[HN Gopher] EU Digital ID wallet is coming
___________________________________________________________________
EU Digital ID wallet is coming
Author : taubek
Score : 155 points
Date : 2022-06-30 06:08 UTC (16 hours ago)
(HTM) web link (www.thalesgroup.com)
(TXT) w3m dump (www.thalesgroup.com)
| DigitalVerse wrote:
| Disappointing to see that they're taking a centralized approach
| to this problem. There are alternatives out there, but I guess
| they're not interested.
| checkurprivlege wrote:
| There's an obvious conflict of interest when an organization
| both offers services, and decides what vendors are allowed
|
| Unfortunately, many people fail to see this obvoius trap.
| throw10920 wrote:
| > Imagine if you could do it in seconds via a mobile wallet app
| that works anywhere in the EU?
|
| There's mention of "mobile" with no corresponding mention of
| desktops or operating systems, so it seems safe to assume that
| the app will only work on iOS and Android phones (and probably
| not even rooted Android devices).
| Avamander wrote:
| Yes, it's very likely software-based solution the likes many
| countries have (Smart-ID, BankID and others). It's in many ways
| just easier that way. Better? I don't think so.
|
| It is possible to do it without an "app" by using SIM applets.
| The keys are stored on the SIM card, it acts as an HSM.
| Estonian Mobile-ID has been implemented using that and it works
| even on feature phones. There are a few papers about the system
| if one searches around and if you're interested.
| checkurprivlege wrote:
| Citizen identification falls under the responsibility of my
| country.
|
| EU is neither my country nor it will ever be. Therefore, no EU
| digital Id for me.
| N19PEDL2 wrote:
| Some EU countries already have a digital ID system. The Italian
| SPID [0], just to give an example, has been one of the most
| important steps forward in e-government in Italy in recent years.
| The goal should be to make existing systems interoperable, rather
| than to create a new supranational EU-wide one.
|
| [0] https://www.spid.gov.it/en/
| jakopo87 wrote:
| It already exists and it's called eIDAS[0].
|
| [0] https://en.wikipedia.org/wiki/EIDAS
| bool3max wrote:
| We're fucked.
| noodlesUK wrote:
| Tbh I'd much prefer a well designed digital ID system that has
| privacy protections built in rather than what we're getting in
| the UK which is weird digital ID being brought in through the
| back door with proprietary products like Yoti [1] getting
| government support.
|
| This could potentially replace some of the most invasive and
| horrible companies like Experian who've carved out a niche in
| verifying ID.
|
| [1] https://www.yoti.com/
| dane-pgp wrote:
| Isn't it possible that the UK government is supporting "weird
| digital ID" because they know it will inevitably fail in some
| catastrophic way and then they'll be forced to step in and
| unify all these proprietary systems into a government-run
| replacement?
|
| It will probably be implemented by a "VIP lane" contractor[0]
| and/or be an extension of the existing Biometric Residence
| Permits (BRP) system[1], which has been mandated for foreigners
| without much protest because immigrants are an easy target.
|
| [0] https://www.bbc.co.uk/news/uk-59968037
|
| [1] https://www.gov.uk/biometric-residence-permits
| ParksNet wrote:
| The EU is just following the WEF agenda:
|
| https://sociable.co/government-and-policy/wef-wto-global-dig...
|
| Next step will be Digital Identity required to post online, and
| police action against wrongthink.
|
| We've already seen Digital Identities used to unperson anyone who
| doesn't accept (arguably dangerous and experimental) medical
| treatments.
| beebmam wrote:
| I don't think the people who made this site are interested in
| presenting an honest analysis of this topic. It looks like
| straight up propaganda, with a massive amount of ads.
|
| Can you find me a source that presents more than one
| perspective on this topic, like perhaps on Wikipedia?
| ParksNet wrote:
| The UK is already pushing this:
|
| https://www.gov.uk/government/publications/online-safety-
| bil...
|
| "Requiring Category 1 services to ensure adult users are
| given the option to verify their identity, and tools to have
| more control over the legal content that they see and who
| they interact with -- this would include providing adults
| with the option not to interact with unverified users."
|
| What starts as 'an option to verify their identity' will soon
| become 'must verify their identity'.
|
| Authorities in Australia have already arrested people for
| _online_ opposition to COVID lockdowns:
|
| https://www.bbc.com/news/world-australia-54007824
| [deleted]
| ellopoppit wrote:
| Lots of well sourced, verifiable information here:
|
| https://unlimitedhangout.com/2021/01/investigative-
| reports/s...
| [deleted]
| thomassmith65 wrote:
| I'm sorry to condescend, but do you have a therapist? It might
| be healthy to touch base with normies once in a while.
| neither_color wrote:
| I don't think it's unhealthy to consider 2nd and 3rd order
| consequences of upcoming policies. What _is_ unhealthy and
| historically documented as potentially dangerous is accusing
| your opposition of mental illness. https://en.wikipedia.org/w
| iki/Political_abuse_of_psychiatry_...
| ellopoppit wrote:
| What a classic, I remember when people would call you crazy
| for claiming that governments were working with
| corporations to perform mass domestic surveillance
| notaspecialist wrote:
| Getting your hands on equipment to make identity documents is
| physically difficult, requires lots of deals, is costly, and is
| limited to a few people.
|
| Replacing this with an electronic system, where access is
| guaranteed via leased lines to many locations, with sloppy
| physical controls... and a back-end that more than likely has
| several holes due to misconfigurations, last-week exploits etc
|
| This is fine.
| janandonly wrote:
| I don't really know how this is (will be) different from the
| current iDin system?
|
| This system allows one to identify him/her self via, for example,
| a banking app.
|
| https://www.ct.nl/nieuws/idin-identificatie/
|
| https://www.idin.nl/
|
| https://www.consumentenbond.nl/betaalrekening/idin
|
| I realize now that I can only find Dutch links to this system, so
| I am assuming The Kingdom of the Netherlands is simply ahead of
| the EU crows?
| scrollaway wrote:
| Several countries in Europe have rolled their own. This system
| is an attempt to digitize the countries that haven't, and
| standardize the countries that have (and make it work EU-wide,
| so it works better for citizens moving between countries).
| onetoo wrote:
| I believe most European countries have their own solutions
| similar to this. e.g. in Denmark we have NemID/MitID as _the_
| way to digitally authenticate yourself to the healthcare
| system, your bank, etc.
|
| If I understand correctly, this EU initiative would unify all
| these separate country-level identification tools into
| something that works EU-wide, so I can take my Danish digital
| ID and e.g. use it in a bank in the Netherlands.
| Heliosmaster wrote:
| Each country has their own system. in NL we had DigID, and
| apparently now iDin (first time i hear about it). In Italy we
| have SPID who uses a bunch of external providers (phone
| companies, italian posts, internet providers, ...). The whole
| idea is to create an interoperable standard.
| einarfd wrote:
| The article does point out that several countries have these
| kind of systems but they are not cross border. Solving that is
| supposed to be part of this initiative. Being able too use a
| swedish issued id to authenticate in the Netherland would imo
| be a nice and a big step forward.
| Avamander wrote:
| > Being able too use a swedish issued id to authenticate in
| the Netherland would imo be a nice and a big step forward.
|
| That's unfortunately caused by the proprietary solutions
| chosen, BankID and similar. If Sweden and Netherlands had
| gone with very widely supported Smart Cards (like Finland,
| Estonia and Latvia), they would interoperate trivially.
| Especially with the advent of eIDAS.
|
| Hopefully this legislation forces proprietary implementations
| to become more open.
| stncls wrote:
| If you want a horrifying overview of this technology in 3
| minutes, see this video advertisement by the makers themselves:
|
| https://m.youtube.com/watch?v=PxvNzzgoJX8
|
| For context, the French company Thales Group is "the 8th largest
| defence contractor in the world with 55% of its total sales being
| military sales".
|
| https://en.m.wikipedia.org/wiki/Thales_Group
|
| They are proudly proposing that we outsource government functions
| to them, promoting the _proprietary_ tech they will use to that
| end.
| francis-io wrote:
| "...reminding Lucy of her mandatory vaccination" is very
| chilling.
| Dig1t wrote:
| Right out of dystopian sci-fi.
| ellopoppit wrote:
| "#Vaccinepassports are a precursor to Digital ID wallets,
| offering citizens unparalleled convenience and #security."
|
| https://mobile.twitter.com/ThalesDigiSec/status/142535144657.
| ..
| baal80spam wrote:
| > https://m.youtube.com/watch?v=PxvNzzgoJX8
|
| And _of course_ comments are turned off for the Digital ID
| Wallet movie. No visible dislikes and no negative comments =
| everyone is happy!
| marcosdumay wrote:
| Good thing that Lucy lost her passport and not her phone.
| moffkalast wrote:
| Lucy has lost her phone. Unfortunately she is now not only
| locked out of her social life, but her job, her bank, and
| also her identity. How convenient.
| 0xfaded wrote:
| Don't worry, the government knows where her phone is.
| edmcnulty101 wrote:
| They just casually threw mandatory vaccines out like it was
| nbd.
|
| What other mandatory things will I need to do for the
| government?
|
| Mandatory registration for war! Mandatory birth control!
| Mandatory drug test! Mandatory lie detector test about how
| honest you were on your taxes!
|
| How easy it makes it to participate in society...
|
| is a double edged sword...
|
| with how easy it is to shut them out of society with a flip of
| the switch if they don't comply.
| TacticalCoder wrote:
| > They are proudly proposing that we outsource government
| functions to them, promoting the proprietary tech they will use
| to that end.
|
| Thales is one those supposedly private companies that is
| actually owned by the french state and french state
| apparatchiks. The biggest shareholder is the french state
| itself (26%), then other companies which, surprise, are also
| partially french state owned. It's all Dassault, Airbus, EADS
| etc.: they're all basically partially french state owned and
| own shares of each other. It's the military-industrial complex,
| french style.
|
| I mean: it's basically the government proposing we outsource
| government functions to the government.
|
| All that while pretending that Thales is a private company.
| _Algernon_ wrote:
| >EU digital ID wallet
|
| How is it better that a foreign government has control of my
| id? Most of the EU isn't France.
| cinntaile wrote:
| Thales makes passports too, so there is a big chance that your
| passport was made by them.
|
| A more universal digital ID is a welcome change, now certain
| services are limited to people living in a certain country
| because there is no support for foreign digital IDs.
| dane-pgp wrote:
| > A more universal digital ID
|
| Would you support a global digital ID, based on standards
| from the UN? It could even be used to store your vaccine
| data:
|
| https://www.telekom.com/en/media/media-
| information/archive/c...
| freeone3000 wrote:
| Yes, this sounds awesome. Way better than having to re-
| prove myself to every country I enter.
| poo_clown wrote:
| Distributed consensus of personhood updated in realtime
| is the wave of the future! Keep those nasty germs at bay.
| durnygbur wrote:
| Massive oven for a cash solving a problem which doesn't exist.
| Bureaucrats will hire each other then produce gigabytes of PDFs
| and half-baked MVP. After the covid masquerade ball, where
| remotely switched "certificate" determined one's basic civil
| right (freedom to travel), I'm not installing any app from
| authorities.
| checkurprivlege wrote:
| It's a problem when thousands of bureaucrats want to "do a
| career" spending budgets on things absolutely nobody asked for.
|
| I want society to experiment with firing all these bureaucrats.
| Then listen carefully at the silence. Are we missing anybody?
| sreeramb93 wrote:
| Reminds of me Aadhaar in India.
| this_is_not_you wrote:
| Sounds like the BankID system they have in Norway and Denmark
| (maybe also Sweden?).
| tmikaeld wrote:
| Yes, it's also standard in Sweden (BankID is a private entity
| though, not government controlled), so the swedish state want
| to create their own [0].
|
| [0] https://feber.se/samhalle/regeringen-vill-ha-en-statlig-e-
| le...
| yaris wrote:
| Sweden also, yes. Although it is not similar. As I understand
| the way BankID works - it is responsibility of the bank that
| issued your BankID (or another company, as there are a few non-
| bank companies where one can get "Bank"ID) to identify you
| physically (using a passport, national ID, driving license
| etc). The government (in Sweden at least) is not (visibly)
| involved in the process.
| this_is_not_you wrote:
| I am not sure what you mean by "to identify you physically".
|
| The way it works in Norway is that, once you have a bank
| account (which means you had to identify yourself using
| passport or similar) you can get a BankID which allows you to
| log in to a lot of online services (health, tax, employment,
| etc) without having to do anything else.
