5 ms·
Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not gr
by makerofthings 6mo ago
Requiring people to use products from one of two private American companies with a bad track record of locking people out of their accounts is more than “not great”. Some things are better not done if they can’t be done well.
- mytailorisrich 6mo agoYes but in the real world all smartphones are either Apple or Android. Europe has zero footprint in either software or hardware. It is not creating a requirement to use specific products, it is using the products people already have. So one may argue that the implementers are only taking the pragmatic approach regarding something that is out of their hands.
- jonathanstrange 6mo agoWe're talking about an essential government service, not just another weather app. You have to look at this through the lense of national security, the debate about EU digital sovereignty, and the requirements of the GDPR in light of the US CLOUD Act, as well as prior decisions of EU courts about these issues.
- mytailorisrich 6mo agoYes all that you wrote is true. But that does not magically change anything to what I previously stated: in the real world all smartphones are either Apple or Android... I don't know what the eIDAS 2.0 requires in term of security but it may make the choice the implementers made here unavoidable in practice, as hinted by @webhamster. If so, it seems that a solution, if technically possible, might be to mandate that OSes provide the required security features without tie-in. The outrage in the comments feels a bit like people yelling at clouds...
- taotau 6mo agocorrection. in the real world all smartphones are either apple, android or none/other. in terms of legals, you really do have to cater to all three, which is why we don't have one world government.
- mytailorisrich 6mo agoThis is about a digital wallet, so people who don't have a smartphone are out of scope. Now, "other" than Apple/Android is so small as to be negligible and governments also have a duty not to waste taxpayers' money, which means not spending hundreds of thousands to cater for an ultra small number of people who have an easy access to an alternative. To have government apps work only on iOS and Android is perfectly reasonable in the current state of the world where this covers 99% of smartphones.
- znort_ 6mo ago> To have government apps work only on iOS and Android is perfectly reasonable in the current state of the world where this covers 99% of smartphones. the fundamental flaw with that approach is that it is totally unreasonable to have government apps in anything other than open source and fully public systems. nothing else can really be trusted, and any private/closed source option should be disqualified from the get go. the reason is simple: you can't trust private entities or opaque systems, and you can't trust government either, thus the solution has to be fully transparent or you're doing nothing. the problem with that is that it is hard, expensive and/or inconvenient.
- limagnolia 6mo agoWhy should I have to have a smartphone to have a digital wallet? Smart watches, tablets, laptops, portable game consoles, etc, are all perfectly cromulent hardware for running a digital wallet.
- Hackbraten 6mo ago> in the real world all smartphones are either Apple or Android... So you're claiming that Mobian doesn't exist? PureOS doesn't exist? PostmarketOS doesn't exist? Ubuntu Touch doesn't exist? SailfishOS doesn't exist?
- mytailorisrich 6mo agoDon't be disingenuous. All of what you mention are rounding errors in term of market share. This discussion feels unreal, really.
- MrDrMcCoy 6mo agoRight, because "you can't use an unpopular OS if you want your full rights as a citizen, and access to those rights must be additionally subject to a foreign corporation's opinion of you" is totally acceptable. I would go so far as to say that a government requiring any particular technology or private service to be a functioning member of society is hostile to all citizens. If your OS vendor / phone carrier / ISP all close your accounts despite no illegal activity, and your government has no alternatives you can use for essential services, then your government has sold your citizenship.
- jonathanstrange 6mo agoEssential EU government services cannot be devised on the hope that US companies will invent something that - contrary to current US legislation - will somehow provide the attestation services needed in a GDPR-compliant way without forcing EU citizens to provide personal data to US companies. If it's not possible to create such a system for mobile phones because of legal issues (as you seem to acknowledge and judges have found in the past), then the focus would have to be on creating hardware devices in the EU, ideally with open source hardware and software. These can be made reasonably secure, have been used by banks for a long time, and would enhance digital sovereignty. What I find unacceptable is the attitude "well, it will violate the law but as a matter of practicality it's the only choice we have right now so we'll just do it."
