[HN Gopher] EU Digital ID wallet is coming
       ___________________________________________________________________
        
       EU Digital ID wallet is coming
        
       Author : taubek
       Score  : 155 points
       Date   : 2022-06-30 06:08 UTC (16 hours ago)
        
 (HTM) web link (www.thalesgroup.com)
 (TXT) w3m dump (www.thalesgroup.com)
        
       | DigitalVerse wrote:
       | Disappointing to see that they're taking a centralized approach
       | to this problem. There are alternatives out there, but I guess
       | they're not interested.
        
         | checkurprivlege wrote:
         | There's an obvious conflict of interest when an organization
         | both offers services, and decides what vendors are allowed
         | 
         | Unfortunately, many people fail to see this obvoius trap.
        
       | throw10920 wrote:
       | > Imagine if you could do it in seconds via a mobile wallet app
       | that works anywhere in the EU?
       | 
       | There's mention of "mobile" with no corresponding mention of
       | desktops or operating systems, so it seems safe to assume that
       | the app will only work on iOS and Android phones (and probably
       | not even rooted Android devices).
        
         | Avamander wrote:
         | Yes, it's very likely software-based solution the likes many
         | countries have (Smart-ID, BankID and others). It's in many ways
         | just easier that way. Better? I don't think so.
         | 
         | It is possible to do it without an "app" by using SIM applets.
         | The keys are stored on the SIM card, it acts as an HSM.
         | Estonian Mobile-ID has been implemented using that and it works
         | even on feature phones. There are a few papers about the system
         | if one searches around and if you're interested.
        
       | checkurprivlege wrote:
       | Citizen identification falls under the responsibility of my
       | country.
       | 
       | EU is neither my country nor it will ever be. Therefore, no EU
       | digital Id for me.
        
       | N19PEDL2 wrote:
       | Some EU countries already have a digital ID system. The Italian
       | SPID [0], just to give an example, has been one of the most
       | important steps forward in e-government in Italy in recent years.
       | The goal should be to make existing systems interoperable, rather
       | than to create a new supranational EU-wide one.
       | 
       | [0] https://www.spid.gov.it/en/
        
         | jakopo87 wrote:
         | It already exists and it's called eIDAS[0].
         | 
         | [0] https://en.wikipedia.org/wiki/EIDAS
        
       | bool3max wrote:
       | We're fucked.
        
       | noodlesUK wrote:
       | Tbh I'd much prefer a well designed digital ID system that has
       | privacy protections built in rather than what we're getting in
       | the UK which is weird digital ID being brought in through the
       | back door with proprietary products like Yoti [1] getting
       | government support.
       | 
       | This could potentially replace some of the most invasive and
       | horrible companies like Experian who've carved out a niche in
       | verifying ID.
       | 
       | [1] https://www.yoti.com/
        
         | dane-pgp wrote:
         | Isn't it possible that the UK government is supporting "weird
         | digital ID" because they know it will inevitably fail in some
         | catastrophic way and then they'll be forced to step in and
         | unify all these proprietary systems into a government-run
         | replacement?
         | 
         | It will probably be implemented by a "VIP lane" contractor[0]
         | and/or be an extension of the existing Biometric Residence
         | Permits (BRP) system[1], which has been mandated for foreigners
         | without much protest because immigrants are an easy target.
         | 
         | [0] https://www.bbc.co.uk/news/uk-59968037
         | 
         | [1] https://www.gov.uk/biometric-residence-permits
        
       | ParksNet wrote:
       | The EU is just following the WEF agenda:
       | 
       | https://sociable.co/government-and-policy/wef-wto-global-dig...
       | 
       | Next step will be Digital Identity required to post online, and
       | police action against wrongthink.
       | 
       | We've already seen Digital Identities used to unperson anyone who
       | doesn't accept (arguably dangerous and experimental) medical
       | treatments.
        