| mdp2021 wrote:
| > _It proposed to give every EU citizen a set of strong digital
| identity credentials that will be recognised anywhere in the
| zone. These credentials will be accessible from a digital wallets
| and available to anyone from their mobile device_
|
| Is this thing mandating a mobile device as a document?
| onion2k wrote:
| The digital wallet could be something like an Yubikey that
| holds the data and decryption software. The stipulation that it
| should be available to everyone is that it needs to be readable
| from a mobile phone (eg NFC). The phone would issue a request
| for access to some policy, and the device would read the data
| and issue a true/false response (or more if necessary.)
|
| The wallet holder would have control over what their wallet
| gives the reader access to.
|
| I imagine a mobile app would be cheaper and simpler though.
| sofixa wrote:
| The current iteration allows for digital certificates (stored
| on a USB), so there probably will be a fallback for those
| without smartphones.
| Avamander wrote:
| A software-only solution where private keys have the
| potential of leaving the device, be it an app or an USB-
| stick, is not really okay in this day and age.
|
| So a proper fallback wouldn't be an USB-stick with some
| certificates laying around, you can instead just build the ID
| functionality using SIM-card applets. The keys are securely
| stored in hardware and you can use them on both smart and
| feature phones.
| terefooobar wrote:
| Fully digital is bad, what if I lose my phone or my certs get
| somehow stolen. In Estonia we have a physical ID card with certs
| on it and I like that much better.
| mdp2021 wrote:
| I am not seeing information that this "Digital ID wallet"
| excludes alternatives. Did you?
| einarfd wrote:
| I live in one of the countries that have a local variant of this
| already (BankId in Norway). What it is used for here are services
| where either you are able to identify and authenticate yourself
| or if not, there is just now way they can be provided. These kind
| of services are things like banking, taxation, ownership
| transfers, health care, and similar.
|
| I'm hard pressed to view allowing people access to these kind of
| services over the internet as something dystopian.
| nix23 wrote:
| Excellent, and Europol is the next and worse NSA.
| mihaic wrote:
| In theory, I think that something like this is way past its due
| date in many applications on the internet.
|
| In practice, does anyone know how these expert groups are formed
| and how they operate? The execution feels like the same terrible
| EU-driven "plan it in excruciatingly useless detail to have
| everything in the first implementation, and only then realize it
| sucks".
| dementik wrote:
| I think this does not look totally bad. I have lots of good
| experiences on similar digital ID from Estonia. That just works.
| Banks etc rely there on government-backed authentication.
|
| In Finland its totally opposite. We have 10 or so banks, which
| all have their own authentication methods and government has
| outsourced authentication to banks. And every authentication
| costs 0,10EUR (it was previously much higher amount, something
| like 0,70EUR but it is now [since 2017] limited by law).
|
| So, I think at least in Finland banks will be the ones who will
| come up with several reasons why they should not implement this
| new authentication method.
| proc0 wrote:
| > competition is what drives societies to become more complex,
| building more hierarchical armies to fight ever-more-complex
| wars and organizing increasingly bureaucratic governments to
| manage diverse resources and growing populations.
|
| This sounds interesting. Having identification be a cost would
| make people think before engaging with anything that requires
| it, which would encourage companies to avoid. Also, if people
| can choose freely which banks to use, then there is also some
| market pressure on banks to have good privacy and security.
| verisimi wrote:
| > I think this does not look totally bad.
|
| Phew! But it's not something you wanted, right? This is not
| something that helps.
|
| It is something that helps those doing the governing though.
| Tracking you. Why is it planned that we all have these sorts of
| id/wallet/health pass/etc?
|
| Is it possible that it will be used as in China, with good
| citizens (uncritical of the government) allowed access to
| travel, borrowing, schools, etc nevermind the loss of privacy
| as each purchase, movement is tracked?
|
| To me its plainly about control. Control like we cannot even
| conceive of. Even if the government is not rule by the worst
| (and the EU is not a democracy - there's no options to get
| people out) the change in society will change us. If we know we
| are always under close scrutiny, you will change your
| behaviour.
|
| After all we have seen, I hope we are in agreement that this
| sort of gadget should be roundly refused.
| dementik wrote:
| > But it's not something you wanted, right?
|
| I am actually not sure if I wanted this. I think this is
| better than current (specifically comparing to Finnish)
| state, but still far from optimal (mainly based on privacy
| concerns).
|
| > Is it possible that [..] is tracked?
|
| Yes. But I have The Great Belief that EU is _still_ one of
| the Goods. That may or may not last.
|
| Still, it is very easy to exaggregate this (slippery slope)
| and at the same time it is too easy to understate this.
| Probably we - as citizens - should raise loudly these
| concerns and if we are not heard - then roundly refuse.
| verisimi wrote:
| > Yes. But I have The Great Belief that EU is _still_ one
| of the Goods. That may or may not last.
|
| Still eh? What happens when that belief has waned? The
| infrastructure will still be there.
| dementik wrote:
| > What happens when that belief has waned?
|
| Hard to predict but usually (lost) belief transforms to
| feelings/actions like resistance. And probably on that
| point there will be also others who will do the same.
| verisimi wrote:
| How would you resist, when your energy, travel, money,
| internet, etc, is micromanaged by your government?
| dementik wrote:
| The same way I am resisting (in-efficiently) things now
| in democracy: by voting and trying to raise my concerns
| on public forums.
|
| Yes, government could do things which prevent me doing
| so. Still, I am not capable to manage everything by
| myself and at the same time I think it is better to let
| things to be managed by (good) government than
| corporations.
| proc0 wrote:
| There's something inherently unsettling about government having
| so much control over people. I know EU is different but history
| proves EU is more vulnerable to having dictators. It's
| interesting how people don't see the danger here, and I can
| almost see history repeating itself, except on a different scale.
|
| Where is this all going? I hope I'm wrong and it means some kind
| of utopia where people only enjoy the benefits of an all-knowing,
| all-seeing entity that has full control over your life, with none
| of the downsides. To me that seems highly unlikely, at least not
| without some heavy price paid along the way.
| barrysteve wrote:
| If there's a great depression again in the 2030s, like there
| was last time, then the command economy that's established in
| the 2040s will use this and any tech like this to reduce
| unemployment by "force".
|
| The world of Ayn Rand's Fountainhead is looking more and more
| likely. Where every single thing is revealed and the heroic act
| is simply to do something different to the slaving public.
|
| This system doesn't treat people like an end in themselves, it
| treats them like they are a means for everyone else to use
| them.
| jdasdf wrote:
| > I know EU is different
|
| How do you know that?
| proc0 wrote:
| From reading other comments and also I'm just stating the
| obvious. There are different systems of government, which
| work differently and is something people must be accustomed
| to.
| viktorcode wrote:
| All the papers that can be replaced with this digital ID were
| issued by the state.
| _Algernon_ wrote:
| And those papers dont include a gps and internet connection
| that can silently ping your location to the government every
| second.
| kybernetyk wrote:
| While such things can look benign under a democratic and
| liberal governmentthis all changes when some "bad guy" comes to
| power. My personal litmus test for things like these is: What
| if someone like Stalin/Hitler would have had this. And suddenly
| rounding up a group of people becomes nothing more than a SQL
| query.
| Ajef wrote:
| What power does the EU/its governments gain here? Aren't they
| already the only identity provider (passports, ID cards,
| drivers license)?
| stingraycharles wrote:
| And perhaps more importantly, they all have their own
| versions of digital IDs as well, all with their own quirks
| and potential vulnerabilities.
| cft wrote:
| Historically money was not controlled by any government
| (gold). Gold lasted for tens of thousands of years: private
| transactions with money whose value was beyond a single
| government control.
|
| Now we are talking about a single non-elected EU government
| controlling every transaction, not just the issuance of fiat
| money.
|
| I personally think that with time this will implode, because
| the society always evolves towards more freedom, towards less
| centralization. There are multiple steps now in the reverse
| direction. However the discrepancy between the views of the
| government, the ruling classes and the reality is becoming so
| big that without a grand catastrophe (a global war, a
| revolution, etc) the inevitable correction seems less and
| less possible.
| proc0 wrote:
| The article mentions how this would allow all kinds of new
| services:
|
| >Our European companies, large and small, will also benefit
| from this digital identity. They will be able to offer a wide
| range of new services since the proposal offers a solution
| for secure and trusted identification services.
|
| It mentions things like going to nightclubs, and I assume it
| will include many more things that would otherwise not
| require a mobile app. Because this all now goes through
| government controlled servers, it follows they will have
| knowledge of all these new services, and all this new
| activity on every single citizen. In practice, this means
| government will know much more because this is now a
| widespread, mandatory form of ID.
|
| The question for me is, why does government need all of this
| information, as oppose to how can government intervene and
| make ID verification more convenient. The scale of this is
| unprecedented as well, from the amount of people doing it to
| the granularity of where and how it's going to be used.
| ko27 wrote:
| Your own example proves how digital ID can be more private
| and secure. You go to a nightclub, you look a bit younger,
| person on the entrance asks proof of your age:
|
| Option 1 - You give him your ID card and you expose a
| wealth of data, including your full name, address and
| SSN/OIB to that person
|
| Option 2 - He scans your phone app, gets a big green mark
| which proves your exact age, or even just that you are 18+
| and nothing more
| lobocinza wrote:
| Option 2 has all the problems from Option 1 multiplied.
|
| Bouncer can ask for more information and you can't even
| lie about it. Asking for phone number and address is
| somewhat reasonable in our current dystopic present on
| the basis of KYC and "what if there's an emergency". And
| you can be sure that the data will be stored in local DB
| with poor oversight and security and it will be used for
| marketing and eventually leaked.
| proc0 wrote:
| I think "private and secure" mean two different things
| here. It may be private and secure from malicious actors
| trying to steal your ID, but it's probably not private or
| secure when government decides it needs to coerce you
| into doing something you don't want to do.
|
| Option 2 is more convenient, but at what cost? I would
| think the probabilities of the cost being high is
| proportional to the probability that government will have
| corruption and abuse the system, which seems high in
| history and even today in many countries.
| bboygravity wrote:
| Option 1: one guy gets to see all of your ID data, but
| most likely won't keep a record of it and will forget all
| he saw within 10 seconds.
|
| Option 2: the same guy has no idea who you are. Instead:
| your ID gets scanned, the scan hits a government server
| for verification. A record is now kept forever of where
| you went, when and with whom and this information is
| added to create a profile of you (and your
| friends/partners). They can know if you were cheating on
| your partner, whether you where dating, if you went out
| "with the boys" that night, what political flavor the
| people you party with prefer, and so on and so forth.
| 100's of people and algorithms can access these records
| in the future _in secret_ , including: the NSA (even if
| you're European, all secret service data is shared with
| the NSA), local secret services, the police if they want
| access, the tax-man, any future dictator(s) that rises up
| and his subordinates, same for others in other countries
| that are friendly to him, anybody in politics interested
| in you for whatever reason that may develop in the future
| when data access rules get weaker (or remain unpoliced),
| and so on and so forth. Furthermore, if for whatever
| reason your political preference becomes unwanted in the
| future, you can fully automatically be banned from public
| life at the press of a button with 100% efficiency (this
| already happens in countries such as China as we speak,
| Canada CAN'T WAIT to have such a system as well).
|
| I pick option 1.
|
| It blows my mind that people don't see where this is
| going after Snowden.
| moffkalast wrote:
| Not to mention the fact that they will find a lame excuse
| to roll this into the credit score system sooner or
| later, so they can know if you are a "responsible"
| citizen or something.
|
| And also that government employees are incompenent so
| they'll send the entire thing through wetransfer or
| something and it'll be leaked sooner or later.
| gumby wrote:
| Increasingly, in the US, bars and stores swipe your DL to
| validate your age. This is in the name of making sure the
| id was checked and not requiring the bouncer/clerk to
| recognize all sorts of state IDs.
|
| Really, all the info goes to the establishment and/or the
| company providing the reader.
|
| The old fashioned "bouncer will forget all the info"
| doesn't apply any more.
| switch007 wrote:
| I've never had my id "swiped" in Europe. I'm sorry but
| your US experience has no relevance to the topic.
| ellopoppit wrote:
| I'm in the US and have never had my ID scanned like that
| person is claiming
| toofy wrote:
| we've had it here in the us for long time.
|
| privacy forums were recommending people run magnets over
| the stripes on id's at least 10 years ago when companies
| started swiping them.
