9 ms·
German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this u
by haagch 6mo ago
German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices?
Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.
- dark-star 6mo agobecause then it will never get done. There are still people using old Nokia phones, for those there will never be a solution. The usual 80/20 rule applies here as well. And if you really are a German citizen, you know how slow the wheels of government already turn in Germany, I assume next week you would be the one complaining that "Germany is so far behind" and that "other countries are so much faster at implementing stuff" :)
- abc123abc123 6mo agoYeah, let's burn the witches who care about privacy! Jokes aside, in a democracy, the systems must be designed so that everyone can participate. We manage to do it with voting, with income tax declaration, but for some strange reason, with ID we want to achieve 1984 nirvana, and crush the voices who tell us that the surveilance society we are building is just setting us up for the next Hitler.
- haagch 6mo agoNah, I'm that one idiot who uses alternative open software and just accepts when services aren't offered to me. The older I get, the easier it feels to not give a fuck anymore. Can't buy any single fare public transport tickets online here in Stuttgart? Sure, I'll use the DeutschlandTicket NFC card. Can't view the EPA? Fine then I don't. Can't pay with Wero? Fine, I don't actually need to use shops that don't offer SEPA Vorkasse or Lastschrift (only without a dodgy "identity verification" fintech startup of course.
- futune 5mo agoYou are not alone.
- sippeangelo 6mo agoThen maybe it shouldn't be done? What??
- jijijijij 6mo ago> There are still people using old Nokia phones No one wants support for toasters and washing machines. We're talking general purpose compute hardware. TCP is also supported on all these devices. Quite frankly, it's probably easier to implement, if you are not fighting a locked-down OS like iOS.
- microtonal 6mo agoWe are not talking about old Nokia phones, but perfectly modern phones like those with GrapheneOS, that can be run on cutting-edge hardware, with a secure enclave, does not use Google Play Services by default, and has a high probability of being more secure than iPhone or any Android phone. It is exactly the kind of alternative that European countries should embrace to become less dependent on US tech. I am not sure if you are European, but why people are still supporting the GMS Android/iOS duopoly after the US revoked the Google accounts, Office 365 accounts, credit cards, Amazon accounts, etc. of ICC judges is beyond me. Supporting only iOS/Google GMS Android in a government app basically gives the US all the means to blackmail you and/or disrupt your digital infrastructure. It seems there are still people working for European governments (including developers) who seem to have missed 2025 and the first few months 2026? We are repeating the same mistakes as depending on Russian oil/gas again.
- p2detar 6mo agoDo we have stats how many germans use something else than Google Android, Samsung Knox or Apple? I recon it should be less than 1% which quite honestly is in fact „all“ citizens.
- elric 6mo agoSure, let's just arbitrarily exclude ~1million people because they're not running the government's preferred American spyware.
- p2detar 6mo agoThis is an unfair and a straw man argument, is it not? Are you also unhappy that in a democracy the 51% choose how the other 49% are going to be governed? Why device attestation is required is quite well explained by this github comment [0]. I am in the industry and I agree fully with it, because it is a fact a problem for most smart phone users in terms of security. 0 - https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/287#issuecomment-3009806384 https://github.com/eu-digital-identity-wallet/eudi-app-andro...
- Hackbraten 6mo agoI think your analogy is flawed. I can be part of the losing 49% and still be entitled to receive the same services as the 51%, whereas people who chose a privacy-oriented OS are essentially going to be excluded from essential governmental services. That's a whole different kind of thing. I'm not going to replace my 1200 EUR smartphone with a device that forces me to have an account with Apple or Google. I've been issued a German identity card, which is its own computer that includes a digital identity already. I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need. They should just stop excluding me already.
- p2detar 6mo ago> privacy-oriented OS Well, in all seriousness what examples could you give me here in terms of device hardware attestation? Even GrapheneOS does use Google root certificates to attest your device. There is indeed an option for EUDI to keep a list of keys and I bet this is probably the way they are going to go for Android in the future. We shouldn't forget this is still in the planing phase. > to have an account with Apple or Google. True for Google, not true for Apple. Device attestation on iOS does not require you to have an iCloud account or sign into some Apple services. It works entirely using device hardware ids. > I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need. Nope. This is eID and verifies your identity, it does not attest the security of your hardware. These are two different problems we talk about here.
- ExoticPearTree 6mo ago> Why are we not refusing to implement this until we know we can make it work on all devices? Simply put: this will never happen. Way too many devices implementations to make this a reality.
- fsflover 6mo agoIt's just a matter of creating a web app.
- well_ackshually 6mo agoAnd what attestation services does your web app use? Do we lock that web app behind having Secure boot enabled, along with a Java applet for the fun of it? If your answer is "none", you missed the point.
- fsflover 6mo agoAttestation of what? It's none of your business how I secure and configure my phone. I use a smart card on my Librem 5 btw. See also: https://news.ycombinator.com/item?id=47647047 https://news.ycombinator.com/item?id=47647047
- well_ackshually 6mo agoMy business, no. Your government however, has a few reasons to want to ensure that the ID you're going to use to vote, to prove your identity to any service, etc, etc, does not get passed from device to device. Configure your phone however you want, then use your physical ID because your phone isn't supported. They're not taking it away. In the same way that you can file your taxes. Having an online filing service doesn't mean you're being "excluded" because your i386 running BeOS isn't part of the supported hardware. Send a letter. It'll still work.
- haagch 6mo agoI second the question, attestation of what? I have a Solo key that I use with webauthn for several services already. Is that not good enough and even if not, there surely are sufficient alternatives, least of all the actual electronic id on the national id card via nfc?
- miki123211 6mo agoDo all German hospitals serve vegan food? If you were averse to carrots (without any health restrictions on eating them), would every government institution in Germany be required to serve you carrot-free food? If not, why should they be forced to accommodate every smartphone brand in existence, even if there's only 3 people in Germany using it? THe list has to end somewhere.
- RobotToaster 6mo ago> Do all German hospitals serve vegan food? Can't speak for Germany, but they do in the UK. It would be illegal discrimination against a belief for them not to.
- vovavili 6mo ago[flagged]
- sotix 6mo agoVegetables, legumes, nuts, and grains are not expensive, and veganism is a protected class in the UK.
- plagiarist 6mo agoYeah but when you're mad at a nation not force-feeding meat to vegans you have to come up with some reason why the vegans are bad.
- account42 5mo agoHaving a separate option is however not free.
- aziaziazi 6mo agoActually the subsidies mostly go to diary farming. Vegan food is cheap to produce but mostly not subsidised. This, plus the (no) economy of scale makes the shelf prices sometimes slightly higher, eg soy milk vs defatted milk.
- dabber21 6mo agoalso German here, we have to get rid of the 100% perfection at launch expectation its crippling this country
- conception 6mo agoBut things not in the launch can easily be deprioritized as budget issues indefinitely. “Oh why spend the money adding support for just a few people??” will be the line moving forward.
- charcircuit 6mo agoIt would be cheaper to just buy all of the outliers a bottom of the barrel Android phone for them to use with the tax money.
- fsflover 6mo agoAnd force them into the Google surveillance, https://news.ycombinator.com/item?id=26639261 https://news.ycombinator.com/item?id=26639261
- charcircuit 6mo ago[flagged]
- fsflover 6mo agoSo please tell us what the difference is.
- charcircuit 6mo agoWith surveillance a person gets surveilled with telemetry a person doesn't. Telemetry is collecting information about the operation of the device. The goal of telemetry is to understand how the device is operating where with surveillance it is about seeing what a person is doing.
