14 ms·
Source code for Dutch DigiD app released under Dutch Open Government Act
- kf 4y agoExample: https://imgur.com/a/9cIDQtk https://imgur.com/a/9cIDQtk
- jpnc 4y agoIs this literate programming?
- sam_lowry_ 4y agoIt's been extensively discussed on twitter, and the general conclusion seems to be that yes, this particular snippet is good code.
- Freak_NL 4y agoThe only thing that jumps out at me is this: if (percentage == 0) return […]; if (percentage > 0.0 && […] Can a double have a value that is larger than 0 but smaller or equal to 0.0? I would have expected '> 0' instead.
- kadoban 4y agoIn any language I can think of, 0 and 0.0 are the same, once you're comparing them against a double.
- DoingIsLearning 4y agoTechnically what is happening behind the scenes is that for most languages the compiler/interpreter will promote the integer to a double to avoid foot guns. Nevertheless integer comparisons with any kind of floating point is not a wise choice. The idiomatic way to compare a double would be to take into account whatever is the double precision epsilon for that language. Or just use the greater/less than like they have in the subsequent if statements in the original code snippet.
- LudwigNagasena 4y agoDiscussed by whom? By people who deem every non-built-in data structure as "too clever" for maintenance?
- geraldwhen 4y agoIt’s not, though. To confirm the method works you need to check every single comparison operator and value to ensure the range is bounded correctly. It’s code that stops you in your tracks. Pull request denied.
- icoder 4y agoIf that's the intended behaviour (having those boundaries and those results), how can you ever confirm that behaviour without checking them all?
- doodlesdev 4y agoYou could have one check such as if(percentage < 0 or percentage > 1) { // Throw error here } Also the checks in the if statements in the linked code are redundant since they simply disregard the previous check, they could simply check if percentage < x instead of checking it's within a range sincs the previous check already proved percentage to be > x - 1/10. To be fair though, this is the kind of code where "if it's stupid and it works, it's not stupid" applies perfectly. While I would make these changes if I had to approve a PR I wouldn't change this in a live codebase just for refactoring purposes, specially because there are better ways to show progress to a user than using Unicode characters, which I think is the real smell here.
- yread 4y agoI like it. Easy to understand, fast, no allocations.
- kwhitefoot 4y agoIt has almost twice as many comparisons as necessary. The term to the left of each AND is redundant because it has already been checked by the preceding IF. It also does not guard against negative arguments. Perhaps the environment in which it is used guarantees that negative arguments cannot occur. If I were reviewing this code I would at least ask the developer to add an assertion or contract requiring that the argument be in the inclusive range [0..1] The choice of variable name, percentage, is also misleading. At least I suspect it is because I would expect the comparisons involving percentages to be to numbers between 0 and 100. If lack of allocations is a requirement then one could create a static array of strings and use int(percent * 10) as the index. This would eliminate all of the comparisons and also throw an index out of range (in any sane language) if the value was outside the allowed range.
- Luc 4y agoYou know it's only a matter of time before someone dissects each one of your objections. In fact you could do so yourself with a bit of a wider perspective.
- kwhitefoot 4y agoHow long do I need to wait?
- dayvan 4y agoI think they're all great suggestions (albeit for such a tiny, irrelevant piece of code). The only problem I can think of is that the given code rounds up, but your suggestion of `int(percent * 10)` rounds down.
- Luc 4y agoIt's just too obvious. The metrics you're optimizing for don't matter to any of the stakeholders.
- pelorat 4y agoI'm triggered by the lack of brackets after every if-expression. Sure it looks nicer this way but the default Visual Studio code style settings will complain if you don't do it, hence I'm used to it.
- lucumo 4y agoI've started to remove them from my own code. It's widely mentioned as The Right Way, but I feel the reasons why are obsolete. The stated reason is always that you could forget to add braces when adding a second statement. That was useful in a time where a text editor was "smart" when it copied your indentation to a new line. But nowadays any tooling will warn you when indentation doesn't match the bracing. The odds of people making that mistake has gone so far down, that the risk is no longer worth the reduced readability.
- googlryas 4y agoYou don't know what tooling anyone editing your code is using though.
- Thiez 4y agoIf you enforce correct formatting before commits or in your CI builds that is no longer a problem.
- kwhitefoot 4y agoThat's a big if though.