|
| is the new digital id terrifying? probably. but honestly
| from a privacy perspective, the way companies and
| government working together suck up all of our digital
| movements is terrifying if privacy matters at all to us.
|
| to me, this was an obvious next step considering the
| world we've decided to build. we're doing this.
| government employees. corporation employees.
|
| we're allowing power to consolidate at a rapid pace. we
| can't decimate the separation of governments and
| companies, then build company after company after company
| which heavily rely on human data for their profits, and
| then simultaneously be shocked when this happens.
|
| either we have privacy from both governments and
| companies or we don't. particularly in a world where we
| refuse to hold power to any sort of reasonable standards
| (and by "power" i mean governments, corporations, wealthy
| individuals, individuals with power backing them,
| organizations, etc...)
|
| i guess my ramble really boils down to this: many of us
| on this exact forum are building the tools. many of us on
| this forum are directly enabling power _of all kinds_ to
| consolidate. it isn't clear to me how we can complain
| about it too.
| roblabla wrote:
| > your ID gets scanned, the scan hits a government server
| for verification.
|
| I mean, you're already assuming things work a certain way
| that is not necessarily true. The ID card could just have
| all the information stored and signed by the govt. Then a
| scanner would only have to check that the signature is
| valid, no need to actually ping the govt server.
|
| I haven't checked the technical details, so I've got no
| clue. But this is how the EU COVID-19 vaccine
| verification works IIRC. No pinging of a central server
| is ever done - the mobile app just checks that the
| message in the QR code is properly signed with the
| expected root of trust.
| dane-pgp wrote:
| > No pinging of a central server is ever done
|
| Until the next time there is a terrorist attack or other
| scary event, and the opportunistic politicians say "We
| could have stopped this if only we had been keeping these
| pings in a database, just like we keep logs of everyone's
| internet metadata[0]. Don't worry, the database would
| only be looked at by AI, so it's not even a breach of
| your privacy."
|
| Then everyone is just a single firmware update away from
| a completely different regime, and it's too late to
| boycott the app because everyone assumes you have it and
| requires you to run the latest version. Of course, you
| could always try protesting, but you might not get very
| far.[1]
|
| [0] https://aboutintel.eu/european-metadata-retention/
|
| [1] https://www.reuters.com/world/china/china-bank-
| protest-stopp...
| tokinonagare wrote:
| > It blows my mind that people don't see where this is
| going after Snowden.
|
| The majority may actually approves it, instead of turning
| a blind eye. During the covid crisis, how much of the
| population was ok with the government (taking France as
| example here) excluding from social life, and in some
| case professional life, 10% of people, on the ground of
| them not pumping Pfizer et al. stock price? I bet on
| something like 70%. Those people think because there are
| in the "winner" side they'll always stay there, and don't
| realize how fast the wind turns, and the same method will
| apply to them soon for whatever reason.
| kettleballroll wrote:
| The question here is whether option 2 is implemented on
| the edge device (which in turn makes it more likely that
| someone can steal your identity) or goes over a
| government owned server (which means the government could
| soy on you)
| _Algernon_ wrote:
| The ID is now also a gps tracker that can send its location
| everywhere you go.
| stncls wrote:
| > There's something inherently unsettling about government
| having so much control over people.
|
| The article is way worse than that. It's about _outsourcing_
| government surveillance to military hardware maker Thales, who
| is proudly explaining how they 'll do it using their exclusive
| proprietary technology.
| stingraycharles wrote:
| Isn't outsourcing incredibly common for this type of thing?
| Not saying I am particularly fond of Thales (I'm not), but I
| have extremely low expectations of an EU in-house software
| development team. All things considered, I'd expect a
| military contractor to be proficient at security as well.
|
| If your concern is the lack of transparency, then I agree.
| This needs to be open technology.
| stncls wrote:
| > If your concern is the lack of transparency, then I
| agree. This needs to be open technology.
|
| Yes, exactly. My understanding is that openness is not
| really in Thales' culture.
|
| > I have extremely low expectations of an EU in-house
|
| I agree that modern ergonomics and convenience are not
| usually the strengths of in-house gov IT in the EU. But
| sometimes the basics got done right. I'm thinking of some
| of the smaller countries' digital/electronic IDs. Also,
| setting aside all ethical questions, the technical side of
| EU Covid passes was ok, as far as I understood.
| gorbypark wrote:
| I recently moved to Spain and managed to get a digital identity
| certificate. It seems to be a fairly open implementation, but has
| a few weird things. It's just an x509 certificate (in p12 format)
| that you install into the OS certificate manager and then it is
| used on various governmental websites to authenticate
| yourself/sign documents.
|
| First weird thing is that there's no method to recover the key if
| it's lost, besides starting from the beginning and going through
| the physical identity verification process again.
|
| The other thing I noticed is that the "configurator" macOS app
| isn't a sandboxed/signed app. They even have instructions on how
| to enable opening app from untrusted sources on their website. I
| feel they should bite the bullet and get a $100/yr developer
| account. AFAIK, all the app does is generate the certificate,
| transmits it to a server (to be signed by the CA after your
| verification happens) and generates a PIN you need to show when
| you are showing your physical ID. Once you are verified you enter
| another code that was emailed to you and it spits out your pk12
| file.
|
| Anyways, it's come in handy so I think an EU wide standardized
| version could be helpful in day to day life.
| Avamander wrote:
| Sounds really half-assed not to make it hardware-backed. With
| that implementation, malware can relatively trivially steal
| your certificate.
| dalke wrote:
| I don't believe a word. The three scenarios used to promote the
| benefits have some big stumbling blocks that can't be solved with
| simple credential storage.
|
| > With the EU Digital ID wallet, the bank can request the
| necessary credentials from the applicant. He or she selects them,
| and in seconds they are verified by the bank. The process even
| includes an eSignature that signals the applicant's agreement.
|
| This seems a bit off.
|
| As a US citizen living in Sweden, my bank also wants to know if a
| customer is a US citizen, because special regulations apply.
|
| For the above scenario to work, the EU Digital ID wallet will
| have to store citizenship information, including potentially
| multiple citizenships.
|
| Sweden recognizes the State of Palestine. Will the EU Digital ID
| wallet allow storing that information?
|
| > The student can use her EU Digital ID wallet to access, for
| example, the diploma she gained in one country and have it
| accepted instantly in any other EU country.
|
| That's ... also odd. That's not how it works now. A diploma in
| one country doesn't necessarily translate to something directly
| in another country. Quoting
| https://www.uhr.se/globalassets/_uhr.se/bedomning/informatio...
| "A recognition statement is a document that shows what your
| qualification corresponds to in the Swedish education system. To
| prepare the statement, we review your education documents."
|
| An app storing credentials isn't enough.
|
| > With the EU Digital ID wallet, the person can provide trusted
| proof of age and nothing more.
|
| Bars and nightclubs also gather names to help spot people who
| have been banned, and will also share a list of banned people
| with other bars. They also gather this information to spot VIP
| customers.
|
| They are't going to want to give it up.
|
| In practice it will be like a a go-away-cookie-banner button. The
| bar's system will ask for more information, people will press the
| "confirm" button w/o reading, and the bar will still get
| demographic information. Those few who do read and say "no" will
| not be allowed entry.
|
| If preventing this sort of information leak is important, then
| make it illegal to collect more information than is needed to
| verify age, or restrict what can be done with that information.
|
| > Billions of people regularly use mobile apps, so the process
| will be familiar to the vast majority of citizens and businesses.
|
| An odd statement. The population of the EU is less than 1
| billion, so this refers to the world-wide population. But world-
| wide, billions of people _don 't_ regularly use mobile apps.
|
| A better statement would be the number of people in the EU who
| regularly use mobile phones.
| https://newzoo.com/insights/rankings/top-countries-by-smartp...
| says for Italy that's about 75% penetration.
|
| I assume that more direct comparison wasn't used to avoid talking
| about what to do for the people in the EU who don't have or don't
| want smartphones.
| an9n wrote:
| What could go wrong?
| [deleted]
| throw7 wrote:
| "THALES - building a future we can all trust"
|
| Well, that's ominous.
| tomjen3 wrote:
| And I bet it won't work as an ID in Apple Watch. However it will
| probably make some company a boatload of money to develop.
|
| Meanwhile there is an entire standard of government certificates
| or FIDO that is made for this use case.
| Avamander wrote:
| FIDO and relatives are really not designed for such one-to-one
| identity use-cases, it was intentionally designed in a way to
| limit cross-provider tracking. National ID's are the exact
| opposite.
| Markoff wrote:
| diebeforei485 wrote:
| People should have this option.
| [deleted]
| qwerty456127 wrote:
| > Proving your identity matters
|
| In many cases when it is meant to, it should not.
|
| > whether you are a citizen opening a bank account, renting a
| flat or a business registering a new service.
|
| I never had to prove my identity to rent a flat in the EU. Good
| people trust each other.
|
| Why is it considered OK to take a bus or eat at a restaurant
| anonymously but renting an apartment or paying humble sums of
| money is not?
|
| > How do you even know they are human?
|
| You never know anymore. Give this up. Just keep in mind it may be
| a bot.
| Keirmot wrote:
| > I never had to prove my identity to rent a flat in the EU.
| Good people trust each other.
|
| For how long was this rent, and WHERE? Every time I rented for
| living spaces, the contract had to signed, marked on every
| sheet that had text, and taken to a notary to be considered
| valid. This is because all the info is then used to calculate
| taxes at the end of the year.
| qwerty456127 wrote:
| For years. In some places I didn't even had to sign a
| contract, in other places I would sign it but nobody ever
| checked my ID. Apparently nobody really cares much as long as
| you look and sound nice and pay them a deposit. They would
| only ask for the ID in hotels (which I'd vote to abolish as
| well).
| judge2020 wrote:
| I just want to comment that this was a very strategic HN post.
| 3AM EDT/12AM PDT for the US, so pretty much all comments are from
| EU-located posters.
| sixhobbits wrote:
| Or people in the EU tend to submit stories about the EU when
| the EU is awake... I love how US centric the internet is
| sometimes that an American staying up late to suubmit an
| article about the EU is somehow more top of mind than, you
| know, an actual EU person.
| Aaronstotle wrote:
| I hope there is a lot of pushback, this will undoubtedly be
| accompanied by some type of social credit system. I don't think
| it will be as extreme as the one in China, but worrying
| nonetheless.
|
| On the other hand, it would be nice if states in the U.S. offered
| some type of digital equivalent, been in situations where I don't
| have my physical ID and the counter-party refuses to accept a
| picture as proof.
| rockbruno wrote:
| This is great (I'm from Sweden which already has this), but you
| need to be careful as this also makes it really easy for you to
| fall into scams. I'm at this moment fighting a company who
| required me to login with BankID when using their website's
| contact form, and as soon as I was done with my inquiry they
| tried to blackmail me by saying "nope, when you logged with
| BankID, you technically signed (extremely unfair contract that
| says I need to pay them obscene amounts of money for simply
| reaching out to them) and we will sue you if you don't pay"
|
| Fortunately I'm fine in this case as the law states that you
| cannot be tricked into signing a contract that was never
| presented to you, but I think most people don't make the
| connection that your BankID logins are considered legit
| signatures by law and that you can be held accountable for what
| you use it for.
| tmikaeld wrote:
| While BankID is nice, it's owned and operated by a private
| entity and not controlled by the government, which the
| government want to change [0].
|
| [0] https://feber.se/samhalle/regeringen-vill-ha-en-statlig-e-
| le...
| dijit wrote:
| ^ this
|
| It's a fantastic system, especially when I compare how it
| used to work when I lived in the UK with how it works in
| Sweden: it feels like the UK is 50 years in the past.
|
| It should be government owned, definitely, but Sweden has a
| very poor history of securing it's IT systems in government.
| Like.. very poor.
|
| So, maybe I'm not 100% on-board. There needs to be oversight
| for sure.
|
| https://www.holmsecurity.com/resources/the-1177-leak
|
| https://www.bitdefender.com/blog/hotforsecurity/sweden-
| leaks...
| scoutt wrote:
| > In short, companies will have much more control of the data
| they wish to share.
|
| What does that even mean? Even in that context.
|
| > Most users will access the EU Digital ID wallet in the form of
| a smartphone app.
|
| Why the EU thinks, presumes or pretends I have a smartphone? If
| they want me to use a smartphone and obligate me to purchase one,
| then they should also provide a free or super cheap alternative
| phone + line contract.
|
| Every time I read something like this it urges me to put together
| some ESP32 plus a Modem, write an email and chat client, and
| throw away my current phone. When they'll ask me about my phone,
| I would pull out some ugly 3d printed case.
