17 ms·
German implementation of eIDAS will require an Apple/Google account to function
- NooneAtAll3 6mo agowhat's eIDAS?
- ezfe 6mo agohttps://en.wikipedia.org/wiki/EIDAS https://en.wikipedia.org/wiki/EIDAS electronic IDentification, Authentication and trust Services
- whizzter 6mo agoEU digital identity law to make inter-EU signatures (And authentication) work. As an example, an EU citizen working in Sweden should be able to submit Swedish tax forms whilst living here by using a digital identity from the originating nation. There are also some standards in place like ETSI standardized extensions to PDF signatures so that you can verify that a signature inside the PDF was actually signed by a specific physical person (the standard is there but it's not fully used throughout the EU yet due to some legacies). Implementation is a bit of a mess still but things are converging.
- stefan_ 6mo agoThe gold standard for digital signatures today is - someone sends you a docusign link - you sign up with your email - you sign with your name in a cutesy font Theres a dispute? Well it was going to end up in court no matter how you signed it anyway. This has all the hallmarks of a design by committee project by people whose salary is paid regardless of demonstrating market fit, productivity, usage, plain sensibleness...
- bossyTeacher 6mo ago> Theres a dispute? Well it was going to end up in court no matter how you signed it anyway. The fact that it's ALWAYS a docusign is the ridiculous part. It is just a glorified where you enter your name and email. No need to pretend otherwise. Any other service would be just as good. This is basic human sheep-like behavior?
- martimarkov 6mo agoCan I use Docusign to provide my identity in Estonia online via my phone when I move there to buy a SIM card or open a bank account or file a document with the local authority? Can I also send the Docusign document via Signal without Docusign knowing the person who signs it? Because that is what the eIDAS is supposed to deliver on top of cryptographic validation of signatures.
- alfiedotwtf 6mo agoMade me laugh then cry. I’m willing to bet your comment still stands in 2030 unless someone like Apple allows FaceID to be used to sign too (this seems like an obvious and easy thing to do as they already got more than half of the infrastructure in place)
- functional_dev 6mo agoFunny part is that the real infra behind digital signatures is insanely serious compared to DocuSing "cutesy font".. I did not know that root CA keys are generated in faraday cages?? Multiple custodians persent, then kept in tamper proof vaults. I had no idea until I saw this visual breakdown - https://vectree.io/c/public-key-infrastructure-pki-and-certificate-authority-chain-of-trust https://vectree.io/c/public-key-infrastructure-pki-and-certi...
- mzajc 6mo agoIs there a reason this user-hostile mess is preferred over an X.509 certificate (besides big tech lobbying)? Slovenia hands out certificates for online government services, including document signing, and it seems to be going fine, with the added benefit that Google can't take away my access.
- Maken 6mo agoeIDAS is about making the electronic IDs emitted by the different EU governments intercompatible, so you can use a Slovenian certificate to authenticate into the German tax system, if you want to.
- sfjailbird 6mo agoMost people wouldn't know what to do with a certificate, so governments build some stuff on top (like an official mobile app) which makes auth easier. It's usually just certificates underneath (not exposed to the user). Eidas tries to harmonize these implementations across EU member states.
- whizzter 6mo agoIn the end it's mostly x509 certificates, an ETSI pADES PDF signature for example contains the signing x509 certificate (ETSI specifies extension OID's to the x509 certificates to contain personal numbers, country, etc). The big question is how to let users properly handle their certificates so they won't get abused into being useless. If I understood it correctly, the German current Ausweissapp seems to require NFC to read it from your personal id card together with a PIN code you got with the card, it's not entirely user-friendly since aligning the card with your phone seems to be prickly. Swedish BankID handles it internally in their app (unlocked via PIN's) but they don't have a good way to use it to sign things (It all relies on the infrastructure even if they give out signature documents it's not compatible with pADES). There's a new govt sponsored one that I assume will piggyback on the personal cards/passes that are readable via NFC. Norway and Denmark iirc supports proper signatures but I don't think the certificates are under user control (someone correct me if I'm wrong here). Now these things are mostly issues for document signatures, authentication is often handled via other flows. What I skimmed from the article, it seems to be more in line with Swedish BankID and is actually fairly smooth for end users even if less secure than what they have now with Ausweissapp.
- lucb1e 6mo ago> inter-EU signatures I assume this should be "intra-EU"? I'm not very familiar with eidas so I'm not sure, but afaik it's about signatures within the EU, not between different EUs (as there is only one in this world). (I hate this inter/intra wording, always have to translate it in my head to understand whether it's like internet (between networks) or like intranet (within a network). Would recommend using "within-" instead of intra whenever it's not already a well-established word, like intranet)
- whizzter 6mo agoYes of course, a bit tired here since it's nighttime.
