4 ms·
The government still plans to place the authentication system of all Dutch citizens in USA hands. And interestingly, code.overheid.nl runs from a residential i
by oever 5mo ago
The government still plans to place the authentication system of all Dutch citizens in USA hands.
And interestingly, code.overheid.nl runs from a residential ip address.
- hvb2 5mo ago> The government still plans to place the authentication system of all Dutch citizens in USA hands. That's not a fair characterization. The company that runs it might be bought. That's not planning to put it in USA hands
- moi2388 5mo agoIt is a fair characterisation. They can access the data, as their data protection officer warned about, it hereby falls under US law, they have to give data when requested, and can shut it down at any time.
- embedding-shape 5mo agoNone of those things make "The government still plans to place the authentication system of all Dutch citizens in USA hands" a fair characterization, it doesn't seem to be true by any measures, the government has no such plans, unless you can point me to some public session/document that shows that this is actually the plan?
- oever 5mo agoTheir plan is to do nothing to stop the transfer of the system to a USA company. By doing nothing, they are making this happen.
- embedding-shape 5mo ago> Their plan is to do nothing to stop the transfer of the system to a USA company And you have concrete proof that this is indeed the plan, stated by the government as the official position, or this is based on your own extrapolation of rumors? The amount of misinformation that any story related to any European country seems to pull in is crazy, seems to be something about the continent that makes some parts of HN feel blood in their mouth or something.
- oever 5mo agoThere has not been a single action or communication from government that indicates that they are preventing the ID system from ending up under USA jurisdiction. Parliament has asked government with near unanimity to prevent this from happening. Government has not even acknowledged that this should be prevented.
- embedding-shape 5mo agoRight, which I agree, sucks, they should be upfront about what they want to do, regardless of what that is. And ideally their plan should be to try to stop it, I'm with you on this. But the lack of action is not proof that "their plan is to do nothing" nor "the government plans to hand authentication data over to US", those stronger claims require stronger proof, something you seem to be unable to provide.
- fragmede 5mo agoC'mon, be nice, they read a Russian propaganda post and are repeating it as a fact they earnestly believe. We can't all see through their lies.
- moi2388 5mo agoNo, we follow the actual governmental debates. Are you stupid?!
- deleted 5mo ago[deleted]
- noirscape 5mo agoSince a lot of this discussion is talking around the actual situation, let me try and explain it in more detail. The dutch government has an authentication system called DigiD. It's effectively an OAuth protocol for government sites, and one of the few ways in which the Dutch government has centralized IT. Every dutch citizen can get access to it, and probably will need it at some point to deal with the government (paper options are meant to exist, but you can already guess on how easy the availability of that is.) DigiD is currently hosted by a dutch company named Solvinity and developed by Logius (the governments in-house IT development organization). Solvinity is currently in the process of being bought out by another company, Kyndryl, which is based in the US. The government approved the takeover under the previous coalition (who are no longer in power.) The takeover currently is under extreme public scrutiny because of everything to do with the US - most people are at least vaguely aware of the deadly combination of the US CLOUD/PATRIOT laws, which would compel Kyndryl to hand over data on any dutch citizen to the US government for any reason[0]. The US government right now is not exactly behaving like a good steward with the powers it has, instead favoring maximum exploitation within (and outside, if the lawsuits are any indication) it's legal limitations, and is also verbally attacking it's own allies near constantly. Given DigiD is effectively a list of personal information on almost every dutch citizen, it's probably a bad idea to hand access to it over to a hostile foreign country. On an employee level, the takeover is deeply unpopular - some government workers have actively reached out to the press to warn about the deal, something which very rarely happens as government workers aren't expected to publicly break with government policy. This has led to a motion in the second chamber (parliament) to change DigiDs hosting from Solvinity to another provider being passed... in 2028, for a deal set to go through in a much shorter timespan. At the same time, the government (this time: the elected politicians) is unwilling to reconsider it's stance on the Solvinity takeover, claiming that because it already said it was OK before, it can't change its mind now. [0]: It's also, almost certainly illegal in a GDPR/AVG (local version of GDPR) sense. US/EU privacy laws are fundamentally incompatible with one another because of these two laws, and the courts keep shooting the international data transfer agreements to bits every time. Even on a basic level, having your government authentication systems legality tied to whether or not Max Schrems wins his court cases is a bad idea.
- embedding-shape 5mo ago
- moi2388 5mo agoIt does. The government is not stopping this takeover, and the authentication system is going to an American company. Rather strange how adamant you are in your position given that you clearly didn’t look into this at all. https://www.tweedekamer.nl/zoeken?qry=Solvinity&form_build_id=form-kNAdtdUaW2qcRFUA99sqe4_aCvP09Pden82lku1bt3E&form_id=tk_external_data_autonomy_search_form https://www.tweedekamer.nl/zoeken?qry=Solvinity&form_build_i...
- oever 5mo agoThe sale could be stopped by government. The ID system might be moved to a different company. The government could by the part of the company that hosts the ID system. None of these measures are being taken. The result is that the information needed to log in to all the important government systems becomes subject to American jurisdiction. Foreign agents will be able to authenticate themselves as any Dutch citizen and act on their behalf.
- QuantumNomad_ 5mo ago> And interestingly, code.overheid.nl runs from a residential ip address. That’s not what I’m seeing. IP address is currently 147.181.37.238, which is assigned to ODC-Noord via RIPE. ODC-Noord is a data centre for national government organisations according to https://www.odc-noord.nl/ https://www.odc-noord.nl/
- oever 5mo agocode.overheid.nl points to 62.59.196.156 which is in the Odido ASN. Checked with `host`, `dig` and hosting-checker.net
- QuantumNomad_ 5mo agoDarn, I’m on mobile and the tool I used decided to give me details for the base domain overheid.nl when I asked for details about code.overheid.nl :(
- deleted 5mo ago[deleted]
- sigio 5mo agoIt's an ODIDO ip, but from the old versatel block. I'm assuming it's a business netblock, not the typical ftth/dsl range.
- martijnvds 5mo agoTraceroute goes through `.ftth.glasoperator.nl` routers though.