16 ms·
German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support.
by webhamster 6mo ago
German implementer here. We have to use some kind of attestation mechanism per the eIDAS implementing acts. That doesn't work without operating system support.
The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). It is simply a matter of where we focus our energy at the moment, not that we don't see the issues.
- archerx 6mo agoWhat if I don’t have a smartphone?
- jahnu 6mo agoI wonder if there will be a big enough market for a very compact smartphone equivalent device that can be used just for credentials? A device that is offline on standby except when you need it. Perhaps the size of a car key.
- Matumio 6mo agoIf it can go online, I'd prefer to use an android work (or user) profile with only auth apps in it, and nothing else. As a separate device, it should be offline always IMO, and perhaps the size of a passkey. Or one of those banking devices with a display that show an authenticated text saying what you are confirming.
- archerx 6mo agoWhat if it was the size of a credit card and it had stuff like your name, date of birth and even a picture of your face. I want to name this invention an ID card…
- subscribed 6mo agoAnd if you added a cryptographic layer to it, with your own private key baked into it, you could both sign the documents, confirm your identity and the government could confirm it's actually you.... ....wow, that would be reinventing the existing model of the leading ID cards.... Crazy if you think about it :)
- AndyMcConachie 6mo agoYou're screwed. This has been the way for a while now. You cannot exist in society without a smart phone and it's only going to get worse.
- HighGoldstein 6mo agoEssential services (banks, government services, public transport) generally still support SMS as an alternative to their mobile apps when there's no completely offline process.
- maccard 6mo agoIf you can't exist in society without a smart phone already, how is it going to get worse?
- 0x3f 6mo agoPerhaps you won't be able to exist in private without a smart phone. Or there will be some technology beyond a smartphone that you can't exist without.
- subscribed 6mo ago...without a smartphone that is surveilling you 24/7. Private smartphones are excluded already.
- anileated 6mo agoNo one is required to use EUDI: https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/713526976/FAQ https://ec.europa.eu/digital-building-blocks/sites/spaces/EU... Companies and providers (like banks) have to support it, but use is voluntary. Check out the spec and legal framework, it actually makes sense and is open to different implementations, though you might need to certify it.
- bschwarz 6mo agoIf they have to support something that most everybody has they will soon stop supporting alternatives that are not required by law. What then?
- pastage 6mo agoYou are not required to accept anything other than digital ids. So from experience, whatever demands euid has will be what is required to identify you.
- dudefeliciano 6mo agoMy prediction is that eventually services for people NOT using the digital ID will be so degraded to be almost useless or seriously disadvantageous. Kinda like the discrimination DB does for people using paper tickets vs those using the DB Navigator app.
- EmbarrassedHelp 6mo agoThere are attempts make it almost mandatory through mandatory age verification. Which would mean that you'd have to submit to privacy violations or be cut off from a sizeable portion of the internet.
- verbalize2224 6mo agoYou should think about how easy it is to permanently lose access to your Google account for very trivial issues and Google doesn't offer any form of recovery. That in addition to the current geopolitical situation should be reason enough not to rely on that for any justification. And personally as a software developer myself i know that nothing is more permanent than a temporary solution. No one will prioritize or give budget to change it later "because it works"
- trklausss 6mo agoWhat? They should freaking think of sanctions, not about "how easy is to lose Google account". Both Google and Apple are American companies. If someone lands on a sanctions list, they close your account without further notice [1]. Let me get this straight: you can be a defender of human rights, aligned with the country you live in, but if you fall in disgrace with the American government, _you can't even do transactions with your own country_. So this is fundamentally flawed, and violates the fundamental rights of German citizens in Germany. [1] https://www.lbc.co.uk/article/british-icc-chief-prosecutor-lost-email-bank-accounts-frozen-trump-sanctions-rpTkm_2/ https://www.lbc.co.uk/article/british-icc-chief-prosecutor-l...
- applfanboysbgon 6mo agoSanctions are a bonus point argument, but shouldn't be a factor either. No citizen should be subjected to this, whether the company running it is American or German. Can you imagine if the Nazis had this level of control in the 1930s? Imagine having your ID digitally revoked, effectively cutting you out of society completely, without so much as an attic to hide in before it can happen. This is a completely dystopian legislation from start to finish. There is no possible way this can ever provide a benefit to the German people, it exists only to control them.
- extraduder_ire 6mo agoHis wife and kids are sanctioned too. Sometimes it isn't even anything you did.
- GoblinSlayer 6mo ago
- ibbtown 6mo agoWhy is a trusted device chain needed? It will put more trust in the potential Chinese device maker and American software companies than the user who's id is shown?
- kodebach 6mo agoSimply because the law was written that way. But also the whole idea of identity verification becomes pretty useless, if there is no chain of trust. You could run a modified client that lets you assume any identity you choose, exactly the opposite of what eIDAS is trying to achieve.
- notpushkin 6mo ago> You could run a modified client that lets you assume any identity you choose Provided you know the secret key to a government-issued certificate. Making it impossible to copy said certificate is not really a requirement for identity verification.
- subscribed 6mo agoSome countries fixed it already, see Estonian ir Polish IDs with digital layer (performing signing, authentication, etc), and the devices only acting as untrusted interfaces to these.
- notpushkin 6mo agoIt’s still impossible to extract an Estonian certificate from the smart card (or Mobiil-ID/Smart-ID), no?
- subscribed 6mo agoI believe do, I didn't see a successful attack yet.
- sam_lowry_ 6mo ago
- brador 6mo agoGoogle has banned many accounts of genuine users. What is your fallback for such an important vital service?
- notpushkin 6mo agoTo play the devil’s advocate here: MEETS_STRONG_INTEGRITY on Android doesn’t require a Google account AFAIK. But it might change, of course. Edit: but as pointed out elsewhere in the thread, Play Integrity is not the only way to do hardware attestation on Android. GrapheneOS devs have a guide: https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu... So avoiding proprietary Google stuff altogether is possible and we should encourage it.
- subscribed 6mo agoHow do you propose running Google play checks on the phone without working Google play? :) I don't think it's possible. And indeed, avoiding is possible and better, but the companies choose lie of play store "integrity".
- notpushkin 6mo agoFor Play Integrity, you do have to have the Play Services installed, but that doesn’t mean you need to sign into Google :-) (By the way, microG, an open source Google Play Services reimplementation, can achieve BASIC_INTEGRITY now, too. Which unfortunately doesn’t help much as most applications that do use Play Integrity want DEVICE_INTEGRITY at least.) > but the companies choose lie of play store "integrity" Agreed, very unfortunate. Most apps don’t even need it, but the security theatre is easier to do than actual security.
- reconnecting 6mo agoHumiliating disregard for sovereignty.
- ksjfjsmb 6mo agoSich bei staatlichen Dienstleistungen auf Google oder Apple zu verlassen, kommt schon fast einem Verrat gleich. Trump hasst uns.
- ghighi7878 6mo agoTbh, I feel this is stupid. Banks are giving out QR Tan. Optical TAN devices which work with credit cards and it has been going pretty well. Why can eiDAS not have something similar. Distribute hardware tokens. Get rid of dependency on any OS.
- mariusor 6mo agoI'm pretty sure electronic IDs are a good starting point for exactly this. Hopefully they get wider use inside the EU.
- dudefeliciano 6mo agowhy do you hope that?
- mariusor 6mo agoBecause there are many interesting uses for having a personal electronic token that's also recognized by your own government. My own interest is in using it as a base for establishing an identity for electronic ballots.
- dudefeliciano 6mo agosure but I don't understand how electronic IDs are a good starting point for having QR TAN or some other hardwarde device. I think OS-agnostic hardware should be the default starting point, not the other way around.
- mariusor 6mo agoThe electronic ID hosts a cryptographic key that can be used through some sort of hardware device in order to generate QR codes, or whatever that are linked to the user's official identity... The public part of the identity (which in our example it was enrolled at bank account opening) can be used by the server that checks the QR code to see if it actually belongs to the correct account owner.
- longdidi 6mo agoWhy not do it right from the beginning? https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu...
- subscribed 6mo agoThey don't really want to.