- ResearchAtPlay 6mo agoDo you happen to know if German citizens can obtain a certificate to sign PDFs (from the government / for free)? Several paid providers for X.509 certificates exist but document signing certificates cost around 80 € per year [0]. And if I want duplicate X.509 certificates for my redundant Yubikeys then the cost doubles. Other providers require an initial deposit and then charge per signature [1], which leads to intransparent pricing. In the interest of open commerce, I strongly believe that securely signing an electronic document should cost the same as my manual signature, i.e. nothing. A partial solution already exists because I can use my electronic ID card with the AusweisApp to prove my identity when interacting with German authorities. This feature is generally useful because I live outside of the EU, but I especially appreciate that I can have my OpenPGP key signed by Governikus (a government provider) to prove the key belongs to my name [2]. Technically, I should be able to use my certified PGP key to sign documents, but in practice most non techies don't know how to validate my signature. For the average user opening my signed PDF in Adobe Reader, I would need an X.509 certificate from a trusted Certificate Authority for users to see the green check mark. [0] https://shop.certum.eu/documentsigning-certifcates.html https://shop.certum.eu/documentsigning-certifcates.html [1] https://www.entrust.com/products/electronic-digital-signing https://www.entrust.com/products/electronic-digital-signing [2] https://pgp.governikus.de/wizard/requirements https://pgp.governikus.de/wizard/requirements
- nickslaughter02 6mo agoA mistake.
- stefan_ 6mo agoSo what was the point of putting a crypto chip into every ID if you are gonna try and reinvent the entire trusted environment in the fucking smartphone?
- mr_toad 6mo agoID cards don’t connect to the internet. These days an ID system that doesn’t work online is next to useless.
- haagch 6mo agoIt's an NFC card that can be read with any NFC card reader, USB or smartphone based. https://www.ausweisapp.bund.de/en/open-source https://www.ausweisapp.bund.de/en/open-source I just saw that it's available in alpine. So I tried installing it on my postmarketOS smartphone and it runs out of the box: https://i.imgur.com/nRIAyrq.png https://i.imgur.com/nRIAyrq.png My Shift6mq is listed has not having NFC support in postmarketOS, so I can't actually test it, but I assume the USB card reader option will work once it's supported.
- jml7c5 6mo agoIs the link broken for anyone else? I'm getting ERR_CONNECTION_CLOSED.
- lucb1e 6mo agoWorks for me in Germany. I wonder if it's some overzealous bot protection that's cutting off humans again, in this case from what looks like a government website, but without further testing that's hard to say. You could check if it works from another network, or if other people on your network range have the same issue (like if you're in 13.37.0.0/16 then maybe someone else at the ISP is also in that range and could check if it got blocked outright)
- lta 6mo agoThat sounds like a very smart move at the time where Europe realize the US isn't such a gray partner and it's trying to reduce it's critical dependencies on foreign nations tech and infra. Good job. I'm actually very surprised to see this from the germans who have this reputation of great engineering culture
- iknowstuff 6mo agoNot in software. German software is awful. Think german cars, banks, telecoms etc
- newsicanuse 6mo agoWhile I agree, it'd be hard to say that SAP is not good
- zelphirkalt 6mo agoSAP software is the bane of most people, who have to use it, except for expensive consultants, who make bank preying on hapless clueless companies opting to use SAP software.
- c0balt 6mo agoAs someone who has experienced a Migration to SAP, no it is quite hard to say it is good. Doesn't work on mobile (unless you toggle on "desktop" mode, at which point if kinda works), is slower than the preceding PHP solution and generally functions like a POS. Other SAP implementations did not seem to behave much better. They might have some great software _somewhere_ but I have yet to see it.
- gpvos 6mo ago[citation needed]
- herbst 6mo agoStrong =! Good
- 6mo ago
- livvy 6mo agoCan anyone point me to where in the MDVN page it mentions requiring Apple and Google account? Thanks
- weikju 6mo agoBecause the attestations will only work on iOS and Google Play integrity attested devices. Meaning Apple and Google accounts required.
- livvy 6mo agoThis is an assumption, but not confirmed.
- AppAttestationz 6mo agoI spent months designing a system, exactly like this. An account is not needed, at least for Apple. Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through the Play Store. Indirectly, requiring a Google account.
- blitzar 6mo agoA phone is also required then?
- raphman 6mo agoMastodon thread on this topic: https://mastodon.social/@pojntfx/116345677794218793 https://mastodon.social/@pojntfx/116345677794218793 See also this issue from 2025 where the developers responded: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-development-documentation-public/-/issues/2 https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen... AFAICT, there is no mention of an Apple or Google account being required in general - the documentation just lists "signals" that are used to securely authenticate a person - such as Google's/Apple's security ecosystems. I am not sure what this means in practice. Can anybody with deeper understanding explain the actual implications and possible outcomes? (Note: BMI is the German Federal Ministry for the Interior)
- pojntfx 6mo agoHey, Fel from the fedi thread here Explanation: https://mastodon.social/@pojntfx/116345725515845020 https://mastodon.social/@pojntfx/116345725515845020 There is in practice no known way around it for now, and even less so one for regular people, to use this on a device without a Google account
- zb3 6mo ago> threats: > unknown system image (e.g. custom ROM) Oh no, what a horrible crime, somebody dared to modify operating system on their own device..