|
| > A key aim of any EU wallet is therefore to give EU-based
| businesses a strong, secure and powerful tool for authentication.
|
| And all this should be safe until someone steals Thales
| encryption keys, as already happened in the past (Thales was
| formerly known as Gemalto).
| Barrin92 wrote:
| >Why the EU thinks, presumes or pretends I have a smartphone?
|
| They don't. As the site says any traditional form of ID still
| works. This isn't mandatory.
| xxs wrote:
| Actually I'd hope the standard plastic ID cards would work just
| fine via a usb card reader.
| gobengo wrote:
| lets go web5
|
| If you wanna study this stuff, participate in
|
| * https://w3c-ccg.github.io/
|
| * https://trustoverip.org/
|
| * https://identity.foundation/
| iasay wrote:
| What happens if I don't want to identify myself?
|
| What happens if poverty does not allow me to carry a digital ID?
|
| What happens if I lose my digital ID wallet or it is compromised?
|
| Also judging by dealing with the average citizen on a daily
| basis, even securing an iOS device and remembering the iCloud
| password is beyond their level of care.
| kabes wrote:
| > What happens if I don't want to identify myself?
|
| The same thing as what happens in the offline world when you
| try to open a bank account or board a plane without ID: You're
| refused. Like it or not, for some services you need to identify
| yourself.
|
| > What happens if poverty does not allow me to carry a digital
| ID?
|
| While this is an issue, the issue is with a service being
| available only online. That issue already exists. Most
| governmental stuff is obligated by law to be available offline
| as well, but for private companies its more difficult. E.g. If
| I want to open a bank account and I don't have a phone or
| computer, some banks already make it hard to do it in person.
|
| > What happens if I lose my digital ID wallet or it is
| compromised?
|
| The same thing as what happens in the offline world. Procedure
| depends on where you live. Here you have to file a record to
| the local police and you get a new ID card a couple of days
| later. Now it can probably actually be blocked and you get a
| new id immediately.
|
| > Also judging by dealing with the average citizen on a daily
| basis, even securing an iOS device and remembering the iCloud
| password is beyond their level of care.
|
| It's up to the government to educate people and make a
| foolproof system. That's easier said than done but a lot of
| countries already have digital ID systems and it's worked well
| for almost 2 decades now.
| mdp2021 wrote:
| > _some banks already make it hard to do it in person_
|
| It is called a good market that you avoid them.
| d8c6c050cb0a4d7 wrote:
| > What happens if I don't want to identify myself?
|
| It is already an offence in several EU countries to fail to
| present official ID documents when asked by the police.
|
| If you don't want to identity yourself the outcome will likely
| depend on the mood of the police office. They may give you a
| verbal warning and send you on your way or they may choose to
| arrest you until they can ascertain your identity.
| [deleted]
| iasay wrote:
| Yes the police for sure, but this is normalising full ID
| verification everywhere.
|
| At some point there will be a situation where you cannot do
| anything because you are in the 0.01% of the system that is
| broken.
| d8c6c050cb0a4d7 wrote:
| That's already the case. Since you must be able to identify
| yourself when asked, you have an obligation to carry your
| identification with you.
|
| I believe the obligation to carry identification, and to
| have identification are enforced differently in different
| countries / states. But there is more information here:
|
| https://en.wikipedia.org/wiki/Obligation_of_identification
|
| https://en.wikipedia.org/wiki/National_identity_cards_in_th
| e...
|
| > At some point there will be a situation where you cannot
| do anything because you are in the 0.01% of the system that
| is broken.
|
| Not wanting to identify yourself and not being able to
| identify yourself are two seperate topics. I sympathise
| with people who fall outside of the system, but e-identity
| is currently a matter of convenience for people who already
| have identity documents and are seeking easier ways of
| accessing services online.
| xxs wrote:
| >Yes the police for sure, but this is normalising full ID
| verification everywhere.
|
| The UK is not a part of the EU any longer, for pretty much
| all of the rest member states, that has not been an issue
| for quite some time... save for Ireland.
|
| >At some point there will be a situation where you cannot
| do anything because you are in the 0.01% of the system that
| is broken.
|
| The issued ID plastic cards would be as useful when you are
| present in person.
| misja111 wrote:
| Replace 'digital ID' with 'passport' in any of your questions
| and you will find the answer.
|
| > Also judging by dealing with the average citizen on a daily
| basis, even securing an iOS device and remembering the iCloud
| password is beyond their level of care.
|
| The EU digital ID is based on EIDAS, a technology that is
| already in use by banks in the entire EU. You can be sure it is
| safe, otherwise any bank in the EU would have been hacked
| already.
| wfn wrote:
| Just to clarify, eIDAS is an EU regulation
| (https://en.wikipedia.org/wiki/EIDAS). Regulation means it's
| law in all EU member states.
|
| Organisations can implement eIDAS-conforming technology to
| provide eID services if they get certified; e.g. our company
| provides such services (remote onboarding without video
| conference need + qualified electronic signature signing):
| https://www.zealid.com/en/
| moffkalast wrote:
| > What happens if I don't want to identify myself?
|
| You get arrested until the police can figure out who you are,
| at least that's how it works presently in most of the EU.
| yourusername wrote:
| >What happens if I don't want to identify myself?
|
| That's already illegal in many countries. You'll be fined and
| possibly arrested until you can prove who you are.
| iasay wrote:
| When you book a hotel you will be fined and arrested until
| you can prove who you are? That's the use case being
| promoted.
| sofixa wrote:
| In some countries/cities it's already mandatory to provide
| ID when booking.
| Keirmot wrote:
| That's a strawman if I ever saw one. If you don't provide
| ID to the hotel they may refuse sell you their services.
|
| If you don't provide ID to the police, however, that's
| another issue altogether.
| mdp2021 wrote:
| The poster is probably just trying to build a cases tree.
| "What if I will not have electronic devices to buy
| prescribed medicines? // Then you will probably present a
| paper copy of the presctiption // Will it be allowed
| tough?".
| threeseed wrote:
| None of these questions are new.
|
| Verifying your identity without a global ID is done today
| through a combination of primary and secondary identifiers. For
| example a passport and bank statement. Or a driver's license
| and recent tenancy agreement. So if you don't want to verify
| yourself using the above combination then companies and the
| government will simply not choose to interact with you.
|
| And not sure if you've used a phone before. But you don't need
| the full iCloud password to unlock your phone and access a
| digital ID. You just need FaceID, TouchID or a 4/6-digit PIN.
| iasay wrote:
| The issue is more what happens when you buy a new phone or
| lose the old one. Then you need the full iCloud details and
| password. More than one person I know has got to that state
| and have no idea what it was. They don't even know what their
| own email address is to start with.
|
| Incidentally I know how it works. I work next to the sector.
| The issue is that these are all legitimate questions that we
| have to work with daily and the abstract "we will arrest you
| until you ID yourself" does not work when you book a hotel...
| onion2k wrote:
| _What happens if I don 't want to identify myself?_
|
| This is the proposed solution. The point is that the ID system
| only gives someone the information that they need. If you only
| want to prove something like "age > 18" then you can do that
| without giving up your name, address, ethnicity, etc. Every
| existing solution to that requires you have over more than a
| boolean answer that your age is above a minimum threshold.
|
| This is effectively "attribute-based access control" (eg IAM)
| for the real world.
| [deleted]
| raverbashing wrote:
| The digital ID is optional
|
| Requirement of carrying ID varies country by country
| ranguna wrote:
| > What happens if I don't want to identify myself?
|
| That's a non issue in the EU.
|
| > What happens if poverty does not allow me to carry a digital
| ID?
|
| Governments will probably pay this for you.
|
| > What happens if I lose my digital ID wallet or it is
| compromised?
|
| Same as the current EU eIDs in use right now or a passport.
| Revoke and reissue.
|
| > Also judging by dealing with the average citizen on a daily
| basis, even securing an iOS device and remembering the iCloud
| password is beyond their level of care.
|
| True, but that's probably something that needs to be improved
| with education.
| _Algernon_ wrote:
| >That's a non issue in the EU.
|
| For now
| closewith wrote:
| > That's a non issue in the EU.
|
| Maybe in your EU country. ID cards are not mandatory in mine
| (Ireland) - a national ID card has been rejected by the
| electorate multiple times.
|
| Be careful not to generalise your own experience to the
| entire bloc - it's not a homogeneous entity.
| timeon wrote:
| I would welcome this ID but also think that this needs to
| be optional.
| xxs wrote:
| Actually I can think of only Ireland...
| tomjen3 wrote:
| Dane here, I am not required to provide id, only to
| identify myself if asked by a police officer.
| dalke wrote:
| https://en.wikipedia.org/wiki/Identity_documents_in_Swede
| n: "There are several identity documents used in Sweden.
| None are compulsory by law, meaning that there is no
| formal penalty for not possessing one."
|
| In practice things are more difficult without one one.
| (Mine expired in January. I didn't notice until I needed
| to pick up a package a few weeks ago. Ended up using my
| US passport instead.)
|
| https://en.wikipedia.org/wiki/Identity_document says "A
| number of countries have voluntary identity card schemes.
| These include Austria, Belize, Finland, France (see
| France section), Hungary (however, all citizens of
| Hungary must have at least one of: valid passport, photo-
| based driving licence, or the National ID card), Iceland,
| Ireland, Norway, Saint Lucia, Sweden, Switzerland and the
| United States."
|
| Checking Finland,
| https://en.wikipedia.org/wiki/Finnish_identity_card says
| it's about the same as Sweden: "Possession of an ID card
| or any ID document is non-compulsory in Finland, though
| interactions with officials and companies, like voting,
| picking up a parcel from Posti offices or buying alcohol
| when a salesperson suspects buyer to be under 18 or 30
| years old, can be difficult or impossible without an ID
| card, a passport or a driving licence."
|
| As I recall, in Sweden to vote without id you need
| someone who does have an id and knows you to vouch for
| you.
| wink wrote:
| To sum it up, it's a complete mess and every country has
| different rules and also enforces them differently.
|
| After all these years I still have no clue what is
| actually an official ruling of anything because I've had
| no problem showing my driver's licence when officially
| I'd needed my id card (in Germany). Then there's the
| decade old widespread rumour that you need to _carry_ any
| form of id, which is completely wrong (with a few
| exceptions).
| Asooka wrote:
| Freedom is messy.
| andrewshadura wrote:
| > a national ID card has been rejected by the electorate
| multiple times
|
| However there's a passport card, which is nearly
| indistinguishable from an identity card:
|
| https://en.wikipedia.org/wiki/Irish_passport#Passport_Card
| closewith wrote:
| It's nearly indistinguishable from a passport, not a
| national ID card (at least as implemented in other EU
| states).
|
| The closest thing in Ireland was the "mandatory but not
| compulsory" Public Services Card and the related MyGovID,
| until it was ruled unlawful to require a PSC for access
| to government services.
|
| There really is nothing like a mandatory national ID card
| in Ireland.
| Keirmot wrote:
| Please forgive me if I'm jumping to conclusions here, but I'm
| guessing you're American.
|
| > What happens if I don't want to identify myself?
|
| In some countries that is not an option. For example, in
| Portugal when in a public space, the police has the ability to
| ask for ID if they have a reason. They must first identify
| themselves, and list the reasons to ask for identification. If
| you have no valid ID with name and photo, someone that knows
| you and can attest to your ID can do it, IF they themselves
| have ID. If you're alone, you can either ask someone to take
| your documents to where you are, or ask the police to go with
| you to where you have them. If that is still not possible for
| whatever reason, they you can be taken into a police station
| until you're properly identified and your fingerprints are
| taken.
|
| After all that, if the reason why you were identified lead to
| nothing you can request for the info on you to be eliminated.
|
| > What happens if poverty does not allow me to carry a digital
| ID?
|
| Most countries have state issued ID cards. Note, I wrote most,
| not all.
|
| > What happens if I lose my digital ID wallet or it is
| compromised?
|
| Same thing that happens when you lose your wallet, I guess. Go
| to the nearest police station, tell what happened. Then go on
| from there.
|
| > Also judging by dealing with the average citizen on a daily
| basis, even securing an iOS device and remembering the iCloud
| password is beyond their level of care.
|
| People take government stuff more seriously than they do other
| things. For example, my mother that can't remember her router
| password knows her hexadecimal password to the IRS website by
| heart. My in-laws kept the letters from the IRS with the
| password in a well known place just to use it once a year when
| they need to fill their forms.