- rsynnott 4y agoI vaguely suspect that this is a product of the sort of environment where you have to fill out a form in triplicate to get the static analyser to let you concatenate strings (which, to be clear, may not be inappropriate for something like this). I do object to the variable being called ‘percentage’ tho, as it clearly isn't one.
- doodlesdev 4y agoI have no idea where all of you got the idea that percentages go up to 100. It's in the name: PER centage, meaning x/100 [0]. For instance if you want 20% that could also be expressed as a fraction such as 20/100, which turns out is the same as 2/10 or 0.2. I do think they should remove the redundant statements in the conditions and also have an assertion that guarantees percentage to be [0, 1]. > The term "percent" is derived from the Latin per centum, meaning "hundred" or "by the hundred". The sign for "percent" evolved by gradual contraction of the Italian term per cento, meaning "for a hundred". The "per" was often abbreviated as "p."—eventually disappeared entirely. The "cento" was contracted to two circles separated by a horizontal line, from which the modern "%" symbol is derived. This might be a little more obvious for me since my first language is derived from Latin, but anyhow it still keeps the meaning in english. [0]: https://en.m.wikipedia.org/wiki/Percentage https://en.m.wikipedia.org/wiki/Percentage
- rsynnott 4y ago20 percent means, literally, 20 per hundred; it's equivalent to 0.2 or 2/10 or 1/5 or whatever, of course, but if `percentage==0.2` then that fairly clearly, on the face of it, should mean "0.2 per hundred", ie 0.2% or 0.002.
- doodlesdev 4y agoIt really shouldn't. 20% means _literally_ 20 / 100 so if you need to express that numerically (as you do in code since % is reserved for modulo) you write that as 0.2. That is still a percentage, just in numerical decimal form instead of in the form of a fraction, the value is exactly the same and it didn't stop being a percentage. If I write 0.2 in a piece of paper and give it to someone and tell them that's a percentage it should be pretty obvious that means it's 20%. If you do the same but you write 0.2% then of course it's 0.2%. If they really wanted to they could've written the comparison using the numbers as fractions in the comparisons such as percentage < 10/100 which would be perfectly reasonable, but again, that resolves to 0.1, so you might as well right it in decimal form already.
- c7DJTLrn 4y agoIt's pretty pathetic how many people feel the need to dunk on this bit of code just because it's not how they would write it. There's nothing really wrong with it. I'm sure the author was aware of alternative, perhaps more concise solutions using a string builder but they chose to be clear instead. So many big egos in software.
- doodlesdev 4y agoI'm pretty sure they weren't because of the redundant conditionals which simply defy logic. If there was only one check for every if statement, honestly I could give this a pass since it's at the very least simple, but by adding one extra redundant check for every statement you just created 9 new places where a bug could appear. Furthermore, using Unicode characters to represent progress is the true smell here. There simply are better ways to do this. In the grand scheme of things, does it matter? No. But this is Hacker News LOL, someone has to discuss it.
- jeroenhd 4y agoIf I had to show a progress bar for less than a second in a screen the user will only open up once per 10 years (it's NFC code for scanning passports/ID cards), I wouldn't bother writing a reusable custom progress bar component either. Sure, you can do it better, but why would you? There are other, more pressing issues in this code (that probably also don't warrant spending extra time on refactoring). Those redundant checks are highlighted in every IDE I can think of. I can only assume they're there for readability.
- arp242 4y agoI mean, if this is the worst code people can come up with then it's better than most codebases I've had to deal with at $dayjob.
- Am4TIfIsER0ppos 4y agoQuestion: can you modify, compile, and run that code and still have it work for the same uses?
- debarshri 4y agoI dont think self complied version would work with service like belasting etc. I did not look in depth, but the source code would reveal how thing are getting encrypted and business flows but not the data. That is in the digid's infrastructure
- contravariant 4y agoThey explicitly say it's not intended for reuse, and various stuff has been redacted (though I've not identified any that would stop the code from working). Interestingly you are allowed to reuse the code under the EUPL license.
- WhyNotHugo 4y agoIt would seem so: https://github.com/MinBZK/woo-besluit-broncode-digid-app/blob/master/LICENSES/EUPL-1.2-EN.txt https://github.com/MinBZK/woo-besluit-broncode-digid-app/blo... The interesting aspect of this is that it can be studied to write clients for platforms that are not officially supported -- currently, only Android and iOS are supported, but it'd be great to see a Linux client too. It's a big shame that history has been rewritten and heavily redacted though. Version control history often has a lot of contextual information that's not immediately obvious in the source code itself.
