Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
130 Indlæg 99 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mjarteaga@oslo.townM mjarteaga@oslo.town

    @pojntfx This scenario raises two main conflicts:
    Availability and Access: The GDPR and EU principles require that access to fundamental rights not depend on third countries. Forcing a citizen to accept the terms and conditions of a private U.S. company in order to use their state-issued identity is viewed by many regulators as coercion that invalidates the “free consent” required by the GDPR. 1/2

    mjarteaga@oslo.townM This user is from outside of this forum
    mjarteaga@oslo.townM This user is from outside of this forum
    mjarteaga@oslo.town
    wrote sidst redigeret af
    #98

    @pojntfx Mitigation Measures in Germany and the EU 2/3

    Interoperability between Member States: According to the regulation, if the German wallet fails due to a lockout, citizens should be able to legally use any other certified wallet from another EU country to identify themselves for German services.

    1 Reply Last reply
    0
    • mjarteaga@oslo.townM mjarteaga@oslo.town

      @pojntfx This scenario raises two main conflicts:
      Availability and Access: The GDPR and EU principles require that access to fundamental rights not depend on third countries. Forcing a citizen to accept the terms and conditions of a private U.S. company in order to use their state-issued identity is viewed by many regulators as coercion that invalidates the “free consent” required by the GDPR. 1/2

      mjarteaga@oslo.townM This user is from outside of this forum
      mjarteaga@oslo.townM This user is from outside of this forum
      mjarteaga@oslo.town
      wrote sidst redigeret af
      #99

      @pojntfx Mitigation Measures in Germany and the EU 3/3

      Physical media as a backup: Germany maintains the physical ID card with a chip (nPA) as the primary “source of truth.” The wallet is only a digital representation; if the phone fails or is locked, the citizen can always use their physical card and a standard NFC reader to identify themselves. https://ec.europa.eu/commission/presscorner/detail/en/ip_24_3433
      https://www.vzbv.de/en/digital-markets-act-apple-and-google-fail-comply-certain-regulations
      https://www.reddit.com/r/europrivacy/s/mgTR3gEoAr

      1 Reply Last reply
      0
      • pojntfx@mastodon.socialP pojntfx@mastodon.social

        https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

        So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

        Absolutely pathetic

        strule@bolha.oneS This user is from outside of this forum
        strule@bolha.oneS This user is from outside of this forum
        strule@bolha.one
        wrote sidst redigeret af
        #100

        @pojntfx that's just stupid

        1 Reply Last reply
        0
        • pojntfx@mastodon.socialP pojntfx@mastodon.social

          https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

          So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

          Absolutely pathetic

          project1enigma@chaos.socialP This user is from outside of this forum
          project1enigma@chaos.socialP This user is from outside of this forum
          project1enigma@chaos.social
          wrote sidst redigeret af
          #101

          @pojntfx I knew.

          project1enigma@chaos.socialP 1 Reply Last reply
          0
          • project1enigma@chaos.socialP project1enigma@chaos.social

            @pojntfx I knew.

            project1enigma@chaos.socialP This user is from outside of this forum
            project1enigma@chaos.socialP This user is from outside of this forum
            project1enigma@chaos.social
            wrote sidst redigeret af
            #102

            @pojntfx

            Like when people argued that age verification is ok bc it can be implemented in a zero knowledge way, I knew that it would never be actually done like that.

            1 Reply Last reply
            0
            • hannorein@mastodon.socialH hannorein@mastodon.social

              @unnon89 @EloPup @pojntfx @tdelmas I don't know. I think incompetence can not be ruled out either. Hard call.

              wronglang@bayes.clubW This user is from outside of this forum
              wronglang@bayes.clubW This user is from outside of this forum
              wronglang@bayes.club
              wrote sidst redigeret af
              #103

              @hannorein @unnon89 @EloPup @pojntfx @tdelmas both?

              1 Reply Last reply
              0
              • pojntfx@mastodon.socialP pojntfx@mastodon.social

                If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                alatiera@mastodon.socialA This user is from outside of this forum
                alatiera@mastodon.socialA This user is from outside of this forum
                alatiera@mastodon.social
                wrote sidst redigeret af
                #104

                @pojntfx If you get sanctioned by the US, like the ICC judge Nicolas Guillou, you are already fucked.

                There is also an even worse case, where the EU has decided to effectively unperson Hüseyin Doğru over his reporting on Gaza and not only can he not participate in a society, its illegal for any EU citizen to even give him money to not starve.

                I think we are doing pretty well even without the digital ID.

                1 Reply Last reply
                0
                • tdelmas@mamot.frT tdelmas@mamot.fr

                  @pojntfx that Google dependency is unacceptable. That said, there is no reason (other than "they want to") to require a Google account to use the Play store (to download free apps). From a GDPR perspective, that is already a breach of the law, and already should have been fixed.

                  roxystar@mastodon.socialR This user is from outside of this forum
                  roxystar@mastodon.socialR This user is from outside of this forum
                  roxystar@mastodon.social
                  wrote sidst redigeret af
                  #105

                  @tdelmas @pojntfx hi, Peruvian 🇵🇪 here... most of the bank apps on my phone stopped working after I removed the Google Play services.

                  Is like I couldn't use my own money because I didn't give away my personal information, huh.

                  1 Reply Last reply
                  0
                  • ahasty@techhub.socialA ahasty@techhub.social

                    @hannorein @unnon89 @EloPup @pojntfx @tdelmas never attribute malice to that which can be adequately explained by stupidity.

                    leadore@sunny.gardenL This user is from outside of this forum
                    leadore@sunny.gardenL This user is from outside of this forum
                    leadore@sunny.garden
                    wrote sidst redigeret af
                    #106

                    @ahasty @hannorein @unnon89 @EloPup @pojntfx @tdelmas

                    Why not both?

                    1 Reply Last reply
                    0
                    • pojntfx@mastodon.socialP pojntfx@mastodon.social

                      https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                      So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                      Absolutely pathetic

                      r4d10_411310p47hy@hispagatos.spaceR This user is from outside of this forum
                      r4d10_411310p47hy@hispagatos.spaceR This user is from outside of this forum
                      r4d10_411310p47hy@hispagatos.space
                      wrote sidst redigeret af
                      #107

                      @pojntfx codifying the use of AmeriKKKan tech is a really stupid autonomy move... And that doesn't even scrape the surface of reasons this is going to be really, really bad for privacy. Dumb as hell.

                      1 Reply Last reply
                      0
                      • pojntfx@mastodon.socialP pojntfx@mastodon.social

                        https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                        So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                        Absolutely pathetic

                        ell1e@hachyderm.ioE This user is from outside of this forum
                        ell1e@hachyderm.ioE This user is from outside of this forum
                        ell1e@hachyderm.io
                        wrote sidst redigeret af
                        #108

                        @pojntfx I wonder, why isn't anybody writing about EU age attestation in the first place? https://leminal.space/post/31858818/21120139

                        1 Reply Last reply
                        0
                        • larymir@chaos.socialL larymir@chaos.social

                          @fallbackerik @pojntfx @arjen so yeah, good point, maybe you don't need an account, but it still wouldn't work an a degoogled phone
                          So maybe it's not as bad, but still bad

                          And I'm not sure if people who are banned from having a Google account are also forbidden from using those other Google services (without an account)
                          (Of course you could still just use them, how will they know it's you? But we shouldn't expect people to break end user agreements)

                          debacle@framapiaf.orgD This user is from outside of this forum
                          debacle@framapiaf.orgD This user is from outside of this forum
                          debacle@framapiaf.org
                          wrote sidst redigeret af
                          #109

                          @Larymir @fallbackerik @pojntfx @arjen

                          It's broken, if it depends on Android (or iOS). It should run on other OSes, too, such as #Linux on PCs or on my #smartphone which runs #Mobian.

                          1 Reply Last reply
                          0
                          • pojntfx@mastodon.socialP pojntfx@mastodon.social

                            If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                            ntropic@chaos.socialN This user is from outside of this forum
                            ntropic@chaos.socialN This user is from outside of this forum
                            ntropic@chaos.social
                            wrote sidst redigeret af
                            #110

                            @pojntfx Can my government please start following the law or at least try to...

