Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
130 Indlæg 99 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • pojntfx@mastodon.socialP pojntfx@mastodon.social

    https://mastodon.social/@pojntfx/116345725515845020

    A bit of an explanation

    sstendahl@floss.socialS This user is from outside of this forum
    sstendahl@floss.socialS This user is from outside of this forum
    sstendahl@floss.social
    wrote sidst redigeret af
    #9

    @pojntfx Honestly I will remain off the opinion the digital wallets are by itself a good idea, and could potentially be more privacy-friendly than traditional methods (thanks to granular sharing of information) and lessen dependence on big tech (the alternative is namely that the private market will do this).

    Having said that, that’s only if implemented right. A dependency on Google Play services is worrying, and shows we still haven’t learned anything from the past years.

    pojntfx@mastodon.socialP 1 Reply Last reply
    0
    • sstendahl@floss.socialS sstendahl@floss.social

      @pojntfx Honestly I will remain off the opinion the digital wallets are by itself a good idea, and could potentially be more privacy-friendly than traditional methods (thanks to granular sharing of information) and lessen dependence on big tech (the alternative is namely that the private market will do this).

      Having said that, that’s only if implemented right. A dependency on Google Play services is worrying, and shows we still haven’t learned anything from the past years.

      pojntfx@mastodon.socialP This user is from outside of this forum
      pojntfx@mastodon.socialP This user is from outside of this forum
      pojntfx@mastodon.social
      wrote sidst redigeret af
      #10

      @sstendahl Yeah, if they used ZKs I can see a way to make it great. But nobody - not one single country, anywhere on earth - is doing that.

      And it's not just Play Services here. Those we can emulate with e.g. the EU-funded microG. It's specifically SafetyNet/remote attestation. That one can't be swapped out in any way we currently know. It's a hard dependency on Google.

      david@fosstodon.orgD 1 Reply Last reply
      0
      • pojntfx@mastodon.socialP pojntfx@mastodon.social

        @tdelmas The whole remote attestation thing should be dropped from the proposal. The rest of it is unfortunate (no ZKs at all, just signed credentials), but the remote attestation part is truly asinine. I have no idea how and why that decision was made. The people behind this are adding a path dependency on Google/Apple on something as simple as showing your ID to buy alcohol.

        lunadragofelis@void.lgbtL This user is from outside of this forum
        lunadragofelis@void.lgbtL This user is from outside of this forum
        lunadragofelis@void.lgbt
        wrote sidst redigeret af
        #11
        @pojntfx @tdelmas they probably haven't given that decision much thought at all, and just do it because almost every other "secure" app (like banking apps) do the same bullshit
        schouten_b@mastodon.socialS benedikt@ruhr.socialB 2 Replies Last reply
        0
        • pojntfx@mastodon.socialP pojntfx@mastodon.social

          https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

          So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

          Absolutely pathetic

          1024bytes@masto.ai1 This user is from outside of this forum
          1024bytes@masto.ai1 This user is from outside of this forum
          1024bytes@masto.ai
          wrote sidst redigeret af
          #12

          @pojntfx Ehh.. What ? That's a stupid bad implementation.

          1 Reply Last reply
          0
          • pojntfx@mastodon.socialP pojntfx@mastodon.social

            https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

            So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

            Absolutely pathetic

            hauswirtschaft_info@hostsharing.coopH This user is from outside of this forum
            hauswirtschaft_info@hostsharing.coopH This user is from outside of this forum
            hauswirtschaft_info@hostsharing.coop
            wrote sidst redigeret af
            #13

            Hallo @bsi,
            stimmt es, dass #eDIAS nur mit Apple-/Google-Account funktioniert?
            Derlei hätte ich nicht zur Verfügung.
            Wird es Alternativen geben?

            PS: Dank an @pojntfx für diesen Hinweis.

            1 Reply Last reply
            0
            • pojntfx@mastodon.socialP pojntfx@mastodon.social

              @arjen SafetyNet checks only pass on devices with unchanged, factory-sealed, non-unlockable firmware. Google has an allowlist of devices that pass that test. The same remote attestation mechanism is also used to block downloading the app through anything other than the Google Play Store, which you need a Google Account for. And you can't use Google if you're on the US sanction list (see e.g. the ICC prosecuter case). Using any open source OS of any type is also completely impossible.

              annehargreaves@ioc.exchangeA This user is from outside of this forum
              annehargreaves@ioc.exchangeA This user is from outside of this forum
              annehargreaves@ioc.exchange
              wrote sidst redigeret af
              #14

              @pojntfx @arjen Oh so it's a no for degoogled phones then?

              1 Reply Last reply
              0
              • pojntfx@mastodon.socialP pojntfx@mastodon.social

                https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                Absolutely pathetic

                acmeworks@social.tchncs.deA This user is from outside of this forum
                acmeworks@social.tchncs.deA This user is from outside of this forum
                acmeworks@social.tchncs.de
                wrote sidst redigeret af
                #15

                @pojntfx I'm not surprised but still disappointed.

                1 Reply Last reply
                0
                • pojntfx@mastodon.socialP pojntfx@mastodon.social

                  https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                  So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                  Absolutely pathetic

                  landelare@mastodon.gamedev.placeL This user is from outside of this forum
                  landelare@mastodon.gamedev.placeL This user is from outside of this forum
                  landelare@mastodon.gamedev.place
                  wrote sidst redigeret af
                  #16

                  @pojntfx Sounds sovereign 👍

                  1 Reply Last reply
                  0
                  • pojntfx@mastodon.socialP pojntfx@mastodon.social

                    https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                    So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                    Absolutely pathetic

                    ujay68@mastodon.worldU This user is from outside of this forum
                    ujay68@mastodon.worldU This user is from outside of this forum
                    ujay68@mastodon.world
                    wrote sidst redigeret af
                    #17

                    @pojntfx I just don’t get it. In Germany, we have electronic ID cards with built-in secure and privacy-friendly age verification that does not even disclose the actual birthdate or identity. And we’ve had these for like, 15 years? So, regardless of whether we like age verification in principle or not, the sovereign technology is there!

                    1 Reply Last reply
                    0
                    • pojntfx@mastodon.socialP pojntfx@mastodon.social

                      https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                      So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                      Absolutely pathetic

                      apz@some.apz.fiA This user is from outside of this forum
                      apz@some.apz.fiA This user is from outside of this forum
                      apz@some.apz.fi
                      wrote sidst redigeret af
                      #18

                      @pojntfx It appears to be more of a rule that all the government projects are like this. Our national ID system here in Finland is also bit of a shit show, where Linux is technically supported but the software is god awful and buggy.

                      1 Reply Last reply
                      0
                      • pojntfx@mastodon.socialP pojntfx@mastodon.social

                        If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                        mjarteaga@oslo.townM This user is from outside of this forum
                        mjarteaga@oslo.townM This user is from outside of this forum
                        mjarteaga@oslo.town
                        wrote sidst redigeret af
                        #19

                        @pojntfx This scenario raises two main conflicts:
                        Availability and Access: The GDPR and EU principles require that access to fundamental rights not depend on third countries. Forcing a citizen to accept the terms and conditions of a private U.S. company in order to use their state-issued identity is viewed by many regulators as coercion that invalidates the “free consent” required by the GDPR. 1/2

                        elexia@catcatnya.comE mjarteaga@oslo.townM 4 Replies Last reply
                        0
                        • pojntfx@mastodon.socialP pojntfx@mastodon.social

                          If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                          mjarteaga@oslo.townM This user is from outside of this forum
                          mjarteaga@oslo.townM This user is from outside of this forum
                          mjarteaga@oslo.town
                          wrote sidst redigeret af
                          #20

                          @pojntfx Extraterritorial Surveillance:

                          There is a theoretical risk that, because it is integrated into the OS ecosystem, the manufacturer (under laws such as the U.S. Cloud Act) could be compelled to provide metadata on when and where the wallet is used, which conflicts with the GDPR’s prohibition on tracking. 2/2

                          1 Reply Last reply
                          0
                          • pojntfx@mastodon.socialP pojntfx@mastodon.social

                            If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                            dzwiedziu@mastodon.socialD This user is from outside of this forum
                            dzwiedziu@mastodon.socialD This user is from outside of this forum
                            dzwiedziu@mastodon.social
                            wrote sidst redigeret af
                            #21

                            @pojntfx
                            You don't need to wait, nor for the US to be involved.