- tadfisher 6mo agoThat "guide" is kinda shit, there is massive work to do for an actual attestation implementation that replaces Play Integrity and supports the various backend frameworks.
- Archelaos 6mo agoGerman citizen here. I find this attitude horrible and threatening. You are working on sacrificing yet another part of our digital sovereignty to a US company. There are trillions of better things to do with your life.
- sam_lowry_ 6mo agoEuropean Citizen here, and indeed lots of people in IT turn a blind eye onto the collateral damage their work may create. I know someone who happily codes "verifiable credentials" in Elixir, disregarding all externalities.
- oytis 6mo agoWhat's wrong with verifiable credentials? It's an important thing to have it seems? Your passport or a bank card are verifiable credentials, or at least are designed to be.
- sam_lowry_ 6mo agoIt's an EU thing, overcomplicated an not sovereign: https://ec.europa.eu/digital-building-blocks/sites/spaces/EBSI/pages/600343491/EBSI+Verifiable+Credentials https://ec.europa.eu/digital-building-blocks/sites/spaces/EB...
- oytis 6mo agoOh dear, web 3.0, blockchain. Do we get our sovereign monkey NFT too?
- esbranson 6mo agoVerifiable credentials (VCs) are W3C standards and do not involve blockchains. Nor does Web 3.0.
- sam_lowry_ 6mo ago
- vaylian 6mo agoThank you for chiming in. > We have to use some kind of attestation mechanism per the eIDAS implementing acts. What does this attestation need to prove? Is this only about ensuring that private keys are managed by a secure enclave or a TPM? > we have support for other OSs on our list (like, e.g., GrapheneOS) I appreciate that, even though I am really not enthusiastic of eIDAS. But time will tell. Thank you.
- subscribed 6mo agoThey won't implement alternatives later, they'll be no point if "most of out customers is using either of the major providers". Concerning secure enclave - what other device except iphones and Pixels have it actually safe?
- Aachen 6mo agoThe nfc chips in identity documents
- vaylian 6mo ago> They won't implement alternatives later, they'll be no point if "most of out customers is using either of the major providers". It's hard for me to assess the effort needed here, but I guess that the GrapheneOS implementation will be 99% like the regular Android implementation. Supporting both systems does not seem to be that unrealistic.
- subscribed 6mo agoBut the "regular android implementation" they decided to choose now is not the regular android implementation (AOSP), they're relying on the signal from Google running play store integrity checks.
- notpushkin 6mo agoJust a quick question, and sorry if it might have been answered already... why preventing duplication is so important? I know it’s in the spec probably [1], but I can’t figure out the reason. And a suggestion: add external HSM support at least? (e.g. things like NitroKey/YubiKey) [1]: https://eudi.dev/latest/architecture-and-reference-framework-main/#432-components-of-a-wallet-unit:~:text=The%20WSCD%20is%20tamper%2Dproof%20and%20duplication%2Dproof%2E https://eudi.dev/latest/architecture-and-reference-framework... I suppose?
- notpushkin 6mo agoI’ve just had another, completely stupid but not implausible, idea: > a local internal WSCD, which is a component within the User device, such as a SIM, e-SIM, or embedded Secure Element, So you could issue SIM-cards / eSIM profiles that only do signatures and nothing else. The app then connects to such eSIM (and you keep your main SIM/eSIM in another slot). The less stupid variant is, of course, to get mobile operators to issue SIM cards with e-sign capabilities. Estonia has that, for example: https://www.id.ee/en/mobile-id/ https://www.id.ee/en/mobile-id/
- Avamander 6mo ago> The less stupid variant is, of course, to get mobile operators to issue SIM cards with e-sign capabilities. Estonia has that, for example: https://www.id.ee/en/mobile-id/ https://www.id.ee/en/mobile-id/ It works great. Just keep in mind that newer phones are starting to deprecate physical SIM slots. At the same time certifying eSIM implementations to the same EAL level is an absolutely crazy task.
- notpushkin 6mo ago> At the same time certifying eSIM implementations to the same EAL level is an absolutely crazy task. It probably is, but it does make sense. eSIM standards were built to solve pretty much the same problem (make cloning eSIM profiles impossible), so it should be a good anchor of trust for that.
