Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
130 Indlæg 99 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • pojntfx@mastodon.socialP pojntfx@mastodon.social

    https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

    So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

    Absolutely pathetic

    isurandil@mastodon.onlineI This user is from outside of this forum
    isurandil@mastodon.onlineI This user is from outside of this forum
    isurandil@mastodon.online
    wrote sidst redigeret af
    #71

    @pojntfx Who wants some of my money for a legal battle against this utter stupidity? 😉

    Can you even use this wallet without a smartphone? From that site it's not clear to me.

    1 Reply Last reply
    0
    • pojntfx@mastodon.socialP pojntfx@mastodon.social

      If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

      schmittlauch@toot.matereal.euS This user is from outside of this forum
      schmittlauch@toot.matereal.euS This user is from outside of this forum
      schmittlauch@toot.matereal.eu
      wrote sidst redigeret af
      #72

      @pojntfx
      Regarding the "not participating in society":
      The eIDAS directive includes a guarantee that identification still needs to be possibly by analog means. So it's at least a loss of comfort, but alternatives must exist.

      Still a bad move.

      1 Reply Last reply
      0
      • ranx@mastodon.socialR ranx@mastodon.social

        @pojntfx Is that what they meant for European Digital Sovereignity? nice... 😏

        nordicsprout@norden.socialN This user is from outside of this forum
        nordicsprout@norden.socialN This user is from outside of this forum
        nordicsprout@norden.social
        wrote sidst redigeret af
        #73

        @ranx @pojntfx when BSI NIS2 registration service started in Germany they set it up on AWS infrastructure, right after they voted for digital sovereignty. So who is wondering about such decisions?

        1 Reply Last reply
        0
        • pojntfx@mastodon.socialP pojntfx@mastodon.social

          https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

          So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

          Absolutely pathetic

          forthy42@mastodon.net2o.deF This user is from outside of this forum
          forthy42@mastodon.net2o.deF This user is from outside of this forum
          forthy42@mastodon.net2o.de
          wrote sidst redigeret af
          #74

          @pojntfx I read to non-duplication of the keys, so I'm now confident they are completely incompetent. This is the security approach you would use for a entry system, i.e. a digital key to open a door, and you want to keep the same rules you had before for people who were granted access: one key per person, and when you fire that person or restrict their access to that door, you get the key back.

          This is not what the ID wallet is about: it's about replacing a written signature, and showing official documents that are bound to a person. It is no problem at all to have those copied on multiple devices, as long as you check that it's the right person accessing the wallet the moment it creates a signature or shows an ID card.

          On the other hand, the single non-copy device still allows the Steffie Graf autograph attack, or, for key entry: you could temporarily lend your unique key to someone else who uses it to enter the secret room and takes out things or data or whatever, and afterwards returns the key to you (you can even pretend it was stolen and returned without you noticing). The actually required access control doesn't happen, but instead some bullshit happens, especially, your valuable IDs, certificates etc. are now bound to a device that can get lost or break, without easy backup.

          rainer@johnmastodon.euR 1 Reply Last reply
          0
          • pojntfx@mastodon.socialP pojntfx@mastodon.social

            https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

            So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

            Absolutely pathetic

            jesterchen@social.tchncs.deJ This user is from outside of this forum
            jesterchen@social.tchncs.deJ This user is from outside of this forum
            jesterchen@social.tchncs.de
            wrote sidst redigeret af
            #75

            @pojntfx @BMDS @bfdi @bsi Hey, was sagt denn ihr so dazu, hmmm?

            jesterchen@social.tchncs.deJ 1 Reply Last reply
            0
            • jesterchen@social.tchncs.deJ jesterchen@social.tchncs.de

              @pojntfx @BMDS @bfdi @bsi Hey, was sagt denn ihr so dazu, hmmm?

              jesterchen@social.tchncs.deJ This user is from outside of this forum
              jesterchen@social.tchncs.deJ This user is from outside of this forum
              jesterchen@social.tchncs.de
              wrote sidst redigeret af
              #76

              @pojntfx Oder auch @dsk @CCC @echo_pbreyer @digitalcourage :

              Was haltet ihr von eID, die nur über Google/Apple funktionieren?

              1 Reply Last reply
              0
              • forthy42@mastodon.net2o.deF forthy42@mastodon.net2o.de

                @pojntfx I read to non-duplication of the keys, so I'm now confident they are completely incompetent. This is the security approach you would use for a entry system, i.e. a digital key to open a door, and you want to keep the same rules you had before for people who were granted access: one key per person, and when you fire that person or restrict their access to that door, you get the key back.

                This is not what the ID wallet is about: it's about replacing a written signature, and showing official documents that are bound to a person. It is no problem at all to have those copied on multiple devices, as long as you check that it's the right person accessing the wallet the moment it creates a signature or shows an ID card.

                On the other hand, the single non-copy device still allows the Steffie Graf autograph attack, or, for key entry: you could temporarily lend your unique key to someone else who uses it to enter the secret room and takes out things or data or whatever, and afterwards returns the key to you (you can even pretend it was stolen and returned without you noticing). The actually required access control doesn't happen, but instead some bullshit happens, especially, your valuable IDs, certificates etc. are now bound to a device that can get lost or break, without easy backup.

                rainer@johnmastodon.euR This user is from outside of this forum
                rainer@johnmastodon.euR This user is from outside of this forum
                rainer@johnmastodon.eu
                wrote sidst redigeret af
                #77

                @forthy42 @pojntfx I guess the (not-so-easy) backup method would be to acquire eIDs from multiple member states (the Estonian e-residence would probably be one of the easier additional ones to get) and then rely on the cross-border mutual recognition which I believe EIDAS guarantees? I hope the German wallet will work with other European eIDs?
                Would this address the issue if one still needs some approved device with Google Play Services and some Google profile?

                1 Reply Last reply
                0
                • pojntfx@mastodon.socialP pojntfx@mastodon.social

                  https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                  So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                  Absolutely pathetic

                  paoloredaelli@mastodon.unoP This user is from outside of this forum
                  paoloredaelli@mastodon.unoP This user is from outside of this forum
                  paoloredaelli@mastodon.uno
                  wrote sidst redigeret af
                  #78

                  @pojntfx
                  And we shall refuse to use it!

                  1 Reply Last reply
                  0
                  • larymir@chaos.socialL larymir@chaos.social

                    @fallbackerik @pojntfx @arjen the existence of other apps which were downloaded from other stores/spurces wouldn't be an issue
                    But if you use a phone without Google play services (e.g. lineageOS (although play services can be added later) or grapheneOS) or a rooted phone you won't be able to use that app at all
                    Maybe just having an unlocked bootloader would keep you from using it (that depends on what level of the device integrity the app requires)

                    larymir@chaos.socialL This user is from outside of this forum
                    larymir@chaos.socialL This user is from outside of this forum
                    larymir@chaos.social
                    wrote sidst redigeret af
                    #79

                    @fallbackerik @pojntfx @arjen with an unlocked bootloader (even if you didn't modify the system in any way (although having an unlocked bootloader just for fun isn't a good idea. But it is necessary if you want to install custom ROMs. So if the manufacturer of your phone adds some stuff you don't want and you just want to install vanilla android (without root and with Google play services) you need to unlock your bootloader)) you fail the play protect certification

                    1 Reply Last reply
                    0
                    • bebef@mastodon.socialB bebef@mastodon.social

                      @pojntfx Thing is: we must NEVER accept any digital-only solution for things like this (IDs, license etc.). Analouge/offline life must ALWAYS be possible!

                      ...regardless of where it's hosted.

                      makeitmythic@mastodon.socialM This user is from outside of this forum
                      makeitmythic@mastodon.socialM This user is from outside of this forum
                      makeitmythic@mastodon.social
                      wrote sidst redigeret af
                      #80

                      @Bebef @pojntfx yeah, i know you can take a picture of your license here in the us and give your phone to a cop in some places, but i would never. rather just hand over my physical license card i paid way too much money for and always carry with me outside the house. just like my phone, but im not handing that to anyone, nor my physical wallet.

                      bebef@mastodon.socialB 1 Reply Last reply
                      0
                      • pojntfx@mastodon.socialP pojntfx@mastodon.social

                        If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                        wiebiwetter@norden.socialW This user is from outside of this forum
                        wiebiwetter@norden.socialW This user is from outside of this forum
                        wiebiwetter@norden.social
                        wrote sidst redigeret af
                        #81

                        Sorry, digital drivers license and Germany? I cannot make these ends meet.

                        Felicitas Pojtinger 🌅
                        @pojntfx
                        If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                        1 Reply Last reply
                        0
                        • pojntfx@mastodon.socialP pojntfx@mastodon.social

                          If a German citizen gets sanctioned by the US government, once this is implemented (later this year), that means they will no longer be able to be a participating member of German society, e.g. to show their (digital) driver's license to traffic police

                          saupreiss@pfalz.socialS This user is from outside of this forum
                          saupreiss@pfalz.socialS This user is from outside of this forum
                          saupreiss@pfalz.social
                          wrote sidst redigeret af
                          #82

                          @pojntfx

                          It is TOTALLY unrealistic this project even works by end of the year. And then it’s gonna been shutdown five to 20 times because of mostly naive yet fundamental design flaws.

                          1 Reply Last reply
                          0
                          • makeitmythic@mastodon.socialM makeitmythic@mastodon.social

                            @Bebef @pojntfx yeah, i know you can take a picture of your license here in the us and give your phone to a cop in some places, but i would never. rather just hand over my physical license card i paid way too much money for and always carry with me outside the house. just like my phone, but im not handing that to anyone, nor my physical wallet.

                            bebef@mastodon.socialB This user is from outside of this forum
                            bebef@mastodon.socialB This user is from outside of this forum
                            bebef@mastodon.social
                            wrote sidst redigeret af
                            #83

                            @makeitmythic @pojntfx "Too much money" is a funny thing to say for a US driving license. German prices are in the $4k ball park.

                            Not trying to diminish anything, just giving a point of reference.

                            makeitmythic@mastodon.socialM 1 Reply Last reply
                            0
                            • pojntfx@mastodon.socialP pojntfx@mastodon.social

                              https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                              So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                              Absolutely pathetic

                              M This user is from outside of this forum
                              M This user is from outside of this forum
                              manul70@mastodon.social
                              wrote sidst redigeret af
                              #84

                              @pojntfx This is european retardation not exclusif to germany

                              1 Reply Last reply
                              0
                              • larymir@chaos.socialL larymir@chaos.social

                                @fallbackerik @pojntfx @arjen the existence of other apps which were downloaded from other stores/spurces wouldn't be an issue
                                But if you use a phone without Google play services (e.g. lineageOS (although play services can be added later) or grapheneOS) or a rooted phone you won't be able to use that app at all
                                Maybe just having an unlocked bootloader would keep you from using it (that depends on what level of the device integrity the app requires)

                                fallbackerik@mastodon.socialF This user is from outside of this forum
                                fallbackerik@mastodon.socialF This user is from outside of this forum
                                fallbackerik@mastodon.social
                                wrote sidst redigeret af
                                #85

                                @Larymir @pojntfx @arjen Fully agreeing with that assessment. But it still is another requirement than needing a Google account.

                                larymir@chaos.socialL 1 Reply Last reply
                                0
                                • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                  I've said it before an I'll say it again: This entire project of identity verification with Apple/Google-account bound mobile devices is going to lead the continent down a dark, dark path into full technological submission to the US

                                  mjsberna@infosec.exchangeM This user is from outside of this forum
                                  mjsberna@infosec.exchangeM This user is from outside of this forum
                                  mjsberna@infosec.exchange
                                  wrote sidst redigeret af
                                  #86

                                  @pojntfx
                                  Is it a Telekom-SAP project?

                                  1 Reply Last reply
                                  0
                                  • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                    I've said it before an I'll say it again: This entire project of identity verification with Apple/Google-account bound mobile devices is going to lead the continent down a dark, dark path into full technological submission to the US

                                    maya_b@hachyderm.ioM This user is from outside of this forum
                                    maya_b@hachyderm.ioM This user is from outside of this forum
                                    maya_b@hachyderm.io
                                    wrote sidst redigeret af
                                    #87

                                    @pojntfx

                                    it'll probably be even more fun for non-resident (dual) citizens who don't (for whatever reason) have a based in Germany mobile phone account - and thus have no access to install whatever authentication mechanism is required.

                                    1 Reply Last reply
                                    0
                                    • pojntfx@mastodon.socialP pojntfx@mastodon.social

                                      https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

                                      So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

                                      Absolutely pathetic

                                      maya_b@hachyderm.ioM This user is from outside of this forum
                                      maya_b@hachyderm.ioM This user is from outside of this forum
                                      maya_b@hachyderm.io
                                      wrote sidst redigeret af
                                      #88

                                      @pojntfx

                                      the Estonian eID system seems to work pretty well and doesn't require any 3rd party corporate account to work.

                                      even works for e-Residents who don't live in Estonia, nor have Estonian citizenship

                                      1 Reply Last reply
                                      0
                                      • sstendahl@floss.socialS sstendahl@floss.social

                                        @david @pojntfx I was mostly thinking of NLWallet, which is actually government backed/owned. As far as I know it’s ZKP, and it’s even open-ish (not GPL, but at least source-available). You can build it from source yourself.

                                        But I’m not as knowledgeable on the matter as @pojntfx, so I could absolutely be missing something here on the implementation of zero knowledge here.

                                        See their GitHub page here: https://github.com/MinBZK/nl-wallet

                                        conamara@eupolicy.socialC This user is from outside of this forum
                                        conamara@eupolicy.socialC This user is from outside of this forum
                                        conamara@eupolicy.social
                                        wrote sidst redigeret af
                                        #89

                                        @sstendahl @david @pojntfx is yivi operating on the same trust level?

                                        1 Reply Last reply
                                        0
                                        • bebef@mastodon.socialB bebef@mastodon.social

                                          @makeitmythic @pojntfx "Too much money" is a funny thing to say for a US driving license. German prices are in the $4k ball park.

                                          Not trying to diminish anything, just giving a point of reference.

                                          makeitmythic@mastodon.socialM This user is from outside of this forum
                                          makeitmythic@mastodon.socialM This user is from outside of this forum
                                          makeitmythic@mastodon.social
                                          wrote sidst redigeret af
                                          #90

                                          @Bebef @pojntfx yeah, i only had to pay like $80 here, but where im originally from it was only like $30 per ~8 years. it cost me $300 to take drivers ed where im from. it looks like to get a license in germany wout lessons its ~425 euro, according to the us embassy website.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper