Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • There's a relatively simple and much more open and secure solution to this: Make physical EU ID cards the attestation source, and require users to tap them against their phone for critical operations (high-value signatures, login on a new device or after repeated authentication failures etc).

    That would solve the open hardware/OS "problem" on the device entirely, as there's no trusted hardware or OS signature required anymore. You could argue that this adds the possibility of a MITM attack on the phone (since you don't know what you sign anymore or who you are providing with your PIN, as the card has no display and no PIN pad), but I wonder if mitigating this is worth all the lock-in concerns that phone attestation goes hand in hand with.

    As it is, all EU ID cards already have mandatory strong cryptographic authentication, but in a form that's usable only for in-person ID checks (under the corresponding ICAO biometric identity document standards), not for remote ID attestation. This is frustratingly close, but not what's needed.

    by lxgr
  • Here in Germany we had court rulings saying the german railway (DB) must offer offline tickets that do not require a computer or smartphone to purchase to not discriminate against the elderly. I am pretty sure we will see similar rulings for EUDI wallet requiring Google/Apple.
  • So when Google bans someone, that person also loses access to all services that require digital ID, forever?

    I remember when a Youtuber asked live viewers to "vote" by typing emojis, and a whole bunch of viewers got their Google accounts banned for spamming[1]. Google is also famously averse to user support (understandable given the scale of their free services), so individual remedy is unlikely.

    I can already see the new ransomware: "pay us or we'll send spam from your gmail and you'll lose your digital ID".

    [1] https://www.engadget.com/2019-11-10-youtube-reinstates-banne...

  • Regulations create monopolies. Even when regulations are aimed at curbing the control of giants, smaller players usually can't afford them and lose market share. This is actually taught as a competitive advantage strategy in business school. Corporations lobby the government to implement laws that seem to hurt them but in actuality create an uneven playing field where marketshare becomes available due to the higher implementation cost.
  • Working as intended. EU wants you to use a device and OS they can fully control. Don't comply with some new ridiculous regulation? Your app will be banned.

    > EU App Store: Apple Removes Thousands of Apps Due to Digital Services Act Requirements

    > Apple’s app removals follow the Digital Services Act, a European law requiring all app traders to display verified contact details, including address, email, and phone number.

    https://www.techrepublic.com/article/eu-app-store-apple-digi...

    You think apps which wouldn't want to implement Chat Control will remain on the app store?

    EU to legislate about Chat Control behind closed doors (https://news.ycombinator.com/item?id=48707719)

  • A European digital ID system that is entirely dependent on 2 US companies.

    Wasn't there some talk about the pressing need for European digital sovereignty recently? Or was that just performative nonsense?

  • Even relying on Android's hardware attestation API instead of Play Integrity is an attack on digital autonomy in my opinion. Any security feature which relies on remote attestation of the users entire platform is government overreach as it ultimately gives the government the power to choose what operating systems are acceptable. It is only a matter of time before this power will be misused to put pressure on OS developers to install backdoors for the intelligence agencies. And no, asking people to own two smartphones is not a solution to this problem.

    Anonymous digital age verification based on a suitable ZKP scheme and/or blind signatures does not require a general purpose operating system, it just requires a few cryptographic primitives and a set of device-bound keys. It is not too much to ask that the EU develops a specialized hardware token with these exact capabilities and offer them for free to all citizens as an alternative to the app. This also gives the citizens of EU the freedom to choose not to own a smartphone without having their access to digital services severely restricted.

  • The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro...

    So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google.

    Nothing will change until the lawsuits start coming in.

    The only hope is the motorola/grapheneOS collaboration and consumer associations, that might sue for anticompetitive behavior.

    Make noise on any channel for the apps that require play services, it will help in the future if the lawsuits start, since it will show user support for the initiative.

Explore Birbla archives

European digital ID wallets rely on safety services of Google and Apple · Birbla