you are viewing a single comment's thread
view the rest of the comments
[–] 8 points 1 day ago (7 children)

Does the app require iOS/Android and google play services, and is proprietary?

Also gives the government data to track people, and presumably what source requested the token, so what the people are consuming. Denmark isn't the worst country, but I wouldn't trust any government with that

Also it locks under 18s out of online communities that could help them and show them alternative perspectives to insular IRL bubbles that can often exist

  • source
  • parent
  • hideshow 7 child comments
  • [–] 5 points 23 hours ago (2 children)

    Germany's app (AusweisApp2) is open source and available for literally every platform. Linux, FreeBSD and even Fdroid included.

    I'm not sure of the exact functionality and whether the government can track anything. You need to scan your ID, the app will then ask for a PIN (2fa) and then will tell you which data will be sent to whoever made the request.

    Authentication is done through an eID server which in theory anyone can set up. The requirement are quite strict though so right now there are only three providers. They check the validity of the ID and request and send the received ID data to the requestor.

    It's quite the complicated procedure to ensure the highest possible security and privacy.

    The entire process is publicly documented and you can probably spend a few hours trying to understand it.

    As for locking people out of online communities: I don't think it's a problem if and only if the legislation applies exclusively to social media providers above a certain size. Such as having 5 million+ monthly users.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 10 hours ago (1 child)

    And then they want a foto of your id

  • source
  • parent
  • hideshow 1 child comment
  • Yeah, that's an issue. Though that is also significantly less trustworthy since it only proves possession of an ID, not ownership. Afaik this method is therefore legally insufficient for platforms that need to know their customer (banks, stock exchanges etc.).

  • source
  • parent
  • [–] 4 points 1 day ago* (3 children)

    It's always interesting to me when I hear people who distrusts governments more than private companies.

    Maybe because I'm from Denmark, but it sounds so backwards.

    If I were from the US tho, I would think the same. Or like "i'm fucked regardless"

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 1 day ago (2 children)

    I don't trust governments that mandate the usage of private American services such as iOS/Google to access the internet

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 15 hours ago (1 child)

    That's a fair point.

    My argument only applied to the age verification in the Danish app, which doesnt share the ID to any server.

    The point is that you get a verification by logging in with another 2FA app, whos only job is to verify with the government server, that you are indeed a Danish citizen with official documentation.

    Then the other app recieves that token that only contains an age group with a true flag. This token is then shared with the private companies.

    As a stand alone solution to age verification that everyone needs to use, this is pretty well thought out.

    If a Linux phone then comes around that everyone would buy, you could do it better, yes.

  • source
  • parent
  • hideshow 1 child comment