- amelius 4y agoI'm still hoping for practical iOS and Android emulators to appear at some point.
- fudgefactorfive 4y agoIt appears any important strings have been replaced with 'S' characters. So you definitely can't use this unless you pull the strings from the compiled APK theyve published.
- throwaway71271 4y agoIn order to verify your ID with the app your phone must have NFC support to scan the passport/id, and on the screen where you do the verification it says: if your phone doesnt have support find a friend with a phone that supports it, I kid you not.. edit, found it in the code: https://github.com/MinBZK/woo-besluit-broncode-digid-app/blob/master/Source/DIG-Common/Source/DigiD.Common/AppResources.en.Designer.cs#L2093 https://github.com/MinBZK/woo-besluit-broncode-digid-app/blo...
- dessant 4y agoAccess to a smartphone with NFC can indeed be an issue for some people, but it is still better than having to record videos of yourself holding your ID next to your face, then a couple of years later finding out that your personal data is freely circulating on the web because one of those sleezy identity verification services has been hacked.
- eptcyka 4y agoDoesn't Apple block NFC support? Or do they allow peasant apps to read via NFC?
- Traubenfuchs 4y agoApple iOS supportss NFC. https://developer.apple.com/documentation/corenfc https://developer.apple.com/documentation/corenfc
- eptcyka 4y agoThat's nice, I was under the impression only ApplePay had access to read and write data via NFC. Still no ability to write arbitrary data via NFC, but for the purposes of this app that's good enough.
- rsynnott 4y agoThat was the case for a while, but they've allowed other stuff for a bit now. I've been topping up my public transport smartcard with my phone for, er, three or four years now, I think.
- dr_dshiv 4y agoIt’s a great app. I mean, there can be challenges, but generally extremely effective. I suppose openness will enhance security over time?
- jeroenhd 4y agoThe company making this clearly doesn't want to open up development, this code was released because the government was forced to. They stripped the commit history and some hard coded details and I don't think they'll develop on this repo either. Some extra eyes on the current code might fix some small issues, but I doubt this is going to improve the app much.
- gagabity 4y ago.Net cross platform!
- vips7L 4y agoOne runtime to rule them all.
- matsemann 4y agoThe Norwegian welfare agency publish most of their code on github: https://github.com/navikt/ https://github.com/navikt/ It's the organization you use if you're sick, lost your job, where you get your social security etc. Basically a huge behemoth of all kinds of social or labor services. While most of the code probably has little value for others (2000 different repos), I think it's quite noble that it's public, given it's made with tax payer money and serves our people. And when working there I found it quite cool to work in the open, a sense of pride in publishing everything we were doing. Also a bit funny, just checked the project I started 5 years ago: "last updated 42 minutes ago".
- gunnihinn 4y agoIceland does the same: https://github.com/island-is/island.is https://github.com/island-is/island.is
- argulane 4y agoQuite similar to Estonia. Tho they run their own Gitlab instance https://koodivaramu.eesti.ee/explore https://koodivaramu.eesti.ee/explore And not everything is there. ID Card software is hosted on Github https://github.com/open-eid https://github.com/open-eid
- dx034 4y agoI think all countries should use their own instances of gitlab or others. It feels wrong that they all depend on GitHub to publish such important information.
- nixpulvis 4y agoJust curious, since it's been a dream of mine to have public services powered by open software: How often do bugs in the services get reported either, with direct references to the underlying software (function names, line numbers, etc.), or as changesets/PRs with proposal fixes? Especially for simpler things like style/accessibility issues, I could see this being somewhat common honestly.
- cloudify 4y agoItaly does the same: https://github.com/pagopa/io-app https://github.com/pagopa/io-app This is the official government app (you can get benefits, pay taxes, etc...), downloaded by 30+ million citizens, stack is React Native + Typescript
- college_physics 4y agomaybe EU countries could save a bundle and co-develop these apps. might also improve quality / ensure best practises are available to all etc.
- simne 4y agoThis is not for co-develop. This is mainly report, of what government done. For some extent it could be used to check safety of software/infrastructure. For example, in Ukraine used closed source software, and only war (because censorship), slightly slowed stream of scandal publications about bugs and vulnerabilities.
- rb666 4y agoStealthy dig at the European military acquisition strategy :)
- reacharavindh 4y agoThis is the baffling side of the EU to all outsiders/newcomers. When I first moved here, that was my first thought as well. There is just so much in common, why repeat everything everywhere instead of single effort with branches everywhere?! (police force, consular services, Identity services, and pretty much any Government paperwork one can think of, transportation services etc). However, the population is very localised and divided. The French do it their way, Italians another way, the Germans on their own way etc. It is hard to find gain common ground beyond what EU already represents(which is very good IMO). I do wish doing things at EU level becomes the norm, and individualities slowly disappear. Imagine a single European rail service (not Euro rail where you can buy a single ticket that will make you take Dutch train, and then connect on a German train, and then on an Austrian train, and if you miss a connection, good luck figuring out your replacement..)
- lucumo 4y agoI find the DigiD app to be one of the most annoying implementations of 2FA out there. You have to unlock the app with a pin code, then enter an app-generated code on the site, then scan a QR with the app, and then grant permission to login to that site. If you compare that to 2FA for Office 365 for example, where you just have a push notification where you press a button to allow, then you can't help but think that some attention to UX would be helpful. As it is, I usually pick SMS verification instead of using the app. Yes, less secure, but so much easier.
- Kaotique 4y agoI have dozens of 2FA codes now that requires searching for the correct one and I have to store backup codes in physical form. Which probably a lot of people keep unencrypted on their desktop somewhere. With the Digid app you just need to remember the pin code or unlock with face id. The app generates the codes for each login and then you just scan the QR. It's very simple to use. Recently I lost my phone and had to set everything up again. I had to start digging for 2fa backup codes, but Digid I could easily set up again using the NFC chip in my passport.
- teekert 4y agoIt's slightly easier on-device (where the app runs), still try opening your government messages inbox, that takes 5 taps/screens/faceID and a code. It always works though, and one does not use it very often. I do appreciate that they keep is so secure (or perhaps I should say, not logged in by default). It works well in general imho.
- dr_dshiv 4y agoOn mobile, you just use pin. So easy! On desktop, you use pin, type code, then scan. I find the flow quite smooth.
- lucumo 4y ago> On desktop, you use pin, type code, then scan. I find the flow quite smooth. I find the constant back and forth between devices annoying. 2FA is already annoying because you have to switch from desktop to mobile and back, but that can't be helped. There's no need to make it 6 times, though: desktop (on site) -> mobile (start app + pin) -> desktop (fill in code) -> mobile (get camera) -> desktop (scan QR) -> mobile (press allow) -> desktop (continue on site) That's just being irritating.
- BasedInfra 4y agoThere’s a lot of gov.uk stuff open source. - https://github.com/alphagov https://github.com/alphagov - https://github.com/hmrc https://github.com/hmrc - https://github.com/dwp https://github.com/dwp
- belter 4y ago"...This code has been disclosed in response to a request under the Dutch Open Government Act ("Wet open Overheid")..."' Sounds like it was not voluntary. Also not sure what kind of transparency is expected here, since there is no way to find if the source code published is the same used to build the app. Maybe decompilation is the way to go...
- noirscape 4y agoIt's semi-voluntary; the request to open source the application came from the Dutch congress/2nd chamber if I recall, but took a while due to private information leaking concerns.
- radicalbyte 4y agoIt was released as the result of a Freedom of Information (WOO/WOB) request made by serial "WOBBER/WOOOER" @BugBlauw, check his twitter (use google translate, works well with Dutch). https://twitter.com/bugblauw https://twitter.com/bugblauw
- 0daym 4y agoC# ?? How is an app written in C#?
- ClassyJacket 4y agoXamarin?
- melvinmelih 4y agoThis function is interesting: https://twitter.com/jeroenfrijters/status/1615204074588180481 https://twitter.com/jeroenfrijters/status/161520407458818048...
- seydor 4y agoLLMs can do better
- eugenekolo 4y agoThis one's pretty fancy from the big GPT. ``` Here is an example of Python code that can print a loading bar at different completion percentages: def print_loading_bar(percent): bar_length = 20 hashes = '#' * int(percent * bar_length / 100) spaces = ' ' * (bar_length - len(hashes)) print(f'\rLoading... [{hashes}{spaces}] {percent}%', end='') for i in range(101): print_loading_bar(i) time.sleep(0.1) ```
- tgv 4y agoShould be C#, though, and for just 11 steps.
