wants to support it. They invented it.

So instead of immediately locking down everyone using android to ONLY Google-dependent method, I'd developers could go the vendor agnostic way, but consciously decided not to.

It's untrue to claim that supporting AOSP attestation only serves GrapheneOS and leaves out everyone using Google-surveiled handset.

Nb, mixing it up with Apple is a conscious way to further the false claim, and I believe it's not accidental since these ecosystems are naturally completely separate.

Post reply on HN