Yes, it is my post, and I am trying to find a reason why it won’t work. Sadly, without such a solution, it will be impossible to use many Internet services without having an Android/iOS.

  • hendrik@palaver.p3x.de
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    edit-2
    4 days ago

    Sorry, I didn’t read the specification. Does it contain something which (in)directly makes Android/iOS a requirement? I mean if it’s just an open protocol how to talk to each other wile doing attestation… Maybe that’s already part of it?! Most important thing I can come up with, would be to mandate public access to the API which grants the token, or connects to the eID, so those government servers actually accept connections from our Linux or FreeBSD phones…

    And better do it for both parties. Otherwise they’re going to come up with some new age verification laws, the phones are fine, but we all have to shut down our internet servers and online forums unless we’re some big company.

    • roundabout@feddit.orgOP
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      4 days ago

      It needs ‘hardware attestation’, so a closed set of OS. It would be much better without any age verification.

      • hendrik@palaver.p3x.de
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        4 days ago

        Thanks. “Hardware” was a good search term. But it’s more complicated than that: “[…] SHALL rely on the device’s native cryptographic hardware […], when they are available.” Shall means mandatory in the document. But seems someone put a loophole there. So I guess technically it doesn’t “need” it?! But I’d also guess it’ll be available for 99.9% of users.

        I suspect we’re going to see more of those hardware backed shenanigans anyway. Several entities are pushing for it. For other, unrelated causes as well. And it fits the purpose because now people don’t really own their devices anymore. Which might already be a thing. I recently tried to back up and copy a phone… And, …well… tough luck. Google is in control. There wasn’t much I could do.

        • roundabout@feddit.orgOP
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 days ago

          The thing is that while the EU standard does not limit hardware platforms, it does not mandate neutrality, so I can expect member states to only implement Android/iOS. In any case, I will not use that.

          • hendrik@palaver.p3x.de
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 days ago

            Hmmh. I think I’d go even further. Even if it was… I’m not going to run government software in some trusted zone of my hardware. I’m still trying to keep Google, Intel etc out… Only properly acceptable solution to me would be if they stop regulating at the specification level. I rather have my favorite operating system come up with the actual software implementation.

            • roundabout@feddit.orgOP
              link
              fedilink
              English
              arrow-up
              2
              ·
              1 day ago

              That’s what I mean. The protocol should be open, so that the software (at least the one running on my host, the opaque smart card does not telecommunicate and is ROM) can be implemented by anyone. No, I would not accept a version that works on some immutable desktop OS with a nonfree client.