|
| I'm not saying there's implicit trust in governments in the EU,
| but from the discourse on the internet, it's clear to me that
| most (western) european citizens trust their government more
| than Americans, overall.
| verisimi wrote:
| > I'm not saying there's implicit trust in governments in the
| EU, but from the discourse on the internet, it's clear to me
| that most (western) european citizens trust their government
| more than Americans, overall.
|
| This is absolutely right. And they are fools to do so! The
| government can write legislation such as the police have the
| right to see your id, and everyone is meant to show it! This
| is nothing to do with right or wrong. It can be couched as
| 'protecting people' whilst being tyrannical.
|
| At least in the US they have access to weaponry to give those
| government officials pause for thought of they attempt to
| implement tyranny. Europe is already defanged though - who
| could fight back, even if they wanted to?
|
| The prospect is rigid stasis - governed by an unelected
| elite, who have the mechanism of fine grained control over
| every citizen. Its neo-feudalism via technocracy.
| blitzar wrote:
| Funnily enough people in the US that bang on about tyranny
| and guns tend to also bang on about making anyone that
| looks like a foreigner present documents.
|
| Freedom for me and stazi for thee
| iasay wrote:
| I'm actually from UK and travel a lot in the EU.
|
| Having been in a police station in Portugal they'd probably
| laugh at you for getting your wallet ripped off and run you
| to the airport.
|
| And then there's the smaller towns in Germany. They don't
| even accept cards out there yet. Cash or fuck off.
|
| I think this is far off the status quo across Europe.
| donquichotte wrote:
| Am I being cynic here or is this just another attempt at total
| surveillance? It solves a problem that does not exist, will
| likely be mandatory at some point and is executed by a defense
| company.
| woodpanel wrote:
| I'm guessing more like a/multiple "recently privatized" ex-
| national telecommunications provider (ie blue chip company with
| the state as majority stakeholder). You know, "plausible
| deniability" and stuff...
|
| Edit: I stand corrected, with Thales writing this article, we
| can expect conglomorates such as Thales or Siemens to build
| this as well (corporations that due to their long standing
| national prominence are de-facto state-entities, although not
| de-jure).
| silversmith wrote:
| You just have a very US centric view. Here's the situation in
| Latvia: Full, searchable (by government institutions) digital
| registry of citizens. Your income is being recorded for tax
| purposes. There's centralised data on what vehicles you own,
| and firearms are registered too. Medical data is also being
| centralised, to handle prescriptions digitally, and share test
| results between labs and doctors. Any criminal offences are
| centrally registered too. The information is there, and most
| likely being cross-referenced already.
|
| What this would add is a more comprehensive log of where proof
| of identity has been used. In my case, the last non-digital,
| non-already-trackable request to display proof of identity was
| last summer, when I was trying to buy a case of beer with a
| mask, sunglasses and a hat completely obscuring my face. Guess
| the police will now know I visit grocery stores.
|
| What's more, that's already been sort of centralised, with a
| single identity broker latvija.lv being run by the government,
| that then relies on other "blessed" identity sources such as
| banks or digital signature providers. The logs on who requested
| the identity verification and who got verified are surely
| there. If they cut the banks out of the loop, I see that as a
| net positive.
|
| As for me, I'm not overly bothered by this. I trust the
| government to not wilfully abuse the data far, far more than I
| trust any for-profit entity.
| swader999 wrote:
| What if Russia were to overtake Latvia in the coming months
| via direct force or through installing a puppet regime? Trump
| in 2024 for our American counterparts. Would you be okay with
| the new masters having all this data and history on you?
| ciupicri wrote:
| If Russia takes over any country, it's game over anyway
| like it was after WW2. The lack of an ID won't protect you
| from rape, robbery, murder, a trip to gulag, etc.
| mrtksn wrote:
| Europeans have a rich history of bad regimes and their
| removal. It's not like the puppet regime would be like "Oh
| no, we can't do anything about this person who tweets nasty
| things about us because we can't look him up in the central
| registry". It's going to be like "hey Twitter give us the
| ip address of this person or you loose your money and
| access to our market" and then they will phone the ISP and
| tell them to give the ID and address of the user with that
| ip address.
|
| So in reality, central registry of information doesn't
| really protect you from anything but saves the bad actor a
| few phone calls. On the other hand, it saves you a lot of
| phone calls and office visits every time you need to deal
| with the government.
|
| If Russians install a puppet regime, the existence or lack
| of central registry wont actually change much. It will
| require popular uprising to make a difference, which
| Europeans are actually accustomed to.
|
| Riots and protests happen all the time everywhere and
| taking down the governments is a thing too. Of course it
| depend on the specific country but in general governments
| in European countries resign all the time and when the
| refuse to resign despite popular demand they end up removed
| by riots.
| swader999 wrote:
| Indeed they do have a rich history of bad regimes. That's
| kind of the point.
| mrtksn wrote:
| So they also have bad history of greedy private
| enterprises on which they don't have a say.
|
| The idea is that there's a value in having an
| enterprise(the government) with centralised record
| keeping because they own that government and have the
| power to change managers on predefined reviews(elections)
| and they have a history of forcefully changing managers
| who try to stick around despite not being wanted.
|
| What do you do when a private enterprise misbehaves? Mind
| you, the governmental duties are often monopolistic by
| nature. What do you do then? Sniper the CEO?
|
| It's much more socially acceptable to riot against the
| government and burn government building than assaulting
| company HQ.
| silversmith wrote:
| Russia is indeed the main threat in our neck of the woods.
| And with the regimes they tend to run, lack of easily
| accessible digital registry is not something that will save
| you from falling down the stairs and accidentally landing
| on couple of bullets with the back of your head.
|
| More importantly, we already have these registries! There's
| already a digital identity verification service in place
| that, according to our law, is sufficient to identify a
| person to the same degree an ID card / passport would in
| person. It's there, I've used it as an end-user, I've set
| up integrations with it for my clients. The issue is that
| if I want to identify myself to a German institution for
| whatever reason, the only way I know of involves burning a
| whole lot of dead dinosaur juice to get to Berlin, standing
| in an orderly queue for a while, and presenting my passport
| in person. And probably filling out couple forms along the
| way somewhere.
| maxwell wrote:
| > You just have a very [U.S.] centric view. [...] I trust the
| [Latvian/EU] government to not wilfully [ _sic_ ] abuse the
| data [ _sic_ ] far, far more than I trust any for-profit
| entity.
|
| If unclear why no one in the U.S. trusts federal, state, or
| local governments:
|
| * The U.S. federal government now mostly acting in service of
| for-profit entities, due to legalized bribery of elected
| officials ( _Citizens United_ ) and inadequate representation
| (the Judiciary Act of 1869 for the Supreme Court and the
| Permanent Apportionment Act of 1929 for the House).
|
| * History defeating the most powerful empire in world
| history, emerging as the first nation to ever overthrow a
| colonial oppressor.
|
| * U.S. law enforcement officers extrajudicially killing more
| Americans than mass shooters in 2019 and police departments
| across the country taking in billions USD every year in
| unconstitutionally seized assets.
|
| * More Black Americans in the "justice" system in the 2020s
| than were enslaved in the 1860s.
| mrtksn wrote:
| > I trust the government to not wilfully abuse the data far,
| far more than I trust any for-profit entity.
|
| The prime difference between American/British world view and
| continental European one and I'm loving it.
|
| Sure, it's very nice to think that the government doesn't
| track you and doesn't know where you live. Then they build
| these giant systems to covertly track everyone and listen to
| everything.
|
| Essentially, everything that the Americans believe that the
| government wants to do to them is already being done - just
| clandestinely.
|
| On the European approach, we assume that the government is
| competent enough and is ours, therefore we give them the
| information needed to provide services and security. If the
| governments misbehave we will simply burn their palaces and
| drag them on the streets.
|
| IMHO, both approaches have merits and I'm happy that they
| exist at the same time. It kind of keeps the institutions on
| track as scandals happen and fixes are implemented in attempt
| of self preservation.
| raverbashing wrote:
| Americans love complaining harshly whenever someone mentions
| "contry-wide" ID like it's literally the thing of the Devil
| while ignoring that every other place illegally uses their
| SSN as an ID number
| snypox wrote:
| It solves on problem for me. Since the introduction of Apple
| Pay I hate taking my wallet anywhere and 95% of the time I
| don't. But my ID and driver's license is in there and it's
| needed sometimes. This gets me closer to the goal.
|
| Let's say, travelling to a different country without a wallet
| would be amazing to me.
| kabes wrote:
| It does solve a problem that exists. In fact the use cases are
| listed in the article: filing tax reports, opening/accessing
| bank accounts, etc. Basically the stuff where in the offline
| world you would've needed to show your ID.
|
| However, many (all?) EU members already have developed their
| own national system. So this tries to unionize those systems so
| dealing with other member nations becomes easier. Today I often
| have to mail a bunch of documents if I want to prove my
| business ownership to foreign companies.
| sathishmanohar wrote:
| and eventually those tax reports and credit ratings will be
| tied to super market checkout systems. So governments can
| pick and choose which tax payers can eat what.
|
| Any data that is aggregated is open to abuse by the
| aggregator and it will be definitely abused if the aggregator
| is a government body.
| dane-pgp wrote:
| > tied to super market checkout systems
|
| Norway is one step closer to that:
|
| https://www.lifeinnorway.net/norway-to-track-all-
| supermarket...
| malermeister wrote:
| I'd much rather have my government have info about me than
| Facebook.
|
| Even in your contrived dystopia, I'd rather have a
| democratic government be the Big Brother than some
| unelected tech CEO.
| sathishmanohar wrote:
| malermeister wrote:
| Could you please elaborate your argument instead of just
| doing drive-by insinuations?
| closewith wrote:
| That's a false dichotomy. We can create a world where our
| right to privacy is respected by both governments and the
| private sector.
| malermeister wrote:
| It doesn't change the fact that our government is voted
| in, while private CEOs are moneyed in.
|
| I trust the former more to have my best interests in
| mind.
| jiveturkey42 wrote:
| The user consents to using a product, but not being born
| into a particular location
| malermeister wrote:
| https://www.cnet.com/news/privacy/shadow-profiles-
| facebook-h...
|
| Come again?
| mdp2021 wrote:
| Why do you have to bring FB into the equation? It seems
| you are mentioning it as a relevant alternative - what is
| that?
|
| When somebody says "This may be controversial // Well,
| much better than being crushed under a rock", the latter
| is supposed to be rhetoric, here somebody seems to treat
| it like a real alternative, as if you went into the
| current events to avoid that!
| mordae wrote:
| > Am I being cynic here or is this just another attempt at
| total surveillance?
|
| I don't think so. The idea is to make the wallet offline.
|
| > It solves a problem that does not exist,
|
| I does exist. Automatically checking identity is hard. Some
| counties apparently issued certificates to their citizens and
| enabled them being verified by anyone, simplifying several
| online businesses patterns.
|
| > will likely be mandatory at some point
|
| More like fast lane. But eventually (30 years) probably yes.
|
| > and is executed by a defense company.
|
| Every country is responsible for their own part. There are
| going to be ETSI standards for interoperability.
|
| The actual trouble here is that (at least in my country) the
| officials responsible believe that rooted phone is higher
| security risk than automatic updates from Chinese government.
| closewith wrote:
| > Automatically checking identity is hard.
|
| This seems like a feature, not a bug.
| stubish wrote:
| Every single non-cash transaction you make every single day
| needs to check your identity. Currently it is outsourced to
| banks, multinationals like visa, thousands of different
| government departments providing trusted docs (usually a
| few different ones per country). And a lot of fraud happens
| because we do a bad job at it. Or for-profits, doing 'good
| enough' where 'better' isn't profitable, because they get
| to pass on the trauma of identity theft to the victims.
| threeseed wrote:
| I can't see much of a difference compared to a passport or
| driver's license.
|
| The quiet explosion in CCTV cameras across Europe is far more a
| threat than some unique identifier.
| mdp2021 wrote:
| > _passport or driver 's license_
|
| Physical documents. This is an electronic system, with
| potential for issues as you (in this crowd) should suspect.
|
| > _is far more a threat_
|
| Which definitely concerns us in its own turn - who the
| daughter is dating will take its own slot.
| isbvhodnvemrwvn wrote:
| The data on the document is just a snapshot of the data in
| electronic systems. These systems are used every single day
| when you use physical documents in healthcare or any other
| government-related scenarios to double-check on that
| physical document.
| mdp2021 wrote:
| > _The data on the document is just a snapshot of the
| data in electronic systems. These systems are used every
| single day_
|
| The issue is not with the governmental database, taken
| for granted. It is with the consequences brought by the
| electronic system on the user side.
| scrollaway wrote:
| Just because you don't see the problem it is solving doesn't
| mean the problem does not exist.
|
| Some context: I'm French, I live in Belgium. I have two e-IDs
| cards: one french, one belgian. When I need to identify myself,
| depending on the government I have to deal with, I have to use
| either my "FranceConnect" credentials, or my Belgian e-ID card.
|
| When using my Belgian eID, there is a government login called
| CSAM, but a lot of people here use a private company called
| "itsme" (https://www.itsme-id.com/). ItsMe does not support
| Linux. CSAM does, but not every service that supports or even
| requires eID login here supports CSAM.
|
| FranceConnect is even more of a mess. French government has a
| plethora of online services, several with their own logins and
| not all support FranceConnect.
|
| Making a digital wallet won't increase surveillance...
| surveillance is already possible on all of this, quite easily
| so. What it will do is greatly simplify life for people dealing
| with these systems; especially for expats and new arrivals into
| a country, who might get stuck in the loop of "You need a bank
| account to get your ID" "You need an ID to open a bank account"
|
| Not to mention all the services that do their own shitty KYC
| and would be better served by using automated ID checking
| instead. Unless you think it's better and "more private" to
| email a photocopy of your ID and passport to somebody who will
| forward it three times, save it on their computer, and share it
| on Slack with the tech team because there's a problem with
| their shitty KYC system.
| _Algernon_ wrote:
| >Making a digital wallet won't increase surveillance...
|
| There is no reason to believe that. You are installing a
| government app on a gps device with a constant internet
| connection. Even if it doesn't send such data initially,
| there is no way for a regular user to know that some forced
| update in the future wont introduce it. At least before they
| would have to go through the courts to get a warrant to get
| it from google or apple.
| TacticalCoder wrote:
| > When I need to identify myself, depending on the government
| I have to deal with, I have to use either my "FranceConnect"
| credentials, or my Belgian e-ID card.
|
| That you even have to identify yourself as often as you do in
| the EU is a problem the EU countries created. So basically
| they create a problem (people needing to identify for
| basically everything: vaccine, going to the restaurant, going
| to nightclubs, maybe going to the toilet in the future, etc.)
| and then come up with a solution: _" Look, it's going to get
| easier to identify yourself!"_ and everybody applauds.
|
| But, wait, why do I need to be identified all the time yet?
| scrollaway wrote:
| Yeah. No. I identify myself when I log in to my utilities
| providers, my bank, when I do my taxes or handle some other
| government related stuff.
|
| I have no idea what you're on and I'd love to know where I
| can get some.
| drawfloat wrote:
| This might shock you but none of those things need ID in
| most EU countries.
| judge2020 wrote:
| > a government login called CSAM, but a lot of people here
| use a private company called "itsme"
|
| It probably doesn't help that the CSAM term has an overlap
| with another english abbreviation.
| scrollaway wrote:
| Belgium is not an English speaking country.
| woodpanel wrote:
| > _Making a digital wallet won 't increase surveillance...
| surveillance is already possible on all of this,_
|
| Sure, because a little minority of people has _" the burden"_
| of managing multiple IDs, lets tear down one firewall between
| citizenry and big-brother for the rest of us.
| malermeister wrote:
| What's the "firewall" in this case? eIDs already exist all
| over the place, as demonstrated in parent. They also
| clearly have their use, even though they are currently
| frequently broken.
|
| Is the brokenness the firewall?
| woodpanel wrote:
| The firewall is who is accountable, who is responsible to
| the electorate. "Broken" no, a feature yes, because
| exploiting technical flaws in a country's digital ID for
| an attacker becomes more troublesome if each country has
| a (an even slightly) different implementation.
|
| Labeling it "broken" - we all are using the same password
| for every account anyways, aren't we?
| malermeister wrote:
| But we're talking about the EU here, the second largest
| democracy in the world. Of course they're accountable to
| the electorate. This isn't a dictatorship.
| woodpanel wrote:
| Totally democratic. Of course. Europeans love it.
|
| From Berlin xHainers to Parissienne Bobos, from Munich
| Schwabing to Noord Amsterdam, there isn't a single
| citizen in the EU with discomfort of his vote becoming
| dilluted from a x-millionth to an x-hundredmillionth.
|
| That's why Ursula von der Leyen is so popular.
| illiac786 wrote:
| Diluted? EU has significantly more power than any single
| country. More than the sum of the power of each country
| taken individually. Hence, mathematically, your vote has
| more power in the EU.
| malermeister wrote:
| But thats just... yknow, how democracies work. More
| voters = less power/vote.
|
| Are you just unhappy the electorate is so large? What
| would the appropriate size be? Mayoral? Households?
| That'd really maximize the power of your vote.
|
| But then, how would we organize at the level beyond that?
| Warring tribes? Go back to when Germany and France were
| constantly at war?
|
| I don't love vdL either. I think the EU is in need of
| reform. But I still think it's fundamentally a good idea
| and I think vote dilution is just inherent to a large
| democracy.
| potatototoo99 wrote:
| There's not much democracy in the EU, and that's by
| design.
|
| I'm only surprised they haven't got rid of the ability of
| countries to secede the union yet. I'm guessing all these
| pushes for further integration are an attempt at de facto
| making it impossible to secede, even if not legally.
| malermeister wrote:
| > There's not much democracy in the EU, and that's by
| design.
|
| [citation needed]. Please don't just throw out wild
| claims without any proof. As far as I'm aware, every
| single element of the EU is democratically legitimized in
| one way or another. Do you have any evidence to the
| contrary?
|
| > I'm only surprised they haven't got rid of the ability
| of countries to secede the union yet.
|
| Why would they? If you don't want to be on our boat, feel
| free to sink on your own. We don't need the dead weight.
| timeon wrote:
| > and that's by design.
|
| And that design is there to keep sovereignty of
| membership countries - so it is strange that you are
| surprised that there is still the ability of countries to
| secede the union. Most powerful entities in EU are
| national governments of countries. Who is appointing
| Commissioners? Member states. Similar like national
| governments are appointing its ministers. Then there is
| veto and of course, who has last word in everything?
| Heads of states / prime ministers.
| rjzzleep wrote:
| Ah yeah, just like how Von der Leyen, Macron said that
| they want to abolish the consensual vote, when Hungary
| didn't play along with sanctions being a landlocked
| country. Totally democratic and totally designed to keep
| sovereignty.
| toyg wrote:
| Macron can say what he wants, he has not written any
| treaty yet. The Hungarian government is still free to act
| as they see fit.
|
| This said, majority-rule can only increase in European
| mechanisms, because a continent cannot be paralized by
| the needs of a tiny minority on every possible choice.
| Does the US Senate (effectively the equivalent of
| EuroCouncil, with almost-equal representation for each US
| state) require unanimity on every choice? Obviously not,
| or it would never get anything done (and even like that,
| it struggles massively to approve anything these days).
| jules wrote:
| From my vote to this decision there are so many layers of
| abstraction that I wouldn't even begin to have a clue who
| to vote for and in which election if I do or do not want
| this E-ID.
|
| At least in national elections there are parties
| campaigning with a platform and then I can decide which
| platform I like best. How often the platforms of the
| elected parties get translated into reality is another
| question, but it can at least plausibly be described as
| demos kratos. Maybe the EU is "democracy" in some modern
| sense of the word, but in the original sense of the word
| it is not. (I'm not even saying that's a bad thing. Maybe
| it is in fact better to have elites deciding.)
| toyg wrote:
| _> At least in national elections there are parties
| campaigning with a platform and then I can decide which
| platform I like best._
|
| I fail to see how you cannot do that in European
| Parliament elections. If anything, EUP elections are more
| democratic than average, by way of using a proportional-
| representation system that matches voters' preferences
| more closely than almost any European voting system.
|
| And if you're saying, "but it's the Commission proposing
| laws!", they don't pull stuff out of thin air: the
| Commission effectively tries to implement an agenda that
| European Council members agree together. And who is
| EuroCouncil? National governments, whom you vote for.
| Also, the Commission doesn't work alone - directives are
| effectively drafted in concert with Parliament
| committees, because in the end they have to be approved
| by such Parliament.
| argentier wrote:
| The EU is not a democracy. Its only democratic organ is
| toothless.
|
| It is an association of democracies, led by an
| undemocratic executive that is increasingly out of
| control. At the moment it is busily destroying its own
| economy in a way that is baffling to many of its
| citizens.
|
| If it doesn't evolve into something more democratic it
| probably hasn't long to go.
| malermeister wrote:
| The executive is appointed by democratically elected
| officials. Y'know, the same way the US president is
| elected by electors, or Prime Ministers are elected by
| parlaments. Most democracies work this way.
| argentier wrote:
| In fact it's quite different.
|
| The US president campaigns before a democratic election.
| The people know who they can choose before they vote.
| Same with the UK.
|
| There is no democratic vote, with or without proxy,
| before the appointment of the Commission.
|
| Why the downvote btw? This isn't reddit.
| M2Ys4U wrote:
| >There is no democratic vote, with or without proxy,
| before the appointment of the Commission.
|
| Err, yes there is. The directly-elected European
| Parliament first elects the President of the European
| Commission, and then has to vote to appoint the entire
| Commission.[0]
|
| And before they do they they hold hearings with each of
| the different commissioner-nominees to evaluate their
| suitability for the role, demanding that people are
| replaced or given different portfolios if they are not
| suitable.
|
| Nominations for the role of President must take in to
| account the results of the election,[0] and the European
| Council nominates somebody from the largest party in
| Parliament. I wish that Parliament had stuck to its guns
| in 2014/2019 and rejected the nominees that weren't
| spitzenkandidaten but hopefully the new proposals tabled
| by Parliament creating transnational lists for Parliament
| will change this.[1]
|
| [0] Article 17(7) of the Treaty on European Union
|
| [1] https://www.europarl.europa.eu/news/en/press-
| room/20220429IP...
| raverbashing wrote:
| > with or without proxy, before the appointment of the
| Commission.
|
| Of course there is. The commission is chosen by the
| countries elected representatives (and confirmed by the
| directly elected EU Parliament)
|
| The downvotes are justified
| mantas wrote:
| Too many abstraction layers and too much happening behind
| closed doors withotu elected politicians present. As a
| citizen of EU member, I find it very hard to define EU as
| a democracy.
|
| We need Swiss-style referendums-on-everything. Now it
| feels like oligarchy managed by lobby groups no matter
| what you vote for.
| scrollaway wrote:
| > _We need Swiss-style referendums-on-everything._
|
| Ah, yes, nothing like asking 450M people for their
| opinion on something they know nothing about.
|
| This is how Brexit happened, isn't it?
| mantas wrote:
| Do we want democracy? Or ruling by oligarchs, hoping that
| oligarch you like will end up ruling?
|
| Obviously democracy needs educated citizens who don't
| take the responsibility lightly. That's why citizenship
| shall be a big privilege with even bigger
| responsibilities. We have to have a lively discussion.
| Otherwise it's people who cry loudest win.
|
| I love Brexit as a democratical move. People voteds and
| government followed through. Now citizens will live out
| consequences, for better or worse. And they can make next
| decision accordingly. That's so much better than
| enlightened oligarchy guarding the masses from their own
| wrong feelings.
|
| That's like raising kids. If you guard kids from their
| own painful decisions, they'll never learn. Eventually
| they'll be adults and they'll keep doing dumb decisions.
| You have to let them experience some pain to teach them a
| lesson.
| [deleted]
| kabes wrote:
| What do you mean itsme does not support linux? It's a phone
| app, you don't need to install anything on your linux
| machine...
|
| However, it's not a good situation that a private company
| gets such a central role. In fact, Belgian government
| yesterday announced they're going to make their own
| implementation. Surely there's already eID login, but that's
| too cumbersome compared to itsme because it's from the pre-
| smartphone days.
| scrollaway wrote:
| Are you talking about this?
|
| https://www.brusselstimes.com/belgium/246070/federal-
| governm...
|
| The Belgian government already has an implementation:
| https://www.csam.be/en/egov-profile.html
|
| I don't use itsme, only CSAM, because itsme does not
| support Linux: I can't log in with Firefox or Chrome on
| Linux with my eID. But CSAM is not universally supported.