                            https://electronicintifada.net/blogs/ali-abunimah/eu-sanctions-german-journalist-shocking-first-over-gaza-reporting

                            sassinake@mastodon.socialS 1 Reply Last reply
                            0
                            • pojntfx@mastodon.socialP pojntfx@mastodon.social

                              https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                              So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                              Absolutely pathetic

                              craignicol@glasgow.socialC This user is from outside of this forum
                              craignicol@glasgow.socialC This user is from outside of this forum
                              craignicol@glasgow.social
                              wrote sidst redigeret af
                              #22

                              @pojntfx so, totally understood the EU desire for digital sovereignty then? 🤦

                              1 Reply Last reply
                              0
                              • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                Absolutely pathetic

                                argyle13@xarxa.cloudA This user is from outside of this forum
                                argyle13@xarxa.cloudA This user is from outside of this forum
                                argyle13@xarxa.cloud
                                wrote sidst redigeret af
                                #23

                                @pojntfx this is unacceptable

                                1 Reply Last reply
                                0
                                • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                  https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                  So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                  Absolutely pathetic

                                  daumenlutscher@fedifreu.deD This user is from outside of this forum
                                  daumenlutscher@fedifreu.deD This user is from outside of this forum
                                  daumenlutscher@fedifreu.de
                                  wrote sidst redigeret af
                                  #24

                                  @pojntfx
                                  Germany is such a mess; they’re just useless, and there’s plenty of that

                                  1 Reply Last reply
                                  0
                                  • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                    https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                    So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                    Absolutely pathetic

                                    gvlx@masto.ptG This user is from outside of this forum
                                    gvlx@masto.ptG This user is from outside of this forum
                                    gvlx@masto.pt
                                    wrote sidst redigeret af
                                    #25

                                    @pojntfx Same thing for Portuguese #eID, which had been working fine for more than 10 years, and was Open Source.

                                    Now the source is no longer available and refuses to work on de-googled devices.

                                    #europe #portugal

                                    1 Reply Last reply
                                    0
                                    • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                      https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                      So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                      Absolutely pathetic

                                      neilk@xoxo.zoneN This user is from outside of this forum
                                      neilk@xoxo.zoneN This user is from outside of this forum
                                      neilk@xoxo.zone
                                      wrote sidst redigeret af
                                      #26

                                      @pojntfx Skimmed it and I’m not sure that they are embedding dependence on Google or Apple so much as recognizing that in a BYOD situation these are the tools they have to verify a device has not been tampered with or is not a credential stealing app?

                                      I can imagine lots of other regimes like sending everybody a physical device like a TOTP generator, but for purely on-device is there another plausible way to do it? In a way where the average person won’t instantly lose their keys/credentials

                                      1 Reply Last reply
                                      0
                                      • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                        https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                        So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                        Absolutely pathetic

                                        felurx@troet.cafeF This user is from outside of this forum
                                        felurx@troet.cafeF This user is from outside of this forum
                                        felurx@troet.cafe
                                        wrote sidst redigeret af
                                        #27

                                        @pojntfx There is some discussion here: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-development-documentation-public/-/issues?show=eyJpaWQiOiIyIiwiZnVsbF9wYXRoIjoiYm1pL2V1ZGktd2FsbGV0L3dhbGxldC1kZXZlbG9wbWVudC1kb2N1bWVudGF0aW9uLXB1YmxpYyIsImlkIjozMTgzNH0%3D

                                        1 Reply Last reply
                                        0
                                        • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                          https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                          So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                          Absolutely pathetic

                                          j9t@mas.toJ This user is from outside of this forum
                                          j9t@mas.toJ This user is from outside of this forum
                                          j9t@mas.to
                                          wrote sidst redigeret af
                                          #28

                                          @pojntfx, would be curious if this holds up in court. Also, why would a sovereign nation (and people) accept that. And, way to read the room (US as a security threat).

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper