Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > Governments are cementing a monopoly they claim to oppose

    Duopoly but yea. Because there is no third alternative. Microsoft failed/gave up with Windows Phone. The people trying to fix secure government services can't really tackle that issue, but the systems needs to be built now anyway.

  • Windows Phone wouldn't be much help here, still an US company.
  • They can't tackle issue oft establishing a 3rd popular mobile operating system, true. But they could support Desktop Linux or AOSP.
  • > but the systems needs to be built now anyway.

    I question that premise.

    by flir
  • There are viable third alternatives which do not require building a full smartphone stack. The national eID in Denmark, MitID, is an app "protected by" Play Integrity, but at least there are two non-smartphone alternatives available in the form of either a TOTP code generator or a FIDO2 chip which you can get for free if you can't or won't buy a smartphone.

    Age verification solutions could also be built on dedicated hardware tokens, even though the tokens required to build a ZKP or blind signature based solution may not be available off the shelf right now.

  • Just a general rule of thumb:

    If I am not able to use any digital service or product on a computer that I could have built entirely myself (or had anyone of my choice build for me), running code I could have written entirely myself (or had anyone of my choice write for me), then that is completely unacceptable.

  • I really don't like how EUDI (OpenID4VP) works in the first place. IMO it should be scrapped and rebuilt from the ground up

    It should be an open standard that's local first. Government issues certificate, user loads it into any supported client app on any platform (official, open-source, Google/Apple Wallet, etc). The user should then be able to selectively share data from the certificate with third-parties, directly between the client-app and the third-party, using an open standardized protocol/format. The important challenge is that we obviously shouldn't have to share the entire certificate (which would include all data in it), there shouldn't be a static subject pubkey which creates linkability between data-shares, and obviously we'd need privacy-focused data fields like {"isover18": true} in addition to full DoB.

  • How exactly is OpenID4VP in your understanding different from what you describe?
    by c2bo
  • EU should have mandated a user-facing authentication scheme using a random string as the only authentication factor for everything. Pretty much like the API tokens for contemporary enterprise software, except that they would be used by ordinary people and not by application developers.

    And complement it with hardware tokens for highly sensitive applications.

    Passkeys could have been that, but they were quickly subverted by the industry.

  • Tell me you’ve never supported a large userbase without telling me you’ve never supported a large userbase.

    What’s the plan for supporting the 50,000 people a day who lost their random string? What’s the plan for supporting the other 50,000 a day who pasted it into a random website? Europe has a billion people.

  • But this does not allow tracking nor marketing, so why would they do that?
    by 71bw
  • There's a relatively simple and much more open and secure solution to this: Make physical EU ID cards the attestation source, and require users to tap them against their phone for critical operations (high-value signatures, login on a new device or after repeated authentication failures etc).

    That would solve the open hardware/OS "problem" on the device entirely, as there's no trusted hardware or OS signature required anymore. You could argue that this adds the possibility of a MITM attack on the phone (since you don't know what you sign anymore or who you are providing with your PIN, as the card has no display and no PIN pad), but I wonder if mitigating this is worth all the lock-in concerns that phone attestation goes hand in hand with.

    As it is, all EU ID cards already have mandatory strong cryptographic authentication, but in a form that's usable only for in-person ID checks (under the corresponding ICAO biometric identity document standards), not for remote ID attestation. This is frustratingly close, but not what's needed.

    by lxgr
  • How can you have a secure enclave without hardware attestation? Processor root-key is the source for all.
  • My French ID card has the features, but also the French digital ID app also requires Play Integrity...
  • Here in Germany we had court rulings saying the german railway (DB) must offer offline tickets that do not require a computer or smartphone to purchase to not discriminate against the elderly. I am pretty sure we will see similar rulings for EUDI wallet requiring Google/Apple.
  • Ideally they should have also told all German banks distribute or offer non-App based accounts or 2FA? But they did not.

    Also people are dependent on Play or App store. DB does not offer the app for direct download.

  • There are AFAIK no plans to completely remove the offline ID everyone is currently required to carry, so I doubt there will be similar rulings for EUDI as long as it remains an optional alternative for people who want to use online services.
  • So when Google bans someone, that person also loses access to all services that require digital ID, forever?

    I remember when a Youtuber asked live viewers to "vote" by typing emojis, and a whole bunch of viewers got their Google accounts banned for spamming[1]. Google is also famously averse to user support (understandable given the scale of their free services), so individual remedy is unlikely.

    I can already see the new ransomware: "pay us or we'll send spam from your gmail and you'll lose your digital ID".

    [1] https://www.engadget.com/2019-11-10-youtube-reinstates-banne...

  • Regulations create monopolies. Even when regulations are aimed at curbing the control of giants, smaller players usually can't afford them and lose market share. This is actually taught as a competitive advantage strategy in business school. Corporations lobby the government to implement laws that seem to hurt them but in actuality create an uneven playing field where marketshare becomes available due to the higher implementation cost.
  • Regulations __can__ create monopolies. DMA is a regulation, but it does not have the shortcomings you mentioned.
  • > Corporations lobby the government to implement laws that seem to hurt them but in actuality create an uneven playing field where marketshare becomes available due to the higher implementation cost

    (nit: I assume you meant "marketshare becomes unavailable")

    So you mean that regulations that are created based on lobbying by corporations help them become monopolies? Sure, that makes sense. But thats different from a blanket "Regulations create monopolies".

  • My intuition is that this is not necessarily true, but probably often true in practice but perhaps someone more educated on the matter can speak on that. It must also depend on the expensiveness of the regulation in question. Since in tons of areas regulations are absolutely vital so that for example our buildings don’t collapse, our food remains non-toxic and the medicine we buy is not the pharmacological equivalent to russian roulette the goal should then be to optimise the cost performance of regulations.
  • Unless regulations explicitely incorporate how to handle incumbents & newcomers. One instance of that is MMTIS (multi modal passenger information), which explicitly states innovation and new players as a goal. There are other similar examples.
  • > Regulations create monopolies. Even when regulations are aimed at curbing the control of giants, smaller players usually can't afford them and lose market share. This is actually taught as a competitive advantage strategy in business school. Corporations lobby the government to implement laws that seem to hurt them but in actuality create an uneven playing field where marketshare becomes available due to the higher implementation cost.

    The only way to guarantee a monopoly is to have a total lack of regulation. It's known that every "free" market will tend towards monopoly due the 1% law. Regulations are the only way to actually guarantee free markets because perfect free markets only exists in abstract, not in reality. Sometimes, a free market is the wrong solution and you need a regulated monopoly instead and with identity that's the best solution. Why? Because identity is unique to the individual. A individual must (in theory) only have one identity and with very extreme and usually well documented exceptions, such identity doesn't change. The state is the one that must provide a good way for identity and if smaller countries doesn't have the resources, then big countries should provide for all. Also, it removes incompatibility inter-countries while keeping private interests out.

    The state should have the sole monopoly on attesting to anyone identity. Because they are the only ones that are not affected by market conditions. This is how countries that have advanced in this topic actually work. If individual states can't reach a common solution, then the collective must do so. The collective failed here because it recommended a private solution rather than mandated a european one. Private sector must not dictate what or how identity is attested, because the private sector has it's profit pursuing agenda, state must evaluate solutions but it's up to the states to run them and implement them.

    Market solutions are good for several things, this isn't one of them.

  • Aren't monopolies is what we end up by default if have no regulation at all?

    And yes, not every regulation destroys monopoly, but regulation is the only thing that could break one.

  • Working as intended. EU wants you to use a device and OS they can fully control. Don't comply with some new ridiculous regulation? Your app will be banned.

    > EU App Store: Apple Removes Thousands of Apps Due to Digital Services Act Requirements

    > Apple’s app removals follow the Digital Services Act, a European law requiring all app traders to display verified contact details, including address, email, and phone number.

    https://www.techrepublic.com/article/eu-app-store-apple-digi...

    You think apps which wouldn't want to implement Chat Control will remain on the app store?

    EU to legislate about Chat Control behind closed doors (https://news.ycombinator.com/item?id=48707719)

  • The only problem is, EU does not control these devices, Google and Apple and by extension the US government does.
  • A European digital ID system that is entirely dependent on 2 US companies.

    Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

  • Europe will never have digital sovereignty from the US.

    It will take 100 years and an extremely expensive, government-mandated reimplementation of every critical US tech service and company.

    No EU country is putting up budget for this, and no private enterprise is going to do it because building a worse version of AWS just so that it is "European" makes no financial sense and would most likely just fail anyway.

  • > Or was that just performative nonsense?

    Yes? Wake up, it is 2026.