                            1 Reply Last reply
                            0
                            • lunadragofelis@void.lgbtL lunadragofelis@void.lgbt
                              @pojntfx @tdelmas they probably haven't given that decision much thought at all, and just do it because almost every other "secure" app (like banking apps) do the same bullshit
                              benedikt@ruhr.socialB This user is from outside of this forum
                              benedikt@ruhr.socialB This user is from outside of this forum
                              benedikt@ruhr.social
                              wrote sidst redigeret af
                              #111

                              @LunaDragofelis @tdelmas @pojntfx this issue was addressed eight months ago via their GitLab repo, so hopefully they've thought about it, but still they didn't change anything: https://gitlab.opencode.de/bmi/eudi-wallet/wallet-development-documentation-public/-/issues/2

                              1 Reply Last reply
                              0
                              • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                @tdelmas The whole remote attestation thing should be dropped from the proposal. The rest of it is unfortunate (no ZKs at all, just signed credentials), but the remote attestation part is truly asinine. I have no idea how and why that decision was made. The people behind this are adding a path dependency on Google/Apple on something as simple as showing your ID to buy alcohol.

                                ww@xyzzy.linkW This user is from outside of this forum
                                ww@xyzzy.linkW This user is from outside of this forum
                                ww@xyzzy.link
                                wrote sidst redigeret af
                                #112
                                @pojntfx @tdelmas as long as age checks are anonymous and allow a generous ratelimit, remote attestation is required to maintain the integrity of the system, that's probably why

                                like, if i can make a custom android rom and automate issuing age proofs, then transmit them anywhere i want, then i can also create a fake miniwallet that would allow anyone to pass the age verification flow using my proofs. for a low price of 5 euros!

                                i personally don't think that age verification is a good idea, and even if it has to happen, remote attestation creates more problems than it solves. people will find ways to bypass age checks regardless, so this only closes one of the gaps, while excluding a fair amount of people. but i imagine this was one of the concerns that led to the decision to make it a requirement.
                                1 Reply Last reply
                                0
                                • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                  https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                  So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                  Absolutely pathetic

                                  pavel@social.kernel.orgP This user is from outside of this forum
                                  pavel@social.kernel.orgP This user is from outside of this forum
                                  pavel@social.kernel.org
                                  wrote sidst redigeret af
                                  #113
                                  @pojntfx So Apple/Google can collect your data? And so Trump can shut you down? That is ... not good. That should not be legal.
                                  1 Reply Last reply
                                  0
                                  • ahasty@techhub.socialA ahasty@techhub.social

                                    @hannorein @unnon89 @EloPup @pojntfx @tdelmas never attribute malice to that which can be adequately explained by stupidity.

                                    zombiecide@polyglot.cityZ This user is from outside of this forum
                                    zombiecide@polyglot.cityZ This user is from outside of this forum
                                    zombiecide@polyglot.city
                                    wrote sidst redigeret af
                                    #114

                                    @ahasty any reasonably advanced stupidity is indistinguishable from malice

                                    ahasty@techhub.socialA 1 Reply Last reply
                                    0
                                    • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                      https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                      So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                      Absolutely pathetic

                                      ww@xyzzy.linkW This user is from outside of this forum
                                      ww@xyzzy.linkW This user is from outside of this forum
                                      ww@xyzzy.link
                                      wrote sidst redigeret af
                                      #115
                                      @pojntfx i wonder if they'll do anything to support huawei phones. according to statcounter, that's 1.6% of the german market!
                                      1 Reply Last reply
                                      0
                                      • zombiecide@polyglot.cityZ zombiecide@polyglot.city

                                        @ahasty any reasonably advanced stupidity is indistinguishable from malice

                                        ahasty@techhub.socialA This user is from outside of this forum
                                        ahasty@techhub.socialA This user is from outside of this forum
                                        ahasty@techhub.social
                                        wrote sidst redigeret af
                                        #116

                                        @zombiecide the real malice is how society seems to give the most power to the stupidest people

                                        zombiecide@polyglot.cityZ 2 Replies Last reply
                                        0
                                        • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                          https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                          So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                          Absolutely pathetic

                                          scatty_hannah@federation.networkS This user is from outside of this forum
                                          scatty_hannah@federation.networkS This user is from outside of this forum
                                          scatty_hannah@federation.network
                                          wrote sidst redigeret af
                                          #117

                                          @pojntfx@mastodon.social this is what I feared and anticipated.

                                          I'm a nerd and early adoptor usually but I'm going more and more offline when it comes to state sanctioned digitalisation efforts as they try to cage me in.

                                          I'm running GrapheneOS - I already can't use most of the mandated apps from my public health insurance as they insist on Google/Apple lock-in.

                                          It's pathetic especially since it is entirely possible to get the same security guarantees using Android APIs alone.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper