Yes, it is my post, and I am trying to find a reason why it won't work. Sadly, without such a solution, it will be impossible to use many Internet services without having an Android/iOS.

you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 3 days ago* (last edited 3 days ago) (1 child)

Sorry, I didn't read the specification. Does it contain something which (in)directly makes Android/iOS a requirement? I mean if it's just an open protocol how to talk to each other wile doing attestation... Maybe that's already part of it?! Most important thing I can come up with, would be to mandate public access to the API which grants the token, or connects to the eID, so those government servers actually accept connections from our Linux or FreeBSD phones...

And better do it for both parties. Otherwise they're going to come up with some new age verification laws, the phones are fine, but we all have to shut down our internet servers and online forums unless we're some big company.

  • source
  • hideshow 2 child comments
  • [–] [S] 1 point 3 days ago (1 child)

    It needs 'hardware attestation', so a closed set of OS. It would be much better without any age verification.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 days ago* (last edited 3 days ago) (1 child)

    Thanks. "Hardware" was a good search term. But it's more complicated than that: "[...] SHALL rely on the device's native cryptographic hardware [...], when they are available." Shall means mandatory in the document. But seems someone put a loophole there. So I guess technically it doesn't "need" it?! But I'd also guess it'll be available for 99.9% of users.

    I suspect we're going to see more of those hardware backed shenanigans anyway. Several entities are pushing for it. For other, unrelated causes as well. And it fits the purpose because now people don't really own their devices anymore. Which might already be a thing. I recently tried to back up and copy a phone... And, ...well... tough luck. Google is in control. There wasn't much I could do.

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 2 points 2 days ago (1 child)

    The thing is that while the EU standard does not limit hardware platforms, it does not mandate neutrality, so I can expect member states to only implement Android/iOS. In any case, I will not use that.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 days ago (1 child)

    Hmmh. I think I'd go even further. Even if it was... I'm not going to run government software in some trusted zone of my hardware. I'm still trying to keep Google, Intel etc out... Only properly acceptable solution to me would be if they stop regulating at the specification level. I rather have my favorite operating system come up with the actual software implementation.

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 1 point 11 hours ago

    That's what I mean. The protocol should be open, so that the software (at least the one running on my host, the opaque smart card does not telecommunicate and is ROM) can be implemented by anyone. No, I would not accept a version that works on some immutable desktop OS with a nonfree client.

  • source
  • parent