Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
130 Indlæg 99 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • pojntfx@mastodon.socialP pojntfx@mastodon.social

    https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

    So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

    Absolutely pathetic

    argyle13@xarxa.cloudA This user is from outside of this forum
    argyle13@xarxa.cloudA This user is from outside of this forum
    argyle13@xarxa.cloud
    wrote sidst redigeret af
    #23

    @pojntfx this is unacceptable

    1 Reply Last reply
    0
    • pojntfx@mastodon.socialP pojntfx@mastodon.social

      https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

      So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

      Absolutely pathetic

      daumenlutscher@fedifreu.deD This user is from outside of this forum
      daumenlutscher@fedifreu.deD This user is from outside of this forum
      daumenlutscher@fedifreu.de
      wrote sidst redigeret af
      #24

      @pojntfx
      Germany is such a mess; they’re just useless, and there’s plenty of that

      1 Reply Last reply
      0
      • pojntfx@mastodon.socialP pojntfx@mastodon.social

        https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

        So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

        Absolutely pathetic

        gvlx@masto.ptG This user is from outside of this forum
        gvlx@masto.ptG This user is from outside of this forum
        gvlx@masto.pt
        wrote sidst redigeret af
        #25

        @pojntfx Same thing for Portuguese #eID, which had been working fine for more than 10 years, and was Open Source.

        Now the source is no longer available and refuses to work on de-googled devices.

        #europe #portugal

        1 Reply Last reply
        0
        • pojntfx@mastodon.socialP pojntfx@mastodon.social

          https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

          So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

          Absolutely pathetic

          neilk@xoxo.zoneN This user is from outside of this forum
          neilk@xoxo.zoneN This user is from outside of this forum
          neilk@xoxo.zone
          wrote sidst redigeret af
          #26

          @pojntfx Skimmed it and I’m not sure that they are embedding dependence on Google or Apple so much as recognizing that in a BYOD situation these are the tools they have to verify a device has not been tampered with or is not a credential stealing app?

          I can imagine lots of other regimes like sending everybody a physical device like a TOTP generator, but for purely on-device is there another plausible way to do it? In a way where the average person won’t instantly lose their keys/credentials

          1 Reply Last reply
          0
          • pojntfx@mastodon.socialP pojntfx@mastodon.social

            https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

            So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

            Absolutely pathetic

            felurx@troet.cafeF This user is from outside of this forum
            felurx@troet.cafeF This user is from outside of this forum
            felurx@troet.cafe
            wrote sidst redigeret af
            #27

            @pojntfx There is some discussion here: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-development-documentation-public/-/issues?show=eyJpaWQiOiIyIiwiZnVsbF9wYXRoIjoiYm1pL2V1ZGktd2FsbGV0L3dhbGxldC1kZXZlbG9wbWVudC1kb2N1bWVudGF0aW9uLXB1YmxpYyIsImlkIjozMTgzNH0%3D

            1 Reply Last reply
            0
            • pojntfx@mastodon.socialP pojntfx@mastodon.social

              https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

              So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

              Absolutely pathetic

              j9t@mas.toJ This user is from outside of this forum
              j9t@mas.toJ This user is from outside of this forum
              j9t@mas.to
              wrote sidst redigeret af
              #28

              @pojntfx, would be curious if this holds up in court. Also, why would a sovereign nation (and people) accept that. And, way to read the room (US as a security threat).

              1 Reply Last reply
              0
              • pojntfx@mastodon.socialP pojntfx@mastodon.social

                https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                Absolutely pathetic

                odevir@mastodon.socialO This user is from outside of this forum
                odevir@mastodon.socialO This user is from outside of this forum
                odevir@mastodon.social
                wrote sidst redigeret af
                #29

                @pojntfx No Brasil, a Caixa Econômica Federal exige conta no WhatsApp para envio de código para atualização de cadastro de clientes. Quem não tem conta na empresa de Menlo Park não consegue movimentar o aplicativo e as agências não sabem como resolver isso.

                1 Reply Last reply
                0
                • pojntfx@mastodon.socialP pojntfx@mastodon.social

                  @tdelmas The whole remote attestation thing should be dropped from the proposal. The rest of it is unfortunate (no ZKs at all, just signed credentials), but the remote attestation part is truly asinine. I have no idea how and why that decision was made. The people behind this are adding a path dependency on Google/Apple on something as simple as showing your ID to buy alcohol.

                  elopup@mastodon.socialE This user is from outside of this forum
                  elopup@mastodon.socialE This user is from outside of this forum
                  elopup@mastodon.social
                  wrote sidst redigeret af
                  #30

                  @pojntfx @tdelmas

                  What I am always asking myself: The ppl behind this (theoretically) have access to pretty much every expert they want to, how do they still come up with stuff like this?