- AppAttestationz 6mo agoThe title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used. An alternative option, would be to use the Hardware Attestation API directly, GrapheneOS would be thanking you. I've spent a good amount of time implementing exactly this type of system for a backup service. his document specifies a way to cryptographically attest the integrity of a HTTP request hitting a server. The attestation proves the request came from a device and attest the legitimacy of the bootloader, OS and app. Google and Apple are in a privileged position to be able to bypass the app attestation though, so depending on the threat model, it's not bulletproof. edit: Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through the Play Store. Indirectly, requiring a Google account.
- bossyTeacher 6mo ago> App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed. To me, there is no difference between your sentences. You require the blessing of an American company to be able use eIDAS. Google has the power to disable eIDAS at a national scale by making the attestation services treat all devices as not certified. There should be NO reliance whatsoever on a private company not under the control (direct or indirect) of the government let alone a foreign private company. Edit: I just noticed your username and the fact that your account is very new. Are you astroturfing?
- AppAttestationz 6mo agoI agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in pure technical & UX terms, you don't need to be logged in.
- bossyTeacher 6mo ago[flagged]
- AlBugdy 6mo agoAll these requirements for specific hardware and software are ridiculous. Let every citizen use whatever computer they want. It should be up to the user to secure themselves. Authentication should only require a password or a key pair. If the user wants more security, they can set up TOTP or buy a security dongle or something. It's also ridiculous how it seems we've forgotten computers other than smartphones exist and that not everyone even has a smartphone, let alone with an Apple or Google account.
- direwolf20 6mo ago> let every citizen use whatever computer they want. That's just not possible, or should the system be legally required to run on an Apple II?
- seba_dos1 6mo agoIt should be legally required to provide enough interoperation capabilities for a compatible frontend to be written for an Apple II by whoever would like to do that, as the government can't be expected to write and maintain clients for every platform that's now in existence or that will be created in future. If only currently popular platforms are to be supported, how could a new platform join them in the future if the use of existing ones is mandated by governments?
- Avamander 6mo ago> If only currently popular platforms are to be supported, how could a new platform join them in the future if the use of existing ones is mandated by governments? The viable solution for that is to provide a trusted hardware implementation that can be used with any computing platform that has a documented interface. It can't be a software-only implementation, basically.
- vslira 6mo agoGlad you mentioned this possibility Countries have centuries of experience providing attestation services through notaries. Germany is even infamous for requiring them for things that would sound ridiculous even in Brazil (both movie and country) I can’t see why governments couldn’t incorporate this existing infrastructure into the digital world. Make them sell hardware ID wallets, enforce the real identity owner to be present to invalidate a previous ID or whatever, and add legal restrictions for the government not be able to alter these registries
- cebert 6mo agoI am shocked that there isn’t more opposition from the general public to policies like this that erode privacy and freedom. I am a parent and can appreciate the need to control what children do on the internet, but at some point parents need to parent. I fear we’re giving up a lot of freedom and adding unneeded complexity under the guise of keeping children safe.
- Ardon 6mo agoAs far as I can tell, people are getting blitzed. People I know are incredibly deep in their personalized bubble and genuinely aren't even hearing about it. It's genuinely distressing. In general and for the future of democracy.
- whilenot-dev 6mo agoIt feels like this era of hyper-individualism requires too much attention from each individual and favors those that can afford to outsource the work. While that stabilizes the role of society as a system, I feel like this is most worrisome for the less privileged in any low-trust environment.
- gmerc 6mo agoGermany is distracted with its version of “the gun debate” aka speed limits. Like every school shooting, every energy crisis brings opportunity to saturate the airwaves with shallow noise that gets people overly upset and they’ll ignore everything else. Every player on both sides is abusing this mechanic for all eternity.
- AnthonyMouse 6mo ago> every energy crisis brings opportunity to saturate the airwaves with shallow noise that gets people overly upset and they’ll ignore everything else. At least their version has an obvious solution: Make electric cars and solar panels and then stop having oil problems.
- 6mo ago
- chmod775 6mo agoThey're taking feedback here: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-development-documentation-public/-/issues?sort=created_date&state=opened&first_page_size=100 https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...
- lucb1e 6mo agoSource? You're linking to a bugtracker. I doubt they're inviting people to spam it with duplicate entries — valid as I think the concern is. But maybe it says somewhere that you can leave feedback here and I just haven't seen it?
- chmod775 6mo agoThey are taking feedback there and also have already responded to some of it. From their README: > We are interested to receive feedback on all aspects described in the document. To provide feedback, please file an Issue on OpenCoDE. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-development-documentation-public https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...
