5 ms·
The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/287 https://
by Luker88 3mo ago
The EU reference for wallets strictly required google play services
https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/287 https://github.com/eu-digital-identity-wallet/eudi-app-andro...
So Italy's IO app https://github.com/pagopa/io-app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google.
Nothing will change until the lawsuits start coming in.
The only hope is the motorola/grapheneOS collaboration and consumer associations, that might sue for anticompetitive behavior.
Make noise on any channel for the apps that require play services, it will help in the future if the lawsuits start, since it will show user support for the initiative.
- 71bw 3mo agoThe lawsuits, sadly, won't matter. "Security" (or, rather, totalitarian control!) is more important than the 1% of nerds who care enough to tinker with their phone.
- esrauch 3mo agoIt's not 1% here though... Graphene has 300k users worldwide. There's 8 million absolutely illiterate and 150 million functionally illiterate people in Europe for comparison on scale here.
- stingraycharles 3mo ago150 million functionally illiterate people in Europe? Just how is that defined?
- oblio 3mo agoWhy are you surprised? Europe has 700 million people. Think of the average construction worker you know, do you think they could read and correctly summarize any moderately complex article? Think an article about inflation or evolution or heat pumps or investment funds, etc. Fairly sure that in most countries the average person reads less than 1 book per year, so half of the population reads less than that. I know people who haven't read a book since highschool, when they were forced to.
- wqaatwt 3mo agohttps://worldpopulationreview.com/country-rankings/average-books-read-per-year-by-country https://worldpopulationreview.com/country-rankings/average-b... The Average Briton allegedly reads 15 books per year. I assume its self reported and poorly sampled. Otherwise its very hard to believe (and variance between countries seems way too high) but stats like this (especially more subjective ones like functional literacy) are usually not very useful on their own.
- ulfw 3mo agoEspecially as it's claimed to be only 50 Million in the US hahahahahaha Whoever believes those statistics I have a strait to sell to
- etiennebausson 3mo ago>150 million functionally illiterate people in Europe 1/3 of the population functionally illiterate in Europe seems beyond wild to me. Are you talking about technical illiteracy? security illiteracy? Or do you mean they can't read english, which is a very different thing.
- w3ll_w3ll_w3ll 3mo agoFunctionally illiterate means that they can read in their own language, but they cannot understand the meaning, a part from very simple things.
- sebastianconcpt 3mo agoAnd we're heading to giving better quality feedback loops to AI models than people. Put this together with ignorance being the mother of evil and... How good this can become?
- Luker88 3mo ago"functionally illiterate" means that while you can read your native language, you will not correctly understand what you have just read. Rates seem to vary state by state, from as low as 8% (denmark) to 43% (romania). It's also not a clearly defined target, since it would be better to have rates based on the reading comprehension of the average school at year X or something similar.
- ralferoo 3mo agoI'm curious about this definition, just because it's not something I've ever considered before and googling seems to muddy the water even more. Is it "functionally illiterate" if you can read the language aloud and not understand it, if you also wouldn't have understood the same thing spoken to you? That seems like it's about comprehension ability, not literacy. Although one thing that just occurred to me is that if your reading level is low, you might be using all your cognition on reading so that you don't have spare capacity to understand as well - that's frequently the case for me with e.g. Chinese where I can read an entire passage out and then the teacher asks what the passage was about and I'm just thinking "I dunno, I wasn't thinking about that but I think I understood everything". And that's definitely a different problem to being able to sound out the words, but just having no idea what those words mean, whether you read them or heard them. And does it have to be your native language, or in any language? Not trying to nitpick, it just feels like the phrase can be usefully applied to a foreign language too.
- ivolimmen 3mo agoI think it does if enough people try this. I will.
- microtonal 3mo agoFirst, GrapheneOS supports remote attestation. So if they want their security, they can have it. Second, the current focus of the EU on sovereignty is a window of opportunity and there are better opportunities to fight this than two years ago.
- Zak 3mo agoPeople keep framing these sorts of debates in terms of tinkering. It's about ownership, not tinkering. It's about preventing megacorporations from having the last word about how government services can function and how people can interact with them.
- 71bw 3mo agoBut it's how the people outside of our circles see it. We tinker with our devices, which is not understandable to them - their phone just works, why would they change anything about it?
- Zak 3mo agoPeople keep talking about it that way inside our circles, and if we do that here, we will surely fail to do better with a broader audience. Last year's example of ICEBlock makes the freedom/tinkering distinction clear to most people. ICEBlock was an iOS-only app for tracking immigration raids in the USA and alerting users when they're nearby. Apple caved to government pressure and banned it. Because iOS users don't have the freedom to install apps from other sources, that's the last word; the app is effectively dead. I've found most people understand pretty well why that sort of thing is a problem even if it did not affect them.
- whizzter 3mo agoHonestly, as long as the architectures is fatally flawed (Even if convenient) it's just bandaids over a larger issue. These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks. Germany was going in the right direction imho, they NFC enabled their ID cards (Sweden has info on them but no enablement procedures) that is then paired with the app, so the card acts as a 2nd factor that makes the app itself less of a security issue since a user will be required to physically enable it (sadly the NFC pairings are kinda fiddly.. but I'd take that as a security option for all non-trivial transfers).