| Example of a site that does not support it:
| https://www.proximus.be/ - Major ISP in Belgium)
| sam_lowry_ wrote:
| Itsme is an authentication token, like eID.
|
| You can login to CSAM protected websites on Linux with
| Firefox or Chromium and with Itsme token running on
| Android or iPhone.
|
| You can also login on Linux with Firefox or Chromium and
| with your eID card inserted in a properly configured card
| reader such as ACR-38U.
| seszett wrote:
| I'm not sure because I don't use itsme anymore (it
| stopped working on jailbroken devices a while ago, so I
| just switched to TOTP auth with CSAM) but if I remember
| correctly the _initial setup_ of itsme doesn 't work on
| Linux, as it requires a browser plugin for the card
| reader that doesn't run on Linux. CSAM uses a different
| browser plugin that does work on Linux.
| scrollaway wrote:
| Yes that's exactly right.
| sam_lowry_ wrote:
| I set up itsme on my android phone using linix. This was
| a couple years ago, so things likely changed for worse
| since then.
|
| P.S. If you use a JB device, you should also use Magisk
| and be ready to troubleshoot.
| ploum wrote:
| Worth mentioning that itsme is a private consortium of
| several banks and phone operators which explicitely says
| that data collected will be used for marketing purpose
| and "research".
|
| That you can't even think of using it if, like me, you
| are not using a phone operator or one of the few banks
| which are part of the consortium.
| seszett wrote:
| That's not true, in my experience you can even use it if
| you only have a French phone number and no Belgian bank.
| ploum wrote:
| Indeed, they added the ability to create an account with
| your eid. It was not the case a couple of years ago.
| thepangolino wrote:
| kabes wrote:
| > Are you talking about this?
|
| Yes, that's what I'm talking about, although
| brusselstimes seems to report it weirdly (sounds like
| they want to extend itsme).
| https://www.standaard.be/cnt/dmf20220627_97617861 -> They
| want to replace itsme with something build by the
| government.
|
| > The Belgian government already has an implementation:
| https://www.csam.be/en/egov-profile.html
|
| You're confusing a couple of things here. CSAM isn't an
| identity provider. It's like a gateway/umbrella to
| multiple identity providers like eID and itsme. You can
| have eID authentication without CSAM and vice-versa.
|
| It doesn't make sense to claim itsme doesn't support
| linux. It's only a phone app, you dont need desktop
| software. I can login to proximus.be using itsme on
| linux.
| sam_lowry_ wrote:
| The worst part af all this government id story that no
| one talks about is that Belgian government lost control
| of its Root Certificate Authority.
|
| It is now handled by Digicert, a US company.
| fazgha wrote:
| Do you have any source for this ? I know that current
| root certificates are self signed. [0]
|
| [0] https://repository.eid.belgium.be/certificates.php
| throw10920 wrote:
| > It doesn't make sense to claim itsme doesn't support
| linux. It's only a phone app, you dont need desktop
| software. I can login to proximus.be using itsme on
| linux.
|
| I think you're seriously confused. It's _perfectly_
| reasonable to claim that itsme doesn 't support Linux.
| Phone have operating systems too, you know - and some
| phones run a Linux userspace (e.g. the Pinephone and
| Purism).
|
| "Does not support Linux" means "itsme can't run on a
| Linux userspace" (as opposed to a Linux kernel but Google
| userspace, which is what Android is).
|
| The author explicitly says this: "I don't use itsme, only
| CSAM, because itsme does not support Linux: I can't log
| in with Firefox or Chrome on Linux with my eID."
| mariusor wrote:
| Is it so difficult to conceive that are people out there
| using phones that run something else instead of Android or
| iOS? Even linux.
| the_biot wrote:
| Of course it is. Note this line from TFA:
|
| _Something the customer is (fingerprint, iris, face)_
|
| Right there, trying to normalize the idea that the government
| needs our fingerprints, iris etc. And that ship has sailed,
| lots of laws getting passed that will _require_ this from
| citizens.
| radicalbyte wrote:
| I'm involved in a group who come into contact with this. It's
| not about surveillance, it's about providing European
| governments, European economy and citizens with electronic ID
| in all situations without having to rely on
| Google/Apple/Facebook. So you can have a secure way to login to
| websites, with many personas, without having to share your GAF
| (and thus be tracked by GAF / share GAF data with yet another
| party).
|
| Thales on the other hand are not what I would describe as a
| good actor but rather one of the "usual suspects".
| mdp2021 wrote:
| > _without having to rely on G. /A./F. So you can have a
| secure way to login to websites_
|
| Said perspective is insanity: for those websites relevant to
| an anagraphic identity it would be dramatically abnormal to
| use any supposed private company related account. It would be
| sheer absurdity to suppose a "need" for accounts with private
| entities to log on to nominal services.
| Asooka wrote:
| The number of websites where I would willingly use my real id
| is no more than five. I almost never want to have anything I
| write online attached visibility to my actual public
| identity. Anonymity is the whole point of the internet!
| swader999 wrote:
| Any functioning society needs anonymous dissent, especially
| a democracy.
| radicalbyte wrote:
| Personally I have a dim view of the companies working in this
| area / the working groups because so far they've not
| delivered anything yet have been working on it forever. You'd
| expect there to be a vibrant community on Github sharing Open
| Source implementations. Or at least speaks. Or at least
| something.
|
| Also there are so many bullshitters and snake-oil merchants
| in this field; makes you think that most of the "security"
| industry is a confidence game.
| woodpanel wrote:
| > _So you can have a secure way to login to websites, with
| many personas, without having to share your GAF_
|
| Let's manage the beloved and accountable Eurocrats in
| Brussels our private Auth-infrastructure, because its not
| like this problem would be solvable otherwise:
|
| https://news.ycombinator.com/item?id=31836922
| blitzar wrote:
| Let's give the beloved and accountable Google / Facebook /
| Microsoft in the US of A our private Auth-infrastructure,
| because its not like this problem would be solvable
| otherwise, and its not like they have ever done anything
| with our data before that would make you wonder if they can
| be trusted.
| woodpanel wrote:
| FIDO is an open standard, that by definition doesn't
| store your data at GAF.
| blitzar wrote:
| I look forward to being able to pick up the phone to
| Google / Facebook / Microsoft, talk to a human and have
| them troubleshoot why they have locked me out of
| everything in the world.
| hourago wrote:
| > accountable
|
| That's the key. European politicians are accountable to
| European citizens. Big corporations are not. This seems a
| step in the right direction.
| woodpanel wrote:
| > _European politicians are accountable to European
| citizens._
|
| That joke made my day. I'm guessing Ursula von der Leyen
| is a real people's champ then.
|
| > * Big corporations are not. This seems a step in the
| right direction.*
|
| So let big corporations develop the technology?
| Especially those that are intertwined with the state? In
| otherwords, entitites where the state has created
| plausible deniability for itself? Great, what could go
| wrong?
| malermeister wrote:
| This might be a shock to you, but people here would rather
| have their democratic government in charge of identity than
| some unelected, for-profit foreign company in a country
| that specifically does _not_ have any privacy protections
| for non-citizens.
| Asooka wrote:
| I would rather not have online identity at all.
| fvdessen wrote:
| Then don't use the system ?
| swader999 wrote:
| It's telling that both you and I opted to choose a
| username that is somewhat anonymous on this system. We
| both saw this as preferable.
| malermeister wrote:
| This system isn't designed for writing comments on Hacker
| News.
|
| It's designed for things like filing your taxes or
| applying for a passport.
| swader999 wrote:
| Won't be hard to use it for everything, especially
| purchases. That's the main issue.
| malermeister wrote:
| It would be hard from an operational and customer
| satisfaction perspective.
|
| Does the grocery store ask you for your passport? If not,
| why should the online store ask you for your online
| passport?
| woodpanel wrote:
| This might be a shock to you, but people in Europe
| already have _their_ democratic government - you may
| google "national elections" ;-)
|
| And again, FIDO is an open standard, that by definition
| isn't run or dependend on the servers of "for profit
| private companies".
|
| But gee, I must be total noob then. Open-Source can be
| bad, as can be accountability.
|
| For the greater good I guess.
| malermeister wrote:
| > This might be a shock to you, but people in Europe
| already have their democratic government - you may google
| "national elections" ;-)
|
| People _in Europe_ don 't. People _in the various
| countries_ do. This is just a level above, just like you
| don 't say "oh why do we need the german government,
| can't the mayors do everything?".
|
| Different levels of organization need different
| democratic governments. Tribalism is not the solution.
| argentier wrote:
| What is democratic about the European Commission?
|
| Having an executive made up of people selected by other
| politicians for political reasons is all very well as
| long as they understand that they do not have much
| legitimacy.
|
| JC Junker, for all that he was a bit of an old sot,
| understood this very well.
|
| Von der Leyen, either because of her immensely privileged
| background, or because of her inability to communicate in
| any diplomatic way, has revealed the undemocratic
| abomination at the heart of the European Project.
|
| Her press conference with Stoltenberg (and Belgian
| nonentity Michel) at the outset of the Ukraine war
| deprived the EU of any room for manoeuvre in relations
| with Russia. She unilaterally committed hundreds of
| millions of people to a diplomatically absolutist
| position. Furthermore, she actively spun against attempts
| by Macron and Scholz to moderate that position.
|
| The EU cannot continue like this: already I'm quite
| dubious as to whether it will survive the winter, with
| double digit inflation and mass industrial layoffs in
| prospect.
|
| If Putin wants to play divide et impera with Russian
| fossil fuel supplies, she has certainly created the ideal
| conditions for him to do so.
|
| She is corrupt (see Pfizer SMS) and unaccountable.
| malermeister wrote:
| The commission is appointed by democratically elected
| heads of government, the same way the US president is
| appointed by democratically elected electors or the Prime
| Minister of the UK is appointed by democratically elected
| MPs.
|
| Are all of those undemocratic, too?
|
| > Her press conference with Stoltenberg (and Belgian
| nonentity Michel) at the outset of the Ukraine war
| deprived the EU of any room for manoeuvre in relations
| with Russia.
|
| Russia's war of aggression on our neighbor deprived us of
| any room for manouvre. We've seen what appeasement brings
| in the 30s, no need to play that game again.
| argentier wrote:
| Not every enemy is Hitler: not every attempt at a
| diplomatic settlement is appeasement. That's
| childishness, and lamentably common at the moment.
|
| The game we are playing is resulting in mass death and
| destruction in Ukraine, and slowly throttling the
| European economies. What's the point?
|
| Perhaps if you expanded your frame of historical
| reference you might see more clearly.
| malermeister wrote:
| Not every enemy is Hitler, but the one trying to find
| more Lebensraum for his volkisch ideology certainly is
| :-).
|
| Perhaps if you educate yourself more about the era you
| might see the parallels more clearly.
|
| You say "slowly throttling the economies", I say finally
| giving us a reason to accelerate investment in renewables
| before climate change kills us all.
| yaantc wrote:
| FIDO allows to authenticate to _an_ identity, which
| ideally is securely stored in a token and cannot be
| cloned or stolen. This identity is only an large,
| arbitrary number and that 's all. This is not enough
| here.
|
| The example provided (bank account, university
| registration) make it clear that we're talking about
| authenticating against a person real, legal entity here.
| It's not needed in all cases, and when it's not FIDO is
| fine, but when it's needed in the end the root of trust
| in Europe is one's national state anyway.
| cm2187 wrote:
| Every time you create an entry into a log file you have
| surveillance. It doesn't matter whether someone is currently
| watching the CCTV in your bedroom if it's all on tape.
| closewith wrote:
| Providing governments with a de facto mandatory electronic ID
| for every citizen is inherently providing the means to
| surveil, though.
|
| I also wonder how this will be regarded in countries like
| Ireland, which doesn't have a national ID card and where a
| recent attempt to make a similar digital ID system mandatory
| was ruled unlawful (PSC/MyGovID).
| slartibardfast0 wrote:
| Ireland can't really do a national id scheme without mutual
| agreement with the UK due to the common travel area &
| mutual residence rights (including voting at parliamentary
| level upon taking residence) that are dealt with in an ad-
| hoc manner for many reasons. due to this, Ireland has
| default opt-out on justice & home affairs issues.
|
| however, as an EU citizen, I can see immediate advantages
| to a cautiously administered digital id. as it is, many
| states within the EU demand a national tax id on
| registration for services as simple as bike rental, such a
| digital id would presumably supersede such nonsense and
| help further the single market everyone is working towards.
| herbstein wrote:
| > Providing governments with a de facto mandatory
| electronic ID for every citizen is inherently providing the
| means to surveil, though.