                  Same story for so many tech related policy proposals…

                  unnon89@nrw.socialU npars01@mstdn.socialN S ori@hj.9fs.netO 4 Replies Last reply
                  0
                  • pojntfx@mastodon.socialP pojntfx@mastodon.social

                    https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                    So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                    Absolutely pathetic

                    jon_bon@toot.catJ This user is from outside of this forum
                    jon_bon@toot.catJ This user is from outside of this forum
                    jon_bon@toot.cat
                    wrote sidst redigeret af
                    #31

                    @pojntfx

                    Oh no... They refer to the text of the ammendment to Eidas called EU Digital Identity Wallet. 🙁 It will be law in december in Sweden, sv, "En statlig e-legitimation", de, "Ein staatlicher elektronischer Ausweis", en, "A government-issued digital ID".

                    So if it will be like in Germany it will be a lock-in in Google Play Integrity and Apple's DCDeviceCheck attestation. Just as I suspected. Hope I will be wrong, but looks really bleak for all EU countries if this will be the outcome of the EU digital wallet thingy... EU sponsorship of the Google/Apple duopoly.😓

                    spacebug@social.n2.mikronod.seS 1 Reply Last reply
                    0
                    • dzwiedziu@mastodon.socialD dzwiedziu@mastodon.social

                      @pojntfx
                      You don't need to wait, nor for the US to be involved.

                      https://electronicintifada.net/blogs/ali-abunimah/eu-sanctions-german-journalist-shocking-first-over-gaza-reporting

                      sassinake@mastodon.socialS This user is from outside of this forum
                      sassinake@mastodon.socialS This user is from outside of this forum
                      sassinake@mastodon.social
                      wrote sidst redigeret af
                      #32

                      @dzwiedziu @pojntfx

                      @pluralistic

                      is this true? Would you look into it?

                      1 Reply Last reply
                      0
                      • pojntfx@mastodon.socialP pojntfx@mastodon.social

                        https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                        So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                        Absolutely pathetic

                        fallbackerik@mastodon.socialF This user is from outside of this forum
                        fallbackerik@mastodon.socialF This user is from outside of this forum
                        fallbackerik@mastodon.social
                        wrote sidst redigeret af
                        #33

                        @pojntfx My understanding is it will require the Apple/Google background services to check that the phone isn't jailbroken etc., and communication with the corresponding servers. But a corresponding account is not necessary for the German ID wallet to work.

                        It's a device check, not an account check.

                        1 Reply Last reply
                        0
                        • elopup@mastodon.socialE elopup@mastodon.social

                          @pojntfx @tdelmas

                          What I am always asking myself: The ppl behind this (theoretically) have access to pretty much every expert they want to, how do they still come up with stuff like this?

                          Same story for so many tech related policy proposals…

                          unnon89@nrw.socialU This user is from outside of this forum
                          unnon89@nrw.socialU This user is from outside of this forum
                          unnon89@nrw.social
                          wrote sidst redigeret af
                          #34

                          @EloPup @pojntfx @tdelmas One word: corruption we have a massive problem with that here <.<

                          hannorein@mastodon.socialH 1 Reply Last reply
                          0
                          • pojntfx@mastodon.socialP pojntfx@mastodon.social

                            https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                            So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                            Absolutely pathetic

                            neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                            neil@mastodon.neilzone.co.ukN This user is from outside of this forum
                            neil@mastodon.neilzone.co.uk
                            wrote sidst redigeret af
                            #35

                            @pojntfx Wait, what?!

                            1 Reply Last reply
                            0
                            • elopup@mastodon.socialE elopup@mastodon.social

                              @pojntfx @tdelmas

                              What I am always asking myself: The ppl behind this (theoretically) have access to pretty much every expert they want to, how do they still come up with stuff like this?

                              Same story for so many tech related policy proposals…

                              npars01@mstdn.socialN This user is from outside of this forum
                              npars01@mstdn.socialN This user is from outside of this forum
                              npars01@mstdn.social
                              wrote sidst redigeret af
                              #36

                              @EloPup @pojntfx @tdelmas

                              Tech companies writing their own rules is a "regulatory hijack"

                              What happens if their age verification app is hacked?
                              Or if these corporations are sold, bankrupt, amalgamated, or nationalized by the state?

                              Privatization or financialization of the means for assuring identification is a very bad idea.

                              Remember who invests in both Google & Apple.
                              https://www.businessinsider.com/saudi-arabia-crown-prince-visits-apple-google-2018-4

                              https://www.cnbc.com/2018/04/07/heres-a-look-at-who.html

                              This is just another effort by fossil fuel funded fascism.

                              1 Reply Last reply
                              0
                              • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                I've said it before an I'll say it again: This entire project of identity verification with Apple/Google-account bound mobile devices is going to lead the continent down a dark, dark path into full technological submission to the US

                                pascaline@mastodon.nlP This user is from outside of this forum
                                pascaline@mastodon.nlP This user is from outside of this forum
                                pascaline@mastodon.nl
                                wrote sidst redigeret af
                                #37

                                @pojntfx

                                It's completely crazy to order the world to submit to Apple/Google.
                                But by now, America has been doing all sorts of things that were unheard of before. They just push to get their way, if necessary start with absurd demands that they will 'tone down' so the others think they reached a compromise but that really gives America what it really wanted.
                                I think most politicians by now turned into profit and ego-driven maniacs, real Wannahaves who adore the Haves.

                                1 Reply Last reply
                                0
                                • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                  https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                  So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                  Absolutely pathetic

                                  ranx@mastodon.socialR This user is from outside of this forum
                                  ranx@mastodon.socialR This user is from outside of this forum
                                  ranx@mastodon.social
                                  wrote sidst redigeret af
                                  #38

                                  @pojntfx Is that what they meant for European Digital Sovereignity? nice... 😏

                                  nordicsprout@norden.socialN 1 Reply Last reply
                                  0
                                  • jon_bon@toot.catJ jon_bon@toot.cat

                                    @pojntfx

                                    Oh no... They refer to the text of the ammendment to Eidas called EU Digital Identity Wallet. 🙁 It will be law in december in Sweden, sv, "En statlig e-legitimation", de, "Ein staatlicher elektronischer Ausweis", en, "A government-issued digital ID".

                                    So if it will be like in Germany it will be a lock-in in Google Play Integrity and Apple's DCDeviceCheck attestation. Just as I suspected. Hope I will be wrong, but looks really bleak for all EU countries if this will be the outcome of the EU digital wallet thingy... EU sponsorship of the Google/Apple duopoly.😓

                                    spacebug@social.n2.mikronod.seS This user is from outside of this forum
                                    spacebug@social.n2.mikronod.seS This user is from outside of this forum
                                    spacebug@social.n2.mikronod.se
                                    wrote sidst redigeret af
                                    #39
                                    @jon_bon @pojntfx Very bad if that's the case. Another service I won't we able to use 😞
                                    1 Reply Last reply
                                    0
                                    • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                      https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                      So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                      Absolutely pathetic

                                      archaide@bonn.socialA This user is from outside of this forum
                                      archaide@bonn.socialA This user is from outside of this forum
                                      archaide@bonn.social
                                      wrote sidst redigeret af
                                      #40

                                      @pojntfx Idiots!

                                      1 Reply Last reply
                                      0
                                      • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                        @sstendahl Yeah, if they used ZKs I can see a way to make it great. But nobody - not one single country, anywhere on earth - is doing that.

                                        And it's not just Play Services here. Those we can emulate with e.g. the EU-funded microG. It's specifically SafetyNet/remote attestation. That one can't be swapped out in any way we currently know. It's a hard dependency on Google.

                                        david@fosstodon.orgD This user is from outside of this forum
                                        david@fosstodon.orgD This user is from outside of this forum
                                        david@fosstodon.org
                                        wrote sidst redigeret af
                                        #41

                                        @pojntfx @sstendahl not sure if this is what you meant, but in the Netherlands the municipality of Nijmegen introduced initial support for Yivi, also available on F-Droid. That seems close, or am I missing something? See: https://docs.yivi.app/

                                        sstendahl@floss.socialS 1 Reply Last reply
                                        0
                                        • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                          https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                          So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                          Absolutely pathetic

                                          gri573@ieji.deG This user is from outside of this forum
                                          gri573@ieji.deG This user is from outside of this forum
                                          gri573@ieji.de
                                          wrote sidst redigeret af
                                          #42

                                          @pojntfx reading the documenta I don't think so... At least as far as I understand they list the available signals and then they state whether these signals are used in the rightmost columns. And the play integrity related signals are listed, but mostly unused, apart from SDK version and whether there are apps that may capture content from the verification app. To quote their description of device integrity:

                                          > rooting via unlocked bootloader, unknown system image (e.g. custom ROM), loss of root of trust (e.g. manipulated boot sequence) + Google proprietary backend MDVM verdict to identify compromised devices (we do not know what they are actually doing in their backend)

                                          They also state that it isn't used.
                                          To me, this actually seems quite good

                                          gri573@ieji.deG 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper