| ▲ | afandian a day ago |
| I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd. This isn't only a digital sovereignty issue, it's also an anti-competition issue. |
|
| ▲ | txrx0000 a day ago | parent | next [-] |
| This is the correct intuition. The problem can be solved with antitrust by forcing hardware vendors to ship their devices without an operating system. Then the market will deliver the parenting solutions that don't require mass surveillance. We're currently being blocked from doing so by anti-competitive measures. For a more detailed explanation of what the root of the problem is, see a past comment:
https://news.ycombinator.com/item?id=49118578 |
|
| ▲ | mosura a day ago | parent | prev | next [-] |
| The EU way is to think these things are “free” and then act surprised by the inevitable consequences five years later when it is irreversible. Our AI gods cannot save us soon enough. |
| |
| ▲ | afandian a day ago | parent [-] | | What are the "AI gods" going to do in this scenario? AI is about many things, but a big factor is enclosure. |
|
|
| ▲ | toasty228 17 hours ago | parent | prev | next [-] |
| They already regulate the amount of rain water you can collect, or how much water you can take from your own well, or how many solar panels you're allowed to use You feel bad because it touches your own personal toy, but if you zoom out you'll discover the vast majority of it was already fucked up |
|
| ▲ | wmf a day ago | parent | prev | next [-] |
| Their solution is to "force open" iOS and Android through the DMA, not to create competition which they know won't work. |
|
| ▲ | petcat a day ago | parent | prev | next [-] |
| The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it. The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years. |
| |
| ▲ | realusername a day ago | parent | next [-] | | > it is virtually impossible for Europe to even begin to displace Apple or Google devices It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats | | |
| ▲ | inigyou 17 hours ago | parent [-] | | What do you expect - the EU to centrally plan a phone OS? They are capitalist with regulations, you know, not communist. Someone has to actually make one themselves. Most of the free hardware and software alternatives are already European, like MNT, and GrapheneOS. They just don't have market share. | | |
| ▲ | petcat 16 hours ago | parent | next [-] | | > are already European, like MNT, and GrapheneOS GrapheneOS is Canadian. | | | |
| ▲ | realusername 17 hours ago | parent | prev [-] | | What do I expect? Mandating open bootloaders by law, banning device attestation and applying existing antitrust legislation. Then if they could give a few millions to some open source communities, that could be the cherry on top | | |
| ▲ | inigyou 16 hours ago | parent [-] | | Now that would be pretty good. I thought there was already an unlockable bootloader mandate but it seems I was mistaken. Most phone makers openly violate GPL and don't get punished, too. |
|
|
| |
| ▲ | afandian a day ago | parent | prev [-] | | Agreed, I doubt that a mega-behemoth like Google or Microsoft could emerge in Europe. Especially not on a compressed timescale. But if they really wanted digital verification without the surveillance capitalism built in, I’m sure there are plenty of companies that could do it. Especially if it was around an open source framework. |
|
|
| ▲ | varispeed a day ago | parent | prev | next [-] |
| Anti-corruption regulators are paid to look away. If they start investigating corruption like e.g. Ukraine does, then the EU countries will be perceived as corrupt. The goal of these institutions is to keep things under the rug so to speak. That's why you barely see anything being done and yet everyone can see how corrupt things are. |
|
| ▲ | tzs a day ago | parent | prev [-] |
| My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws. Most analysts expect sites will offer multiple ways, for a variety of reasons. Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet. |
| |
| ▲ | _jackdk_ a day ago | parent | next [-] | | And how, exactly, will one acquire this "full EU Digital Identity Wallet"? Will I be able to compile it from source and run it on a computing device of my own choosing? | |
| ▲ | matheusmoreira a day ago | parent | prev | next [-] | | > Most analysts expect Total bullshit. There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking. The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense. Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society. This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed. | | |
| ▲ | izacus a day ago | parent [-] | | You can of course create an independent attestation database at any time and mandate its use - verifying that the custom OS you use fits minimum security requirements for digital ID use. We use that approach in several other industries. But.... that requires work beyond just complaining. | | |
| ▲ | matheusmoreira a day ago | parent | next [-] | | > You can of course create an independent attestation database at any time Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices. Come on now. > minimum security requirements for digital ID use Also known as "the user has no control over the device". Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it. > We use that approach in several other industries. Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable. | | |
| ▲ | izacus a day ago | parent [-] | | > Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices. That sounds mostly like copium just to motivate your complete inaction. Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU. But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic. | | |
| ▲ | matheusmoreira a day ago | parent [-] | | > we're using similar approval processes across multiple industries to certify hardware Why not tell us more about the requirements for hardware certification? Seriously doubt it's anything but the usual war on general purpose computing. Requirement #1, the computer runs the mandated surveillance software. Requirement #2, the computer does not allow the user to run any software not approved by the government. Requirement #3, the computer resists tampering so as to preserve the previous requirements. | | |
| ▲ | izacus a day ago | parent [-] | | > Why not tell us more about the requirements for hardware certification? Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated. It's the same set of requirements that are put on credit card smart chips and biometric chips in EU IDs and Passports (which are essentially also TPMs). But sure, it's a all an evil conspiracy against general purpose computing. And they're all out to get ya. Now smash that downvote for a vote against the evil establishment. | | |
| ▲ | matheusmoreira a day ago | parent | next [-] | | > cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM So it must be secure against the user, as expected. Preventing the user from "tampering" with the token means carving out a section of the machine and putting it out of his reach. You just created a government embassy on the user's machine. There's no telling what it will be abused for, and there's no escape. > But sure, it's a all an evil conspiracy against general purpose computing. You just advocated for putting an inescapable persisent cryptographic government ID on everybody's computers. This is the literal implementation of the surveillance state. Everything you do online, this token gets sent. It's the end of anonymity. Not even Tor gets around this. | | |
| ▲ | izacus a day ago | parent [-] | | Yes, that's what a TPM or smart card chip in your ID/Passport does. Prevents tampering even by the "user". I have advocated nothing of the sort you're accusing me of. Please leave your strawman at home. Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away. | | |
| ▲ | matheusmoreira a day ago | parent [-] | | > Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away. It doesn't have to go away. Once the capability is there, they can and probably will simply make it mandatory to even so much as get an internet connection from your ISP. No unbreakable ID chip? No internet for you. The "fallback card" is exactly what added the necessary friction that prevented everything under the sun from demanding these sorts of verifications out of everybody alive. It was somewhat tolerable when it was just a financial transaction. It's still highly problematic given that AML/KYC laws are just the financial arm of global warrantless mass surveillance, but at least it was contained to the financial domain and it was possible to avoid credit cards and use cash instead. Putting this stuff in every computer kicks it up into 1984 territory by allowing tracking of anyone posting wrongthink online. | | |
| ▲ | izacus a day ago | parent [-] | | In most EU states you already need to provide ID to establish internet service, so what are you on about man? |
|
|
| |
| ▲ | imtringued 20 hours ago | parent | prev [-] | | >Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated. So you need a proprietary browser running on a proprietary OS (both userspace and the kernel) with proprietary TPM hardware. You just proved the point. No more Linux. |
|
|
|
| |
| ▲ | imtringued 20 hours ago | parent | prev [-] | | >But.... that requires work beyond just complaining. So you have to build an entire parallel internet just because you want to use Linux? That's what your argument boils down to. The people who are complaining on HN are not platform operators, the platform operators don't care at all. To them it's not even about whether it requires work, they literally don't care. For the people who care, it's not a matter of work, because they don't operate the platform. |
|
| |
| ▲ | petcat a day ago | parent | prev | next [-] | | "Most analysts" actually expect the opposite: https://waag.org/en/article/european-digital-id-wallets-are-... Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation. | |
| ▲ | pembrook a day ago | parent | prev [-] | | I literally lol'd at the "Most analysts expect..." line. Yea, most analysts didn't expect the cookie banner nightmare we're living in either. To think you can get only the narrow outcomes you want with zero unintended consequences while building root-level infrastructure for 1984 just illustrates the laughable hubris of the authoritarian impulse. |
|