- dolmen 6mo agoThere is a 8 months old open ticket, with an official answer, here: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-development-documentation-public/-/issues/2 https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...
- lucb1e 6mo agoYes, hence me saying duplicate above
- 0x_rs 6mo agoDoes this mean sanctioned individuals, such as those in the International Criminal Court, would be unable to access eIDAS, among other things? As it requires, from my understanding, installing app(s) from the play store, thus requiring an account there and being able to access it, which isn't happening if you're among those or really, in any group that might get the same treatment in the future.
- iamnothere 6mo agoIf an account is required, then yes. Good catch. This may not be unwelcome for authorities considering the recent extrajudicial “unpersoning” of many political enemies in the EU.
- comex 6mo agoIt definitely would be unwelcome for EU authorities in cases like the recent US sanctions against ICC officials.
- OgsyedIE 6mo agoNot to mention the German debanking and account closing of a few middle eastern journalists living in Germany, their spouses and in one case their children.
- iamnothere 6mo agoFair... they should think about this then
- raverbashing 6mo agoYes? I don't think it's a bad idea though. If only for bringing the issue to the public And while I do think an alternative would be good, the fact is that protecting the private key is the most important part (for example by keeping it on a smartcard with NFD) - hence why the need for a secure device "but I want to install alternative Android etc etc" yes that's fine - but you know this is a non-secure-(enough) env.
- rkagerer 6mo agoThat headline doesn't match the article at all. Can someone elaborate/confirm this really is the case?
- shevy-java 6mo agoSo much for Europe to decouple from orange-man country ... It is so clear how lobbyists operate here. I'd call it undermining national sovereignty.
- chvid 6mo agoThe Danish MitId also only runs on Google and Apple devices. No alternative phone platforms are supported including open source Android. If you don’t have an iPhone or an android, you can get a physical one time password device.
- tomjen3 6mo agoYou can get that anyway, and you should because 2 is 1 and 1 is none.
- spragl 6mo agoYou can get that, even if you have a phone with the app on it. MitID is perfectly okay with that. At login time you will be prompted for your token code, but there is an option to switch to the app ("Skift til MitID app" in the bottom of the box). The MitID design is strange, but in this regard it is well done.
- TobTobXX 6mo agoSame in Switzerland. The app needed to sign in to fill out my taxes doesn't work on ungoogled Android.
- afandian 6mo agoCan you do your taxes on a computer without a phone?
- herbst 6mo agoYes. Without any issues still. Gladly. There was a time window 2 years ago where it appeared that I need an actual phone number to do my taxes, but even that was replaced with something more universal.
- TobTobXX 6mo agoSomewhat. To fill out my taxes online, I could sign up with either the AGOV app (needs Google Android) or a USB security key. I happened to have a yubikey, but I needed to mess with the firefox about:config (security.webauth.u2f=true IIRC). It did work in the end though.
- nixass 6mo agoSo much about digital sovereignty
- jakoblorz 6mo agoWhat if you „lose“ your google / apple account, like this sanctioned judge of the international criminal court? Crazy to imagine that we are still baking in dependency on US providers in european societies, even though there is clear indications we should be doing the opposite?
- Animats 6mo agoThen you can't take a Waymo any more.
- Animats 6mo agoAmusingly, the points on this posting have been going up and down quite a bit. Range is -1 to 2 so far. The point here is that Waymo requires either an Android account or an Apple account to log into their phone app. Lose that and you cannot take a Waymo. This may be worth a formal complaint to the California Public Utilities Commission, because Waymo is regulated as a common carrier. California civil code section 2170: "A common carrier must, if able to do so, accept and carry whatever is offered to him, at a reasonable time and place, of a kind that he undertakes or is accustomed to carry. A common carrier must not give preference in time, price, or otherwise, to one person over another."[1] This is the core of what it is to be a common carrier. An airline can't require that you join their frequent flyer plan to fly. [1] https://codes.findlaw.com/ca/civil-code/civ-sect-2169/ https://codes.findlaw.com/ca/civil-code/civ-sect-2169/
- _3u10 6mo ago[flagged]
- aparadja 6mo agoThis tone is not very suitable for HN. I’m sure you could start a better discussion if you gave it a proper try.
- debazel 6mo agoYou wouldn't even have to be a high profile target like a sanctioned judge. Simply getting your account banned by some automated process that marked you as "suspicious" will basically render you excluded from society. It is absolutely insane to put this amount of power in 2 foreign companies that will be able to destroy your life with zero reason, oversight, or due process.
- wolfi1 6mo agoI'm not quite sure if the German implementation is possible without mobile devices (couldn't find anything on that at first glance). the Austrian implementation on the other hand does not require a mobile device, if you want to do it on a pc you just need a fido2 token
- NanoCoaster 6mo agoI'm not sure either. I've looked at this other document: https://bmi.usercontent.opencode.de/eudi-wallet/eidas-2.0-architekturkonzept/content/ecosystem-vision-and-fundamentals/what-is-the-ecosystem/#german-eid-card-infrastructure-outside-ecosystem https://bmi.usercontent.opencode.de/eudi-wallet/eidas-2.0-ar... It seems to imply that the already existing way of authenticating via eID, which is the auth chip present on our ID cards, will still work, if I read it correctly? I understand OP's link to refer to a new, alternative system, that can be used without the ID card. But take this with a grain of salt, I'm not very well informed about the whole topic.
- kodebach 6mo agoAs strange as it is, but Austria is quite far ahead in terms of eIDAS since we've had Handysignatur for more than a decade. I wouldn't be surprised, if the Germans are planning to support hardware tokens, but haven't had the time yet.
- 4ad 6mo ago> Austria is quite far ahead Yeah, quite ahead in terms of making anonymous phone numbers illegal and requiring the government to know your phone number. And if you don't want to use a smartphone, ID Austria does not work with regular FIDO security keys, you need special ones. Same for the old SmartCard system which didn't work without government-mandated malware.
- spragl 6mo agoI havent looked into the details of either, but what would prevent Germans from using the Austrian implementation?
- goblin89 6mo agoIn context of eIDAS, your phone starts to be used for much more sensitive matters than typing comments or even logging in to your bank. The repercussions from having a secretly patched bootloader can involve another person assuming your identity, including for large B2B transactions. Requiring citizens to have (buy) some device to simply prove they are who they are seems hostile and dystopian to me. Some say it’s the future; I’m not convinced. However, if you were to allow me to use my pocket computer (and nothing else) to prove I am who I say I am, you would want to trust that I am not pretending to be somebody else after extracting private keys from their phone or whatnot. I.e., you would want to require some sort of trusted computing. Currently, that seems to only be provided by closed ecosystem phones. Even still, I think it’s a mistake to be rolling out eIDAS as a mobile app first. The specification allows for this to be a dedicated hardware key (maybe even something YubiKey-like, and the EU already requires all phone manufacturers to have USB-C), so why not start with that.
- goblin89 6mo ago> Requiring citizens to have (buy) some device to simply prove they are who they are seems hostile and dystopian to me. Actually, that is not what’s happening. Based on further research, the use of eIDAS is required to be left up to citizen’s decision.
- RandomGerm4n 6mo agoI attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulator, a homemade compatibility layer under Linux, or a custom port for MS-DOS, that should be possible.
- reddalo 6mo agoExactly. It's my own device, I can do whatever I please with it. There shouldn't be an automated way for apps to check if my device has been blessed by the US tech giants or not.
- deleted 6mo ago[deleted]
- jurgenburgen 6mo agoIt’s my own device so I should be allowed to let the manufacturer make it secure so I don’t need to worry about security. I don’t want _all_ my devices to behave like that but I definitely want my phone to be more trustworthy for banking and government service purposes.
- like_any_other 6mo ago> I should be allowed to let the manufacturer make it secure so I don’t need to worry about security. You can still do this by simply not rooting your phone, or replacing the manufacturer's cryptographic key with your own, or altering whatever other 'security' measures are in place. What you're asking for is to have no other choice but to give the manufacturer control over your devices.
- estimator7292 6mo agoThat's not the problem at all. The problem is that manufacturers are forcing everyone into this scheme for the express purpose of mass surveillance and control. It has nothing to do with making your device "secure"
- darccio 6mo agoIt makes no sense. eIDAS 2.0 specs don't require specific hardware [0]. They basically store verifiable credentials [1] and any other cryptographically signed attestations. This feels like laziness from German implementers, as they don't want to (quoting the spec literally) "implement a mechanism allowing the User to verify the authenticity of the Wallet Unit". 0: https://eudi.dev/latest/architecture-and-reference-framework-main/#6522-wallet-solution-authenticity-is-verified https://eudi.dev/latest/architecture-and-reference-framework... 1: https://eudi.dev/latest/architecture-and-reference-framework-main/#534-w3c-verifiable-credentials https://eudi.dev/latest/architecture-and-reference-framework...
- mradalbert 6mo agoLook at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason. https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/287 https://github.com/eu-digital-identity-wallet/eudi-app-andro...
- stingraycharles 6mo agoWhy would this be? Bureaucracy / inability to change?
- archerx 6mo agoOr someone could be getting kickbacks on the down low.
- rafaelmn 6mo agoOr it's just way easier to implement this way and they don't want to waste time on stuff only HN crowd cares about ?
- bakugo 6mo agoImplementing Play Integrity is something developers have to go out of their way to do. Not implementing it requires literally zero effort. So no, it's not easier to do it this way.