- doikor 3mo ago> These mobile id's are too powerful, signing contracts, transfering all your funds or taking loans, regulation is also papering it over a bit by requiring high-stakes lenders,etc to do additional checks. Many countries in the EU already have all of that just done though some national equilevant system (for example here in Finland mainly with bank credentials). And in fact additonal checks are done when enough money is moving. For example when I signed my bank loan for an apartment I had to sign it again after 24 hours just to be really really sure that I wanted to sign it. For smaller (but still big enough) stuff a second "second factor" usually kicks in usually in the form of a sms verification after the actual proper login with bank credentials (which has a proper 2 factor auth in itself too)
- donjoe 3mo agoIt's great you do have a bank-bound system in Finland. I hope their implementation is not as bad as e.g. the Swedish BankID. BankID is _in theory_ a nice technology. However, it is only handed out to people registered with the Swedish tax authorities holding a Swedish bank account. All daily activities are nowadays bound to BankID: need a doctor's appointment? -> needs BankID; Want to buy something on Blocket? -> needs BankID. As an European frequently spending some time in Sweden not in possession of a Swedish tax #, I feel very much excluded from online and partially offline activities in this country.
- m4xp 3mo agoThere is too much corruption, nothing can be done at this point. Atleast CIE app works on graphene for now so I can do everything else on the web. If they block that idk what I would even do.
- expedition32 3mo agoDon't assume corruption for something that can be attributed to not giving a fuck.
- tgv 3mo agoI do occasionally suspect corruption, but neither Google nor Apple have any incentive to pay off officials to get this passed. They can't beat each other, and the rest of the mobile OS'es is no threat to their revenue.
- bluGill 3mo agoGoogle and Apple's odds of being caught are too high to expect they would risk it. They have more to lose if caught than they have to gain. Obviously some companies do despite the risks, I wouldn't expect this of any individual company, but as a whole some company will once in a while anyway. So stay vigilant.
- m4xp 3mo agoI do assume corruption, All this random "compliance laws" are not made to help the people but to preserve corporate interest.
- lwhi 3mo agoOne set of people might not give a fuck. Other interested parties can still be trying to steer the ship.
- rjzzleep 3mo agoCorruption to push it through, not giving a fuck to keep it that way.
- WhyNotHugo 3mo agoThe issue isn't just the technical dependency. It's also the fact that it forces each citizen to pay a few hundred Euros to companies which then campaign against their very rights. Citizens get no support of any kind in case of issues, and has to enter a contractual agreement which is ridiculously asymmetrical, where the company has little to no responsibility of any kind, but has very ample rights to track the other party in extremely creepy ways.
- spwa4 3mo agoBut ... the alternative is that the government actually pays a bit of money to fix the situation! To support their solutions. To actually develop them for enough devices. To secure them ... Plus the services the government made are way more invasive than the Google/Apple ones. In addition to the money, actually using them would be hundreds of times more complex, and they don't have the provisions Google has, for example accessibility and security services (like actually stopping people stealing accounts on a large scale). All of this can be done, easily even, but it isn't. Politicians don't want to. https://www.itsme-id.com/business/platform/identification https://www.itsme-id.com/business/platform/identification https://france-identite.gouv.fr/ https://france-identite.gouv.fr/ https://english.rekenkamer.nl/latest/news/2023/03/29/digital-identity-tool-for-citizens-goals-achieved-but-still-uncertainty-about-future-log-in-tools https://english.rekenkamer.nl/latest/news/2023/03/29/digital...
- WaitWaitWha 3mo agoor, not force people into mandatory digital ID wallets at all.
- intrasight 3mo agoI just dont buy the argument that it would be that expensive for the governments to provide certified keychain fobs that provide hardware based identification.
- wqaatwt 3mo agoThat was an option for the past 15+ tears at least in some EU countries. Its just not very convenient (garbage tier software they bought didn’t help either).
- teekert 3mo agoMotorola/GrapheneOS, and FairPhone/e/OS.
- siwatanejo 3mo agoYes
- teekert 3mo agoOh and Sailfish OS [0], Postmarket OS [1], and whatever Purism runs [2]. [0] https://sailfishos.org/ https://sailfishos.org/ [1] https://postmarketos.org/ https://postmarketos.org/ [2] https://puri.sm/products/librem-5/ https://puri.sm/products/librem-5/
- seba_dos1 3mo ago...and Debian, PureOS, Fedora, Arch, NixOS...
- teekert 3mo agoMaybe they should just publish the spec, and then providers can offer ID as a service? I.e as a Proton user, Proton Pass currently supplies my ID everywhere, including for government services. What makes Android and Apple devices special?
- seba_dos1 3mo agoAndroid and Apple devices let the remote server verify whether the local application and the system it runs on haven't been modified by the user and refuse providing services if they were. That's what makes them special, it's hard to imagine how a, say, generic installation of Debian could do that without severely restricting the user. It's an ill-defined "security" measure that should be viciously opposed anywhere it shows up.
- Kim_Bruning 3mo agoFairphone/e/OS is Dutch and French respectively. It'd be funny if the EU forgot to permit the use of a pure european system.
- deleted 3mo ago[deleted]
- Retr0id 3mo agoSpecial-casing support for GrapheneOS would be a band-aid, they should find a way to avoid requiring remote attestation in the first place, so anyone can use whatever OS they like on whatever hardware they like.
- testhest 3mo agoAgreed, it should be open standards only.
- Retr0id 3mo agoNo! An open standard for remote attestation would still be remote attestation.
- hmlwilliams 3mo agoAs outlined here: https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu..., GrapheneOS isn't implementing something unique, it's implementing Android Hardware Attestation: https://developer.android.com/privacy-and-security/security-key-attestation https://developer.android.com/privacy-and-security/security-...
- Retr0id 3mo agoAndroid Key Attestation produces attestations that are signed with a certificate chain rooted in the hardware vendor's CA. If you use Key Attestation on GrapheneOS on a Pixel device for example, it attests that you're using GrapheneOS's AVB keys, but that attestation is still signed by a Google certificate chain. "Adding support for GrapheneOS" means allowlisting their AVB keys specifically, it does not open a door for 3rd party implementations in general. If you run GrapheneOS on a different device of your choosing, attestation would fail. If you run a non-GrapheneOS custom ROM of your choosing, attestation would fail.
- NotPractical 3mo agoNot to mention self-signed custom builds of GrapheneOS.
- layer8 3mo agoAs a technical point, note that however there is no legal requirement to follow this reference. Wallet providers can choose a different implementation.
- seba_dos1 3mo ago[flagged]
- microtonal 3mo agoEvery Android system support remote attestation. It's part of AOSP. Google just decided not to use it, because Play Integrity allows them to lock in phone manufacturers and force them (per leaked agreements) to preinstall a bunch of Google apps and require to run Play Services and some other components privileged on the system.
- seba_dos1 3mo agoSomething being in AOSP doesn't mean your distro has to retain it. Besides, the world doesn't end on Android systems.
- ValleZ 3mo agoPlay Integrity checks if app was tampered with. Hardware attestations can only guarantee key's source and cannot be used to check app integrity.
- microtonal 3mo agoI specifically referred to the remote attestation functionality in Play Integrity and that that can be replaced by AOSPs APIs, since the linked post is about remote attestation. Play Integrity actually does both and passing remote attestation is necessary to pass Play Integrity at the strong level. Remote attestation is used for this level, since a modified OS could fool DroidGuard. I'm sorry if my comment was not clear in what I was referring to.
- chadgpt3 3mo agoThe more the better - being forced to maintain an up-to-date list of Google competitors (including some that don't keep attestation keys secure, so the bad guys will pretend to be those and you'll be forced to allow it anyway) may make some reconsider whether the feature actually brings any value.
- u1hcw9nx 3mo agoThis is only reflects their market share for now. The EU legally forbids member states from making a smartphone mandatory to access public services. The EU explicitly anticipated the danger of relying entirely on the iOS and Android and designed the EUDI Wallet framework to allow for other physical form factors. For example; 1. Smart Cards (for example The Current National ID) 2. Standalone Hardware Tokens & USB Keys
- deaux 3mo ago> The EU legally forbids member states from making a smartphone mandatory to access public services. Yes, I'm sure they'll still allow for mail-in of obscure forms to access public services, which will then take 3 weeks to be processed. If the EU actually wanted to "anticipate" this danger they'd have made it mandatory to include a physical form factor in EUDI wallets. In reality, they don't mind this danger, so it's optional, and you can bet most countries won't include one and make Google and Apple the only options.
- microtonal 3mo agoAlso, as the article says, Play Integrity is most likely a violation of the DMA. Send a message to the EU DMA Team if you live in the EU and are affected by this (or affected by this in the future, if you plan to switch to an alternative): https://digital-markets-act.ec.europa.eu/contact-us-eu-citizen_en https://digital-markets-act.ec.europa.eu/contact-us-eu-citiz... The more examples they get of actual citizens that get hit by this, the better. I have recently sent messages when Google introduced their new device-based recaptcha and when Volkswagen started blocking GrapheneOS. Of course, do not yell, explain patiently and with good argumentation why you are affected by Play Integrity and how you believe Play Integrity is used to enforce the duopoly + goes counter EU sovereignty. Also, for apps that use Play Integrity, e-mail the company. React to their boilerplate replies with follow-ups (this slowly seems to get some headway with VW). Also leave a one-star review on their app, explaining in the review that they broke support for your system. I know that this can all seem hopeless. But especially GrapheneOS is getting a lot of momentum now, rapidly gaining more users. It feels like it is a moment in time where we can seriously influence things for the better. There are ~500,000s users now. If everyone actively participates, we can move the needle.
- artk42 3mo agoLobbyists do not sleep. It's easy to recall how those two, especially apple, tried to sabotage FIDO2 trying to capture webauthn standards, fortunately failed. EU also has to learn their inside traitors who sabotage their great efforts in decentralization of identity, and learn to avoid those incredible situations like happens right now with chat control directly lobbied by silicon valley surveillance vendors