- 6mo ago
- anonzzzies 6mo agoI think it should be possible IMHO, like it is for many banks (still), to get a hardware token and then use whatever hardware/browser. Even a nice EU hardware token which allows banks , govs etc to add their keys/seeds in the enclave would be nicer so I don't have the lug 1000 tokens around, but it's still better than having to trust non sovereign companies for anything without backup; like multiple here said; Google/Apple getting the command from the Dep of War to shut down EU phone attestation, you losing your account etc, or, you know, me simply not wanting to use their stuff.
- ExoticPearTree 6mo agoThe hardware tokens ate being phased out by banks and replaced with SMS OTP codes + passwords. Cost saving measures. Its funny to see that I can access the bank account through FaceID but to actually make a payment I need to use an SMS code.
- egorfine 6mo ago> That doesn't work without operating system support Do you realize where this path is going? Certain European governments would have greatly benefited from KYC/attestation in the late 1930s had it existed.
- elric 6mo agoYup. But apparently the EU is refusing to take lessons from history.
- gambiting 6mo agoGermany is just part of EU - as many other people pointed out, there is no requirement from the EU to implement it this way. Same as California or New York making extremely Draconian laws around 3D printing doesn't represent all of US.
- khalic 6mo agoIt's insane to make yourselves US dependent from the very beginning, at least provide something like a crypto-key that you can get from an official, banks can do it, so can you.
- haagch 6mo agoGerman citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices? Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.
- dark-star 6mo agobecause then it will never get done. There are still people using old Nokia phones, for those there will never be a solution. The usual 80/20 rule applies here as well. And if you really are a German citizen, you know how slow the wheels of government already turn in Germany, I assume next week you would be the one complaining that "Germany is so far behind" and that "other countries are so much faster at implementing stuff" :)
- abc123abc123 6mo agoYeah, let's burn the witches who care about privacy! Jokes aside, in a democracy, the systems must be designed so that everyone can participate. We manage to do it with voting, with income tax declaration, but for some strange reason, with ID we want to achieve 1984 nirvana, and crush the voices who tell us that the surveilance society we are building is just setting us up for the next Hitler.
- haagch 6mo agoNah, I'm that one idiot who uses alternative open software and just accepts when services aren't offered to me. The older I get, the easier it feels to not give a fuck anymore. Can't buy any single fare public transport tickets online here in Stuttgart? Sure, I'll use the DeutschlandTicket NFC card. Can't view the EPA? Fine then I don't. Can't pay with Wero? Fine, I don't actually need to use shops that don't offer SEPA Vorkasse or Lastschrift (only without a dodgy "identity verification" fintech startup of course.
- futune 6mo ago
- retired 6mo agoPerhaps look at the Spanish Cl@ve, it works with Linux. It's just a simple digital certificate that allows you to identify yourself. You can even run it on OpenBSD or TempleOS if you want to.
- ajjahs 6mo ago[dead]
- fredgrott 6mo agoso I have to buy a Yubikey hardware thingie to keep my Google account just to use eIDAS?? For those that do not know, that is the only way to get the Google account back is to use a hardware 2FA in the first place.... AND yubikeys are $60 per yubikey...and generally you want 2 including a backup
- tannhaeuser 6mo agoYou must go back to the drawing board and rely on highly-regulated Telecom standards (that's why they were mandated in the first place!) not monopolistic defacto "best practices" you have no influence over because they're more convenient for you. This is simply unconstitutional and should be escalated ASAP if you don't want to end it before the appropriate court in Leipzig, Karlsruhe, or maybe Luxembourg.
- jonathanstrange 6mo agoAnother German citizen here. I think what you're doing is illegal and will be blocked by German courts.
- 0x3f 6mo agoIt's funny because this is also the exact German response for when your neighbour has an unsanctioned BBQ.
- gorgoiler 6mo agoI know it’s not quite the same thing as an OS vendor, but culturally, if you’re having trouble empathizing with the ick in this thread then imagine if the initial implementation was available only for account holders with Facebook, Yahoo! Mail, or MySpace.
- oytis 6mo agoI don't get it. Are mechanisms in our ID cards not strong enough so that we have to rely on the security of the operating system?