- like_any_other 6mo ago> it will not serve all citizens This is an understatement. Better phrasing would be "when it allows two unaccountable foreign companies to lock citizens out of the digital market". There are plenty of horror stories of tech giants frivolously banning people. We shouldn't be adding state support to that. I don't want to lose access to digital banking because of some deliberately vague "community guidelines" violation, or because I got mass-reported to some "e-safety" provider that both Apple and Google outsource to. Sibling comments see this as a good solution, just not a perfect one. I see it as making a bad problem worse.
- gmueckl 6mo agoYou have the totally wrong expectations here. Some service that requires citizens to buy and bring their own devices in order to use a service will by definition always be exclusive. Whining about lacking compatibility with some niche sbowflake devices is just inappropriate in this context. The only solutiin is to require an actually convenient fallback for those otherwise excluded from that service. The limited selection of attestation providers can be criticized for many other reasons, though.
- class4behavior 6mo agoYour disdain isn't helpinh you here either as you're just as wrong as parent. Such public utilities ought to always prioritize privacy, platform-independence, and empowering market competion long- and short-term. And to achieve that you need to start at the design level. In this case, clearly, you either have to avoid relying on app attestation or lay the foundation for an unrestricted number of independent chain of trust frameworks. The latter, of course, is a policy-level issue, but the ones responsible for the design and development are the ones who need to pass such concerns up the chain.
- gmueckl 6mo agoYou have the right starting point, but the wrong conclusion. Government services need to be inclusive of everybody. But you simply cannot build technical solutions that put technical requirements on devices owned by the users in a way that the service is sufficiently inclusive. That is just a fact. If you want to be critical of the outcome on compatibility grounds, forcing a grind to increase technical compatibility is the wrong thing to ask for. That must necessarily always leave some people behind. The only honest alternative positions on that front are (a) the government issues the tech to everybody itself or (b) the government doesn't build advanced systems at all. The German government offices rely on a lot of quaint-looking paper based processes, but they have one thing going for them: working through them can be done with pen and paper - tools that are available for cheap and broadly compatible. It's probably not such a bad thing after all?
- 6mo ago
- raw_anon_1111 6mo agoBecause you can’t please all of the people. And before someone likens it to the ADA. Even with accommodations you have to make, car makers aren’t for instance required to make cars that blind people can drive. You chose to use a non mainstream platform. Thats on you.
- haagch 5mo agoSure. Something I forgot to mention is that the UBPorts foundation whose mobile operating system I currently use is a German organization.
- illiac786 5mo agoYou are assuming it will not be possible to add support to other OS. Why? What would be “knowing it can work on grapheneOS” for example, in your view?
- subscribed 5mo agoIt will be possible but simply won't be done. And as of now it won't work on GrapheneOS, it doesn't pass anything except MEETS_BASIC_INTEGRITY
- illiac786 5mo agoThat’s not what the parent wrote though. And why is it so bad that they start with a smaller subset of feature and target the 99% of the population using either google or apple?
- subscribed 5mo agoThis is a misleading way to put it. Re: Android. Goggle can supports AOSP attestation like any other vendor who wants to support it. They invented it. So instead of immediately locking down everyone using android to ONLY Google-dependent method, I'd developers could go the vendor agnostic way, but consciously decided not to. It's untrue to claim that supporting AOSP attestation only serves GrapheneOS and leaves out everyone using Google-surveiled handset. Nb, mixing it up with Apple is a conscious way to further the false claim, and I believe it's not accidental since these ecosystems are naturally completely separate.
- illiac786 5mo agoYou are misleading in fact, you use terms such as: “it won’t work on GrapheneOS” “locking down everyone using android to ONLY Google-dependent method” which make it sound like it’s a permanent and definitive limitation. It is not, they can add support later, as they stated already. > It's untrue to claim that supporting AOSP attestation only serves GrapheneOS and leaves out everyone using Google-surveiled handset. hmmm, what do you have in mind? Publish it to F-Droid but not to the google app store?