- jpcrs 4y agoI don't know why so many people are saying that this is bad code. Besides the redundant checks, it's really simple, so simple that an intern, maybe even someone who doesn't code, can understand and update it. It's performant, most compilers will cache the strings. People trying to justify more complex one-liners with "what if you change the symbol, or just show 5 characters" etc. These scenarios wouldn't take more than 5 minutes to adapt this code, and anyone could do it. For me, this code with a good set of tests doesn't get much better.
- jeroenhd 4y agoIt's easy to read, simple to maintain, and performant code. Maybe one of those newer switch expressions would make the code even clearer, but they already left the redundant lower bound checks in so I think the way this looks is quite intentional. Much easier to read than `int count = (int)Math.Floor(percentage / 10); return new String("#", count) + new String("-", 10 - count));` in my opinion and not worth writing a custom progress component for.
- wdb 4y agoAs a Dutch person this is the only bit I was never able to get/register for since it got introduced. Requested it since like 2003/2004 or something.
- yurishimo 4y agoDo you live in Nederland still? You can request the verification via post instead of using your passport. If you lose your DigiD login, you can also create/request another. The account acts as a pointer to your official ID. My wife made a mistake and had to attempt the process 3 times. Not a problem.
- Aeolun 4y agoLiving overseas it took them several yesrs to realize that making a trip to an embassy overseas just to get a registration code was not a feasible way. Luckily Corona made them realize you can also do it over a Skype call.
- yurishimo 4y agoSpeaking as an immigrant from America, I really like DigiD! I wish the US had something even remotely similar. The fact that we do not have a standardized national ID easily available to everyone is embarrassing. DigiD has some minor annoyances, but it's a helluva lot better than some alternatives I could think of.
- vinay427 4y ago> The fact that we do not have a standardized national ID easily available to everyone is embarrassing. Why? I’ve lived in a European country with common national IDs, in the US, and in a European country without national IDs, and I’m not sure that the absence of it is “embarrassing.” Note that in most European countries it’s an identifier of citizenship, not residence, with other ID cards such as residence permits, drivers licenses, or municipal registrations indicating residence. Therefore, it’s far from sufficient for many common use cases that depend on residence, and the countries that don’t have one such as the US or the UK typically use passports (or ad-hoc solutions such as US/Canada enhanced drivers licenses) for travel. I agree that digital IDs can be very useful.
- pionar 4y ago> The fact that we do not have a standardized national ID easily available to everyone is embarrassing. Surely that's hyperbole. State IDs are pretty standardized, and even more so with the REAL ID system (if the mandates for it ever go into effect). When have you ever had a problem using one state's ID in another state?
- yurishimo 4y agoIt makes coordinating your information across many different service providers much more efficient. Here in the Netherlands for example, I can use DigiD to login and pay my taxes, pay for health insurance with a private company, authenticate to my pension plan and a ton of other things. I cant vote with my Texas ID in Wyoming. A passport might be sufficient to vote in a different state for a national election but I’m admit that I’m not 100% sure on that. Every government agency in the US doesn’t know who I am without me telling them. And even then if they fat finger the number I could be in for a world of hurt until someone realizes.
- timwaagh 4y agoGreat so now we can be sure some hacker working at an intelligence agency or criminal syndicate reads this and now knows how to hack DigiD, which is basically the Dutch government's SSO. After you get in you can do all kinds of things like apply for student loans, passport taxes etc. There will be another layer of security but still.. this is not great. Don't get me wrong I am not against publishing source code but they ought to think about what they publish.
- radicalbyte 4y agoIt's the frontend app. Even script kiddies can download it from the Play Store and decompile it.
- pieter_mj 4y agoThere was a request (foia/woo) made to obtain source code for frontend and backend. The latter is still being considered to be released as well.
- radicalbyte 4y agoI know, that will take some time though as it will need multiple deep reviews before it's released (as it's critical infrastructure and releasing it will increase the visibility). Overall this will improve the security of the system, if only from the people I've seen offer their time (for nothing!) to ensure that this process is a success.
- timwaagh 4y agoBut now they have more information. Comments. Variable names. Decompiled code is difficult to read.
- Aeolun 4y agoSo now we’ll know if it’s _actually_ secure. This is a good thing as far as I’m concerned. Trusting it’s safe because you don’t know if its not sounds like a bad idea.
- 4y ago
- seanw444 4y agoThis is one thing I wish the US government did more of. One of the few things I can envy about Europeans. It's taxpayer money, so let us see.
- gbraad 4y agoWhy not host on their own Gitlab of Forgejo/Gitea server? Has all to do with trust and ownership. Now it feels like a mere dump...