- NanoCoaster 6mo agoWill eIDAS be the only way to identify yourself in cases where it's needed, or will we be able to user other mechanisms like the german ID card stuff or an entirely separate alternative? Or to put it another way, is a smartphone required? If not, that would already clear up a lot of issues, I think. EDIT: Whoops, just saw the answer to another comment asking precisely this. So it's not a requirement. Good. Is there a legal framework that ensures that this remains the case? Otherwise, I fear it will become a de facto requirement over time.
- jech 6mo agoOne datapoint: at least in practice, it used to be impossible to delete an entry in the French INPI database (trademarks and company names) without eIDAS. It forced me to unearth an old unmodified Android phone (I run LineageOS on my main phone). If you read French: * https://www.plus.transformation.gouv.fr/experiences/4531155_impossible-de-signer-une-demarche-sur-linpi-sans-smartphone https://www.plus.transformation.gouv.fr/experiences/4531155_... * https://linuxfr.org/users/jch-2/journaux/l-identite-numerique-de-la-poste-mal-securisee-mais-au-moins-elle-ne-marche-pas https://linuxfr.org/users/jch-2/journaux/l-identite-numeriqu...
- NanoCoaster 6mo agoOof, that's disappointing to hear. Thanks though, that's actually quite interesting. I'm also thinking of keeping an android phone purely for auth purposes, separate from my main one. The world's most overengineered (and probably also less safe) Yubikey. > If you read French Let's see how far my five years of French at school will get me. I'm not getting my hopes up ;)
- Aachen 6mo agoAlso if you are legally required to be able to use some backup mechanism, it can become the de facto requirement
- regnerd 6mo agothat‘s not correct. Article 5 eIDAS2 explicitly states, that europeans exercise full control over their data. Therefore EUDI wallet must not be a walled garden. Especially if the wallet shall be used for authenticating and signing, it must be available to all europeans, even those sanctioned by the US. If this is your plan, please go back to the drawing board.
- eMPee584 6mo agoThere's a new initiative by some non-google non-apple phone vendors called *UnifiedAttestation* which I hope you will support at some point in the future: https://www.heise.de/en/news/Paying-without-Google-New-consortium-wants-to-remove-custom-ROM-hurdles-11204037.html https://www.heise.de/en/news/Paying-without-Google-New-conso...
- nip 6mo agoIn light of all of these shortcomings with platform attestation, why go with the eIDAS 2 wallet approach at all? eIDAS 1 already solved this with Mobile-ID (SIM-based, no Google/Apple dependency) and Smart-ID (server-side key management with minimal platform reliance). What does the wallet model give you that justifies this level of dependency on two American corporations’ proprietary backends? Especially considering that mobile-ID has been around since 2007.
- nip 6mo agoI’m sorry to lash out at you but I keep getting disappointed in European countries (more precisely the ever disappointing EU commission) all suffering of the NIH syndrome instead of collaborating and learning from each other
- ExoticPearTree 6mo agoThere is mothing to be gained politically by doing this. You think you look good if you say “hey, the Poles had this really good idea, how about we do the same”? Plus, the process is something like: - we want to do $something - hire consultants to help us define $something and produce a document - hire other consultants to write the specs for the project - launch an RFP - select a winner - wait for the implementation to finish All the proposed solutions will be something paid, ideally made by a really large company to lend it credibility, and with maintenance costs that justify hiring dedicated people for it. In the end no one gets what they want. You think if there was any will wouldn’t the whole EU use whatever the Estonians are doing very well?
- jen20 6mo ago> You think you look good if you say “hey, the Poles had this really good idea, how about we do the same”? Yes. > You think if there was any will wouldn’t the whole EU use whatever the Estonians are doing very well? Using the Estonian system would be vastly preferable. If politics doesn’t allow that, the political environment is broken.
- gmerc 6mo ago“Not Great” is the understatement of the century. It fails to protect sovereign identity by handing the default to companies not only under foreign sanctions control but who also lock people from their accounts without recourse. The device chain is a classic misdirection, it seems everyone here is just following Meta’s lobbying to put this into the OS. Even the carrier layer would be better than the mobile device layer. Or, you know, just look at Singapore’s or Swiss National SSO - it functions on an app that layer just fine, no issues See https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/287 https://github.com/eu-digital-identity-wallet/eudi-app-andro...