|
| But this suggestion ain't it. Most EU countries already
| have a de facto mandatory electronic ID for every resident.
| closewith wrote:
| > But this suggestion ain't it.
|
| What's your basis for this claim? From the declared
| strategy, it seems perfect for abuse as a surveillance
| tool.
|
| > Most EU countries already have a de facto mandatory
| electronic ID for every resident.
|
| As stated elsewhere, my country (Ireland) does not. It's
| attempt at a mandatory electronic ID (MyGovID/Public
| Services Card) was ruled as unlawful (it's still
| available, but cannot be required to access government
| services).
|
| Strategy link: https://ec.europa.eu/info/strategy/priorit
| ies-2019-2024/euro...
| radicalbyte wrote:
| The regulation will have to make that illegal - there are
| several countries who would block the regulation it if it
| wasn't.
|
| So the situation will be better for us than today - there
| will be more options providing the ID (and wallets),
| including highly privacy-preserving tech based on modern
| encryption techniques. That will make it much harder to be
| tracked by commercial players and much harder to be tracked
| legally by governments.
|
| For the blackhat / illegal security agencies: you might
| make it a little harder because the US-compromised
| companies (FAANG + MS) aren't (always) involved.
| swader999 wrote:
| If that's all it is then fine. But it seems to be just the
| first step to what many fear will become a system tied to
| digital currency, speech and social credit.
| cmroanirgo wrote:
| ...and yet because there's only Apple and Google providing
| hardware that's used by the masses, exactly how is this going
| to work? If the environment we're using is completely
| contained (pwned) then how will this not be a draconian
| system of control?
|
| What happens when I buy debian mobile? I presume it will not
| be accepted because there will be no safe app. No app, no
| identity? No identity means you're suddenly locked out of
| society.
|
| What phone theft? Most people's phone security is almost non
| existent.
|
| What about luddites who have no mobile at all?
|
| It seems like it's 100% about control of people. And that's a
| privacy matter. My body, my life, my choice.
| mdp2021 wrote:
| > _mobile_
|
| In theory, you should be able to go on using a passport for
| your actual needs. In practice, it is to be seen whether
| this initiative will cause or not cases where "options"
| become "constraints".
| asdajksah2123 wrote:
| It's surveillance to the extent any ID system is surveillance.
|
| This is a digital form of all the IDs you get from the state
| already.
|
| There are genuine concerns about the scale at which digital IDs
| can potentially be exploited and/or the scale of monitoring
| this can enable, but in functional societies and governments
| you can build laws and systems to mitigate such issues.
|
| The alternative are low quality ad hoc systems that offer
| convenience, but have no incentive for privacy and/or security.
|
| For example, consider the massive Experian hack in the US. A
| credit score is basically required if you want to be a
| functioning member of American society. And yet they barely got
| a slap on the wrist and continue with their pathetically poor
| security practices. And it's not like they (or any US entity,
| for that matter) will not make their data available to the
| government.
|
| In fact, with a government controlled DB the voters can have
| far more say on what the govt can do with that data, as opposed
| to Apple or Google owning that data (which is what's happenign
| in the US with Apple providing digital ID for states, and I'm
| sure Google will get into that as well), which becomes their
| private data and as a member of society you have no say on what
| can be done with that.
| nix23 wrote:
| >just another attempt at total surveillance?
|
| Well yes, have you seen what europol can do now? Safe and
| analyze data even from unsuspected people.
|
| German:
|
| https://www.heise.de/news/Europols-Mandat-zur-Massenueberwac...
| cm2187 wrote:
| Most of the examples mentioned in the article already require
| your identity (opening bank account, tax return, etc).
|
| Others are outright creepy. You can't access medecine without
| verifying your ID? That locks lots of people out of access to
| healthcare (illegals, tourists, etc). Age verification? So porn
| websites will store the real id of all their visitors (or
| alternatively a central EU age verification system will be
| notified every time you visit such a website)?
|
| In France for instance it is illegal to identify people by
| their social security number in a system (at least it was 20
| years ago). That's a safeguard to prevent it from making it too
| easy to correlate an identity across many systems. This ID
| scheme will go around that. To be honest I think that law was
| passed at a time where surveillance was still considered evil.
| I think governements of most liberal democracies today are
| actually entertaining stasi-style surveillance as a greater
| good.
| M2Ys4U wrote:
| >Others are outright creepy. You can't access medecine
| without verifying your ID? That locks lots of people out of
| access to healthcare (illegals, tourists, etc).
|
| Does it not make sense that prescription medication can only
| be picked up by somebody who has been prescribed that
| medication (or somebody who has been delegated that authority
| by the prescribee)? As long as there's an offline mechanism
| available for verification I don't see the problem here.
|
| >Age verification? So porn websites will store the real id of
| all their visitors (or alternatively a central EU age
| verification system will be notified every time you visit
| such a website)?
|
| Presenting a token verifying that one is over 18 is not the
| same thing as presenting one's _entire identity_ so that the
| service can verify one is over 18.
|
| The way it could work is this: You try and access an age-
| restricted service (ARS). It returns a request for age
| verification including a unique ID. You then pass a hash of
| that request to the age verification service (AVS), and get
| back a token which is signed by the AVS. That token is then
| presented to the ARS, which validates that the signature and
| that the hash of their request are valid.
|
| Boom, you have just verified that you are over 18 without
| leaking your identity to the ARS and without leaking the
| ARS's identity to the AVS.
| cm2187 wrote:
| All you have done is to move the juicy log file to the AVS,
| haven't you?
| M2Ys4U wrote:
| All the AVS knows is that you're asking for an age
| verification token for _something_ , but it doesn't know
| what the token will be used for as that information was
| collapsed in to a hash by you.
|
| I'm sure there could be some sort of more elaborate
| protocol that would preserve privacy in the case of a log
| breach, the one I sketched out just shows that (assuming
| logs remain private and there's no collusion) that the
| ARS doesn't need to know the user's identity and the AVS
| doesn't need to know the ARS's identity in order to
| validate the user's age.
| wewxjfq wrote:
| Age verification already works with the current digital IDs
| and it's made in a way that doesn't leak your personal data.
| In general you get to see what personal data is being
| requested before you agree to transmit it. The IDs can also
| create pseudonyms, so different systems don't know that you
| are the same person.
|
| I opted out of the digital functions of my ID, but I plan to
| have them activated, because it's better than video
| identification or uploading scans of my documents. That being
| said, I hope that only serious processes will adopt this.
| zeeZ wrote:
| In the context of German ID cards, this is mostly correct.
|
| For age verification requests, the service provider can set
| the amount of years, and the ID card will simply answer
| with a yes or no.
|
| The pseudonym isn't created, but calculated from the ID's
| private key and the service provider's public key, so even
| a new card means new pseudonym, which makes it slightly
| less useful for login long term.
| ccbccccbbcccbb wrote:
| You're being straight up realist here.
| ekleraki wrote:
| I live in Denmark, I have an "easyID" (NemID), along with a
| social security number that allows me to connect to all
| government websites. The system allows people to use physical
| passcodes mailed to people, or send a push notification to
| their phone, to trigger the NemID application to approve or
| disapprove the entry.
|
| As others have mentioned, similar stuff exist in other
| countries as well.
|
| So to me, I'd rather have a single common, shared and
| opensource system for both Denmark, and all of EU.
| Poppys wrote:
| The problem of digital identity theft/fraudulent identities
| exist very much, you can't get rid of crime by individuals or
| nations. So it seems that this would be a solution.
|
| Most EEA countries issue physical identity cards already, so a
| digital one would seem a logical step.
|
| Not that I don't disagree with the concerns about it.
| nathias wrote:
| this is bad because it will be useful and more web will be
| KYC/AML compliant which serves nothing except surveillance
|
| a good global ID system with zero knowledge is possible of
| course, probably even with this system, but no goverment will
| pass free up free control ...
| sirnicolaz wrote:
| Any hint on what technology they are going to use?
| tagyro wrote:
| It's based on [eIDAS](https://ec.europa.eu/cefdigital/wiki/disp
| lay/CEFDIGITAL/2019...)
| woodpanel wrote:
| Since they mention trust and wallet all the time: Bet on a
| government-run blockchain. What could go possibly wrong?
| mordae wrote:
| Wallet because European ID is a tabu.
| mordae wrote:
| As far as I remember, mostly COVID certificate tech. I don't
| think the standards are done yet.
| DocTomoe wrote:
| This is not the first attempt to set something like this up in
| the EU (in fact, the directive is some 10 years old), and it
| won't be the last. In the end, it will die like all the projects
| that come before it, because with 27 member states all having
| different structures, the complexity will kill it.
| happyweasel wrote:
| I hope you're right on this
| londons_explore wrote:
| It will die because it's in Thales strong financial interests
| to have it die a slow death with many contract revisions and
| cost increases.
|
| Source:. I have been in meetings where defence contractors
| discuss how to corner the customer (the government) to force
| them to pay for more work. Up to 300x the original contract
| value over 7 revisions in one case!
| ChuckNorris89 wrote:
| Also, Thales is basically a sweatshop in Eastern Europe.
| They'll charge the EU several times what the work is worth in
| Western European dev wages, then nearshore the actual work in
| their Eastern European offices. Similar to what IBM, Oracle
| and other consultancies and bodyshops are doing.
|
| I wish I was a Western European manager there. Make huge
| wages without doing much work other than churn out PowerPoint
| presentations to the tech illiterate C-suite and boss around
| some Eastern European juniors.
| snypox wrote:
| The EU digital covid certificate works quite nicely and I used
| it at multiple countries. This might be a bigger challange but
| still.
| fer wrote:
| The EU covid certificate is nothing more than a signed piece
| of data with a PKI behind, the complexities between that and
| the eWallet proposal are orders of magnitude away.
| mordae wrote:
| It won't die this time. They are utilizing the momentum and
| tech lessons from COVID passes. This is happening.
| MonkeyClub wrote:
| I'm of the same opinion, this is definitely happening,
| nobody's asked whether they want it, it's just the next
| necessary thing.
|
| In theory, it's bad for "democracy". But I'm more worried
| that social existence will necessitate a digital existence.
|
| I'm connected, therefore I exist?
|
| No way.
| spinny wrote:
| A very similar system has been in place in Portugal for some
| time.
|
| The Portuguese EU id card (probably like all other EU id cards)
| can be used access multiple government web services. There is
| also a mobile app to go along with it.
|
| The card contains 2 tls certificates (rsa 2048 bits) and are pin
| protected (signing operations).
|
| One is used for authentication (there is a public api available
| IIRC), the other is used for signing (that digital is considered
| a legally binding signature)
|
| Not sure about the mobile app but i assume the same functionality
| without the inconvenience of owning a card reader
|
| Vending machines that sell things for 18+ like smoking papers and
| lighter are required to have a card reader to verify the buyer
| age
| sweden wrote:
| The Portuguese implementation of this is quite poor and widely
| unused. They started to improve it recently but nothing beats
| the implementation of BankID in Sweden, it is definitely a
| killer feature.
| Avamander wrote:
| > for authentication (there is a public api available IIRC)
|
| If it's anything like what Estonia has had for ~10 years, it's
| probably the usual mTLS for authentication.
|
| You can also very likely use it anything that has smart
| card/PKCS#11 support - that includes SSH, logging in to your
| PC, and depending on the certificate S/MIME in Thunderbird or
| Outlook.
|
| > rsa 2048 bits
|
| Curious choice.
| spinny wrote:
| And the cert chain on those is valid. i took a peek when i
| got mine the certificates (at the time) were issued by a sub-
| ca which by the name seems to be a gov entity and issue id
| card certs only. don't remember which company owned the root
| cert of the signing chain (it was a one of the common root
| cert used by browsers)
|
| The choice of rsa2048 is probably because of the card specs.
| it couldn't handle 4096 keys (this was maybe 10+ years ago)
| from what i've read at the time
| upofadown wrote:
| 2048 bit RSA is probably the most conservative choice
| available at this point in time. For a thing like that you
| want conservative.
| Proven wrote:
| dariosalvi78 wrote:
| this is excellent news and I hope they will do it right (reliable
| technologies, secure, privacy-minded etc.). I need to deal with
| public administration in 3 EU countries and managing 3 different
| byzantine digital IDs is a pain in the ...
|
| Of course many people here will scream at "government control"
| and "dictatorship", while happily sharing all their lives with
| unaccountable US corporations.
___________________________________________________________________
(page generated 2022-06-30 23:03 UTC)