- thomasingalls 6mo agoEurope needs a private European identity provider. Until this happens, Europe will remain a technological vassal state of the US. These are expensive products, you need depth of expertise and experience to create a system that could compete with the likes of gmail and Microsoft and ... so it's not a wonder that this hasn't happened yet. But pretending like this can be a public service is foolish (too high stakes ~~if~~ when it gets hacked), and pretending like existing providers that offer identity and email are sufficient is equally foolish. Google and ms and apple etc all offer the basics for free, and this is necessary for mass adoption. It will be an expensive project. But necessary, if the eu wants strategic autonomy. --- Oh and requiring a us based account is not even the most egregious part of this proposal, ffs
- reddalo 6mo agoNot only that, be we also need a European payment system that's not tied to VISA / MasterCard, etc. We're currently paying a small tax to the US for each card transaction we have.
- weddpros 6mo agoSelf Sovereign Identity (aka SSI) is the only way out of those identity sovereignty issues. It shouldn't be acceptable that your identity depends on anything or anyone. It should just be your identity. A paper or certificate can prove an entity trusts your identity to be <firstname, lastname, etc...> but that shouldn't be your identity. You just are. Not your google Id, not your Apple Id either of course. Governments are lame.
- s_dev 6mo agoYou are conflating the philosophical notion of identity with functional identification in the real world. There is no cryptographic escape hatch from the social contract. >You just are/I just am Is not an acceptable thing to say to a bar tender when being served an alcoholic drink when you're 22. You hand them government issued ID.
- weddpros 6mo agoI agree, and that government ID isn't your identity, it's just a piece of it. I'm not arguing against government ID, I'm saying identity doesn't have to be that piece of paper, or that Google ID. Analogy: if google ID is your primary key in your User table, then you're cooked. Instead use a uuid for the PK, and add Google ID as just another id. But the identity is the PK.
- rcbdev 6mo ago> Governments are lame In 2019, the EU created an eIDAS compatible European Self-Sovereign Identity Framework (ESSIF). How is the government lame, here? We've had the infrastructure for 7 years now.
- jonathanstrange 6mo agoHow is that not lame?
- weddpros 6mo agoeIDAS tends to hear "our European Sovereignty" when they hear Self-Sovereign. You can't have a government issue a Self-Sovereign identity to you, it's an oxymoron. They can only issue credentials. But then they'd feel like they're losing control, so they pervert it. Now they call it SSI but it's just digital credentials. The very title says it all: German implementation of eIDAS will require Google or Apple ID. That's not self-sovereign identity. And that's why I find it lame.
- userbinator 6mo agoISO7816 (smartcard) has existed for nearly 4 decades as the standard secure identity card, widely used by the banking industry among others. Very unintrusive and not hostile beyond needing to carry a little chip. If governments want a national ID, they could just give everyone one of those.
- red_admiral 6mo agoAlready exists as biometric passport or ID card in several countries. The problem is things like authenticating online to submit your tax form. App-as-2FA is kind of the standard for example to log in to your online bank portal, though for government services the threat model and privacy implications are different. If you have a FIDO device on your (physical) keyring or a keyboard with a smart card reader or some kind of NFC transceiver connected to your PC, the problem is technically solved - just not practically.
- Aachen 6mo agoNote that phones also have NFC readers. Instead of requiring everyone to have a locked-down phone, they could offer day you use said phone to read the chip or use any other (USB) reader you like. I believe there's a German government app that already does this, Ausweisapp2 iirc. As someone with a different nationality who lives in Germany, I don't know more than that
- JorgeGT 6mo agoThis is exactly how we implemented eIDAS in Spain. The government-issued national ID (DNIe) is an ISO 7816-compliant smart card. Latest versions are also ISO 14443-compliant for contactless reading. To use it, you just need a simple smart card reader or an NFC-enabled phone. https://www.dnielectronico.es/PortalDNIe/PRF1_Cons02.action?pag=REF_110 https://www.dnielectronico.es/PortalDNIe/PRF1_Cons02.action?...
- retired 6mo ago[dead]
- SkiFire13 6mo agoIt seems that many Android devices won't safisfy the requirements, even when using a device approved by Google: > MEETS_STRONG_INTEGRITY also includes the requirement that the device has received a security patch _within the last 12 months_ Good luck with that.
- blindseeker 6mo agoPossibly I‘m not smart enough to understand, but from what I see is that the implementers intend to leverage existing security architecture of Android/Google and iOS/Apple, respectively- arguably to drive adoption. The document doesn’t state anywhere that Apple / Google account is a requirement to use German eIDAS. From what I can tell, one may (continue to) use its government issued ID card with electronic signature for authentication. Please prove me wrong, I genuinely want to understand the implication of the linked document.
- minusLik 6mo agoThe account is not directly required, but you have a very hard time using an Android smartphone without a Google account. It's a bit easier with Apple, however both have in common that the apps required for eIDAS are available in their app stores – and they are not usable without an account (for common users). It's an account requirement in a roundabout way.