- Aldipower 6mo ago"Not great" is quite an understatement from a European perspective. We're talking about a state-issued digital identity system, the European equivalent of your ID card, that cannot function without accounts at two US corporations. That's not a UX limitation. That's a structural dependency on foreign infrastructure for core state sovereignty. The concerns aren't abstract. The US has a documented history of mass surveillance programs (PRISM, XKeyscore) that directly targeted European citizens and governments. Both Apple and Google operate under US jurisdiction, which means CLOUD Act requests, national security letters, and executive pressure are all legal avenues for US government access. PlayIntegrity is explicitly described in your own architecture docs as a black box: "we do not know what they are actually doing in their backend." A critical security component of a state identity system, and you don't know what it does. That's not an engineering trade-off, that's an accountability gap. GrapheneOS being "on the list" is not reassuring. It means the system launches in a state where European citizens who have actively chosen to reduce their dependence on US Big Tech are excluded from their own national digital identity infrastructure. The EU passed GDPR to establish digital sovereignty. It's building eIDAS to establish identity sovereignty. Baking in a hard dependency on Google and Apple at the attestation layer undermines both, by design, at launch.
- oakpond 6mo agoShouldn't the energy instead be focused on creating a standardized eIDAS driver API that OS vendors are required to implement?
- utopiah 6mo ago> The initial limitation to Google/Android [...] is simply a matter of where we focus our energy at the moment Nice... so the rush is to delegate power to the large American platform?
- bakugo 6mo ago> We have to use some kind of attestation mechanism per the eIDAS implementing acts. Sounds like these "eIDAS implementing acts" are the problem, and were influenced by ulterior motives.
- isodev 6mo ago> The initial limitation to Google/Android is not great It’s also illegal on both accessibility grounds as well as violating the eIDAS spirit of no dependency on specific providers. By shrugging it off as “not great”, you’re also dooming every citizen to have to comply with whatever whimsical terms of service Google and Apple have. Have you ever tried to unban your Apple/Google account? So in effect, everyone’s access to eID services will depend on some crappy automation some intern in California setup to detect “abuse” or whatever. There are technical solutions to avoid this dependency and you’re probably getting paid to find, research and adopt them. So … do your job?
- deleted 6mo ago[deleted]
- ulrikrasmussen 6mo agoThis is simply unacceptable. You are not making an innocent pragmatic compromise here, you are launching digital infrastructure which initially will tie everyone to Google/Apple and give alternatives a huge disadvantage for an unknown amount of time. Nobody knows when, or even if ever, support for open platforms will arrive. You should be ashamed of being involved in this monopoly handover to American big tech.
- aenis 6mo agoFingers crossed for the judiciary - if the implementers ignore the intention of the law, then lawyers will have to help them understand the limits of corner cutting - and block this.
- subscribed 6mo agoI bet £50 that the alternative (eg GrapheneOS attestation (based on the standard AOSP attestation)) will be delayed, then delayed, then scrapped since almost everyone is using Google Plag integrity anyway. Yes, I assume malicious intent, sorry, seen this happen enough tines recently.
- tadfisher 6mo agoI'm in the US, not facing a mandate, but I want an open-source alternative to Play Integrity to use in the financial sector. There should be no excuse for anyone not supporting GrapheneOS. I've asked on Google's issue tracker and they are not interested in opening the program to non-OHA ("Google Play Approved") participants.
- subscribed 6mo agoIndeed. Goggle is very hostile to anyone not wanting Google deep in their OS, running undisclosed code with the superuser privileges. I think we all collectively should try the compliance / regulatory ways to force enough companies to have to adkit they know Google lies about security when talking about attestation, then force them into supporting alternative attestation methods.
- chaz6 6mo agoHave you considered Unified Attestation [1] which is an alternative to Google's? [1] https://uattest.net/ https://uattest.net/
- tadfisher 6mo agoOh dang, this is exactly what I've been looking for. Thank you.