- mytailorisrich 6mo ago> Essential EU government services cannot be devised on the hope that US companies... I don't disagree. I am just pointing out that this is wishful thinking right now. As said, Europe has zero footprint in hardware or software so the choice is either not to develop any digital services or to accept that they will run of foreign hardware/software because everything is either Android or Apple and runs on hardware that is from US/Taiwan/China. Developping honegrown alternives is pie in the sky or a 20 year project if we are optimistic (which I am not)... Frankly, many comments, and the reactions to mine, show how out of touch and idealistic or naive the HN crowd can be.
- jonathanstrange 6mo agoEU can build token-generation hardware and that's the solution to the perceived problem. Such approaches have been used by banks for decades. It's not a "20 years project" to issue similar hardware to what my German bank issued 10+ years ago. I've explicitly stated in my post that the EU should not build a software solution for smartphones with US operating systems since this approach violates the GDPR and other laws because of a fundamental incompatibility of EU law with the US CLOUD Act that has been recognized by judges already. The proposed solution you seem to favor is illegal. If I'm right, you're the person ignoring reality and basing their judgment on wishful thinking, not me. I understand why you want to have a smartphone solution ("practicality") but AFAIK that's currently not a viable approach. I might be wrong about the legal situation but that's what I've claimed. Just repeating your talking point is not a reasonable reply to these legal concerns. In addition to this, there are also serious national security concerns, of course.
- subscribed 6mo agoIt literały has created the dependency on google when thought Android offers the standard/generic AOSP attestation. Also you weirdly forget all the Chinese phones. There's also some tiny European brand which will have absolutely no way to limit their users dependency on the famously hostile and unconctactable provider.
- FabHK 6mo agoMost Chinese smartphones run Android (Huawei uses HarmonyOS).
- qwertox 6mo agoMaybe that will force the companies to not be allowed to just lock you out of the account.
- gmerc 6mo agoYa, sorry, no, maybe is not really a durable position here.
- subscribed 6mo agoYou, your siblings, your parents, etc, etc.
- spwa4 6mo agoSo what can be used as an attestation API? WHAT will make sure that when a phone says "you're paying 10 euro to $coffee_place" that it isn't a bitmap being shown over "you're paying 10.000 euro to $scammer", above the pay button. Note: needs to be a real guarantee that isn't a permission question away from going away. Either governments can develop (and pay for) THAT technology, or they can use Apple/Google ...
- xorcist 6mo agoThat seems like a weak argument to require attestation? What would attestation prevent that scenario, specifically?
- spwa4 6mo agoOh I see your confusion. It is not trying to prove it's not cheating with the UI (or remote control, or ...) to the owner of the phone. It's proving to the owner of the website (or app, or SIM, or ...) that it's really the user agreeing to the contract on the screen. Or, more to the point, it's proving it to courts after the fact so they'll convict the owner of the phone rather than the business or government. The scenario it would prevent is that a government gets a filled in form with someone requesting unemployment benefits, or reimbursement for a medical procedure on account X ... and then government finds out after payment, later, in court, that the owner of the phone never agreed to it and it needs to pay it out again (because the claim, true or not, that a scammer initiated the payment agreement in some way rather than the owner). Same for business and agreeing to a loan and ... It is NOT to protect you, the owner of the phone, against scammers (it does not really do that at all), it is to protect companies and especially governments AGAINST the owner of the phone. It is a way to fire most EU government employees by allowing automation that currently can't work because you can't legally trust phone and internet automation to be binding in court.
- GoblinSlayer 6mo agoDo you imply that google can prove such a thing or it's just a security theater for (((compliance)))? AFAIK attestation attests hardware, not software, but hardware attestation is self contained and doesn't require any remote cartel permission, cf yubikey attestation.
- ExoticPearTree 6mo agoThere are no alternatives. I mean you could use Huawei and others, but the FUD campaigns against chinese manufacturers was pretty agressive in the EU.