- webhamster 6mo agoGerman implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support. The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
- archerx 6mo agoWhat if I don’t have a smartphone?
- jahnu 6mo agoI wonder if there will be a big enough market for a very compact smartphone equivalent device that can be used just for credentials? A device that is offline on standby except when you need it. Perhaps the size of a car key.
- Matumio 6mo agoIf it can go online, I'd prefer to use an android work (or user) profile with only auth apps in it, and nothing else. As a separate device, it should be offline always IMO, and perhaps the size of a passkey. Or one of those banking devices with a display that show an authenticated text saying what you are confirming.
- archerx 6mo agoWhat if it was the size of a credit card and it had stuff like your name, date of birth and even a picture of your face. I want to name this invention an ID card…
- subscribed 6mo agoAnd if you added a cryptographic layer to it, with your own private key baked into it, you could both sign the documents, confirm your identity and the government could confirm it's actually you.... ....wow, that would be reinventing the existing model of the leading ID cards.... Crazy if you think about it :)
- zkmon 6mo agoGoogle is becoming a bit draconic. They did not allow me to create new email account, saying I already have too many accounts. But they also don't allow me to delete existing accounts, saying there is no authentication method available to access/delete those old accounts.
- tsoukase 6mo agoEU depending so much on Goo/App feels suspicious for direct lobbying, as someone noted. If I were Ursula, I would draw a red line: no US digital dependence. But the rounding error of the rounding error of these trillion dollar companies is enough to expunge the nonexistent EU infra.
- sylware 6mo agoWell, since it happened also for my gov (France) 10 years ago, we can see this pattern happening in the whole EU. There is a mixure of incompetence and big tech aggressive lobbying on gov 'standards' all over EU... making anything internet hard locked on big tech ultra-massively complex software, protocols and file formats. In my country, it is the web: classic web support interop was actually killed 10 years ago. Now, only web apps requiring one of the gigantic and ultra complex web engines from the WHATNG cartel are working. No more "small' web engines (including their SDK) does work, and it did close the door for good to anything 'not big tech' (here the WHATNG cartel), what a bummer, oopsie! In means in my country, to interact with the gov agencies and dependencies, you are now FORCED BY LAW to use only WHATNG cartel web engines. Wow, corruption (there is big public money there)? brain washing grade lobbying (what seems to be the case)? incompetence (always expected on complex matters)? To add insult to injury, in my country, the ONLY person who have the power to fix that is the prime minister (then also the president). Oooof! Of course, very simple classic web sites do work on 'smart phones' (apple did threaten to remove its browser... we know why: to force a technical hard dependency on them since they have a significant amount of the "market"). We all know their weak spot: a simple and stable in time, "good enough" to do the job, set of existing protocols/file formats (to protect the SDKs, I would include the computer languages, for instance excluding c++ and similar for plain and simple C and assembly to protect against the obviously ultra-complex SDK components): it will reduce dramatically the complexity and size of any current and future, local, implementations. What's seems to be happening when I look at that: some people all over EU countries are trying to fight their way out of big tech because of gov officials probably being brain washed by lobbying (do not exclude the possibility of "corruption" and there is always some level) of incompetence which is expected). Since it is happening in France and Germany, core of the EU... Now what?
- trklausss 6mo agoKnowing the German, how much of a fiasco will this be? Many Germans despise having to go online with specific services due to "Datenschutz". Now you are telling them that they need an external (American) service in order to use this? What I don't understand is: ELSTER (taxes) already uses electronic signatures, don't these signature already fulfil the requirements of eIDAS? Why do we even need Google/Apple?
- coretx 6mo agoGermans are likely going to try and hang the public servants for high treason via their constitutional court.
- deleted 6mo ago[deleted]
- verisimi 6mo agoCorporations + government = fascism. Fascism is the reality. And its global. Global fascism is what is already the case.
- sajithdilshan 6mo agoAs someone living in Germany, the alternative would be snail mail, which is used to send a pre-authentication code, username and then another code. This is pretty common with insurance providers, German traditional banks, etc. However, the annoying part is that if you ever forget or lose the code, then you would have to request a new one via mail that would arrive like 2 weeks after.
- jonathanstrange 6mo agoThe alternative is a secure physical device and that's also the correct way to go if you insist on having online ID checks and take digital sovereignty seriously instead of making it a joke lip service like these implementers do.
- makerofthings 6mo agoRequiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.
- mytailorisrich 6mo agoYes but in the real world all smartphones are either Apple or Android. Europe has zero footprint in either software or hardware. It is not creating a requirement to use specific products, it is using the products people already have. So one may argue that the implementers are only taking the pragmatic approach regarding something that is out of their hands.
- jonathanstrange 6mo agoWe're talking about an essential government service, not just another weather app. You have to look at this through the lense of national security, the debate about EU digital sovereignty, and the requirements of the GDPR in light of the US CLOUD Act, as well as prior decisions of EU courts about these issues.