- EmbarrassedHelp 6mo agoThat just puts the power to allow/ban rooting and operating systems in the hands of a different set of companies. Its still unacceptable.
- codethief 6mo ago> The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS). GrapheneOS uses standard Android APIs for hardware attestation (as opposed to Google-specific ones), so why don't you just use those from the get-go?
- izacus 6mo agoThey did. This is why Graphene works.
- codethief 6mo agoCall me confused. The comment I was responding to is saying something different: > The initial limitation to Google/Android is not great, we know that, and we have support for other OSs on our list (like, e.g., GrapheneOS).
- izacus 6mo agoYes, they still need to audit and whitelist the builds of GrapheneOS. That's what "standard APIs" are - they identify a build of OS, but someone still needs to make sure it's secure. If you don't want Google to do that for you, then the app developer has to.
- subscribed 6mo agoThey said they have GOS support in the roadmap, meaning they know it doesn't work but pinky promise to work on it in some undisclosed future.
- zajio1am 6mo agoWhy not just use U2F or certificates on crypto-tokens?
- zajio1am 6mo agoNote that for eIDAS 1, a Czechia e-identity provider uses U2F tokens.
- crest 6mo agoThis is on the stupid side of lazy (again). You'll still be sovereign only at the pleasure of Apple and Google if you submit to their platform as a service crap.
- inexcf 6mo agoSide question. How come it is always the most incompetent people who get put in charge of implementing things like that. Over and over apps and services are developed in Germany and completely fail at what they are supposed to achieve. Where are these people recruited from?
- cindyllm 6mo ago[dead]
- matheusmoreira 6mo ago> and we have support for other OSs on our list (like, e.g., GrapheneOS) Excellent. Massive respect to you for doing this. This attestation business is an existential threat to "other" operating systems. I'm glad to see people are putting effort into supporting them.
- morpheuskafka 6mo agoWhat happens if someone is banned from both companies (even for a very legitimate reason such as hosting illegal content -- they still need to access government services)?
- dudefeliciano 6mo agoWhat about people hosting content that is illegal in the US but not Germany (not sure what that may be now, but with the direction the US is taking maybe in a couple years even the fat Vance meme could become some kind of illegal subversive content). Anger the big daddy and your identitiy is gone.
- mrsssnake 6mo ago> We have to use some kind of attestation mechanism per the eIDAS implementing acts. Translates to: "We have to make sure citized accessing the public service have not control over the device per the eIDAS implementing acts"
- dudefeliciano 6mo agoglad that the "move fast break things" mentality has finally arrived to Germany, just didn't expect the public sector to be the first to implement it
- amaccuish 6mo agoWhy the need for a Cloud HSM?
- whizzter 6mo agoIs this implementation related to the AusweissApp I've seen mentioned before (that reads the cert via NFC from a physical card) or another implementation?
- nforgerit 6mo agoCongrats, this is the stupidest thing I’ve been reading all day. And that includes the orange man’s post.
- hans_castorp 6mo agoGerman citizen as well. So with a Jolla phone and Linux laptop, I am left in the cold.
- tadfisher 6mo agoAre you interested in a community-maintained alternative to Play Integrity? I work in the finance sector and it's increasingly likely I'll have to implement attestation at some point. Graphene's examples are adaptable, but we need a DB of open Android distribution keys and effective admin to support adding and revoking, possibly something like the LVFS system for Linux firmware.
- greatgib 6mo agoYou know that it is how Germany got its darker period when people were just "doing their job" despite being against the good of the population. Without good conscious!
- EmbarrassedHelp 6mo agoWhy not explicitly forbid the German version of the eDIAS from being used for things like age verification then? That'd solve a ton of privacy issues with the implementation.
- frm88 6mo agoWith a view on current geopolitics I find it absolutely irresponsible to use two US companies for attestation. The sanctions on ICC judges/prosecutors at the latest should have shown that it is a matter of national security to avoid a possibility of being completely shut down by an unstable US government. How do you propose to deal with people who get sanctioned or banned by Google/Apple for whatever reason? What measures do you have in place so these people can still access their ID?
- account42 6mo agoThe proper response to requirements ruling out an ethical implementation is to not implement them, not to provide an unethical implementation.