- mytailorisrich 6mo agoYes all that you wrote is true. But that does not magically change anything to what I previously stated: in the real world all smartphones are either Apple or Android... I don't know what the eIDAS 2.0 requires in term of security but it may make the choice the implementers made here unavoidable in practice, as hinted by @webhamster. If so, it seems that a solution, if technically possible, might be to mandate that OSes provide the required security features without tie-in. The outrage in the comments feels a bit like people yelling at clouds...
- taotau 6mo agocorrection. in the real world all smartphones are either apple, android or none/other. in terms of legals, you really do have to cater to all three, which is why we don't have one world government.
- letmetweakit 6mo ago:facepalm:
- ttkari 6mo agoOh but isn't that great. This is just the kind of digital sovereignty these times call for. Sometimes I wish the Germans had an island of their own somewhere up north near the american continent.
- robertDouglass 6mo agolobbyists!
- kkfx 6mo agoSimply eIDAS must works on smart-cards and desktop USB/built-in card reader, not mobile (cr)App. BUT government do not want sovereignty more than they want snoop on citizens.
- coretx 6mo agoTime for a digital Reichstag fire. When will the germans stop repeating history ?
- nickslaughter02 6mo agoHow many billions will EU countries spend on this bull shit? Who needs it?
- ldng 6mo agoThe solution is simple : https://www.europarl.europa.eu/petitions/en/artcl/I+want+to+submit+a+petition+%21/det/20220906CDT10144 https://www.europarl.europa.eu/petitions/en/artcl/I+want+to+... Because you'll be stonewalled by devs because they can't really changer decisions made bu higher ups. Edit: I'd sign it, but don't want manage and diffuse it.
- 8note 6mo agoWhat does the eIDAs do? Does this lock Germans out of society if they dont buy American tech?
- txrx0000 6mo agoThis is about mass surveillance and control. https://en.wikipedia.org/wiki/Edward_Snowden#Revelations https://en.wikipedia.org/wiki/Edward_Snowden#Revelations The existence of eIDAS itself is already a big problem. They're going to try to gradually push laws to make it so that you'll need a government issued signature to do anything. That's when they'll have total power over you because they can simply refuse to issue. Modern computing and communications technologies can be leveraged to build infinitely stable authoritarian regimes. It's even possible for democracies to stumble into it on their own as they attempt to regulate these new technologies. In hindsight, the Internet was built wrong. It has a top-down structure which all of human civilization is beginning to mirror.
- TacticalCoder 6mo ago> They're going to try to gradually push laws to make it so that you'll need a government issued signature to do anything. And in the EU it's already nearly the case. The dystopian horror that KYC/AML has become for honest citizens is beyond belief. And they're of course hiding behind the excuse that "bad guys are laundering money": but going after actual drug dealers, of course they're not doing that. We now have articles wondering if Belgium (where most of the EU institutions do live and where all these totalitarian laws are passed) has become a "narco-state" (where criminals make the rules). People's life can be ruined when some employee, somewhere, decides he wants to bumps his SAR quota (Suspicious Activity Report): you can have a real-estate transaction fail (and have hence moreover to pay a 10% penalty to the other party) if either a notary, bank employee, real-estate agency employee decided that they've got the nostalgy of the Gestapo-time and decided to act like a good little nazi (yes, Godwin's law: for we're literally talking about totalitarism). I recently had an notary's employee bother my brother for the source of funds when he bought an apartment... A quarter of a century ago. A quarter of a century ago and he was talking to my brother as if he was a criminal for he didn't have access anymore to the bank wire transfer from 25+ years ago. It's crazy for the exact same controls had already been done 25+ years ago when he bought the apartment. And the notary's employee fully knows that. (regarding that case my brother is currently looking into the national federation of notaries and he's going to file a complaint: he's got emails from that notary's employee that are totally out of line). The problem is way too much power over the lives of others is put into the hands of petty people: petty bank employees, petty notary employees, petty public servants. The same kind of people who were all too happy to out jews during WWII and who were making sure trains would leave on time. I previously had a folder where every single money transfer of more than 10 K EUR was saved: I know do it for every transfer below 5 K EUR. And these are to be kept forever for I know that me or my wife or my daughter shall invariably meet motherfuckers asking them "proof of the source of funds from 30 years ago when your father bought that collectible car" (worth less than 20 K back then btw, but worth 6 digits now). Just fuck these systems and fuck anyone working on it and fuck all the nazis participating in it.
- jbverschoor 6mo agoeIDIOTS I guess
- Glorified2202 6mo agoCan every german citizen opt out?
- Glorified2202 6mo agoCan every german citizen just opt out and not have to use any kind of digital ID?
- docmars 6mo agoThis is such an egregious and embarrassing breach in privacy, it's crazy. GDPR good, but oh no... gotta spy on everyone now.
- surcap526 6mo ago[dead]
- aimemobe 6mo ago[flagged]