         | beebmam wrote:
         | I don't think the people who made this site are interested in
         | presenting an honest analysis of this topic. It looks like
         | straight up propaganda, with a massive amount of ads.
         | 
         | Can you find me a source that presents more than one
         | perspective on this topic, like perhaps on Wikipedia?
        
           | ParksNet wrote:
           | The UK is already pushing this:
           | 
           | https://www.gov.uk/government/publications/online-safety-
           | bil...
           | 
           | "Requiring Category 1 services to ensure adult users are
           | given the option to verify their identity, and tools to have
           | more control over the legal content that they see and who
           | they interact with -- this would include providing adults
           | with the option not to interact with unverified users."
           | 
           | What starts as 'an option to verify their identity' will soon
           | become 'must verify their identity'.
           | 
           | Authorities in Australia have already arrested people for
           | _online_ opposition to COVID lockdowns:
           | 
           | https://www.bbc.com/news/world-australia-54007824
        
             | [deleted]
        
           | ellopoppit wrote:
           | Lots of well sourced, verifiable information here:
           | 
           | https://unlimitedhangout.com/2021/01/investigative-
           | reports/s...
        
           | [deleted]
        
         | thomassmith65 wrote:
         | I'm sorry to condescend, but do you have a therapist? It might
         | be healthy to touch base with normies once in a while.
        
           | neither_color wrote:
           | I don't think it's unhealthy to consider 2nd and 3rd order
           | consequences of upcoming policies. What _is_ unhealthy and
           | historically documented as potentially dangerous is accusing
           | your opposition of mental illness. https://en.wikipedia.org/w
           | iki/Political_abuse_of_psychiatry_...
        
             | ellopoppit wrote:
             | What a classic, I remember when people would call you crazy
             | for claiming that governments were working with
             | corporations to perform mass domestic surveillance
        
       | notaspecialist wrote:
       | Getting your hands on equipment to make identity documents is
       | physically difficult, requires lots of deals, is costly, and is
       | limited to a few people.
       | 
       | Replacing this with an electronic system, where access is
       | guaranteed via leased lines to many locations, with sloppy
       | physical controls... and a back-end that more than likely has
       | several holes due to misconfigurations, last-week exploits etc
       | 
       | This is fine.
        
       | janandonly wrote:
       | I don't really know how this is (will be) different from the
       | current iDin system?
       | 
       | This system allows one to identify him/her self via, for example,
       | a banking app.
       | 
       | https://www.ct.nl/nieuws/idin-identificatie/
       | 
       | https://www.idin.nl/
       | 
       | https://www.consumentenbond.nl/betaalrekening/idin
       | 
       | I realize now that I can only find Dutch links to this system, so
       | I am assuming The Kingdom of the Netherlands is simply ahead of
       | the EU crows?
        
         | scrollaway wrote:
         | Several countries in Europe have rolled their own. This system
         | is an attempt to digitize the countries that haven't, and
         | standardize the countries that have (and make it work EU-wide,
         | so it works better for citizens moving between countries).
        
         | onetoo wrote:
         | I believe most European countries have their own solutions
         | similar to this. e.g. in Denmark we have NemID/MitID as _the_
         | way to digitally authenticate yourself to the healthcare
         | system, your bank, etc.
         | 
         | If I understand correctly, this EU initiative would unify all
         | these separate country-level identification tools into
         | something that works EU-wide, so I can take my Danish digital
         | ID and e.g. use it in a bank in the Netherlands.
        
         | Heliosmaster wrote:
         | Each country has their own system. in NL we had DigID, and
         | apparently now iDin (first time i hear about it). In Italy we
         | have SPID who uses a bunch of external providers (phone
         | companies, italian posts, internet providers, ...). The whole
         | idea is to create an interoperable standard.
        
         | einarfd wrote:
         | The article does point out that several countries have these
         | kind of systems but they are not cross border. Solving that is
         | supposed to be part of this initiative. Being able too use a
         | swedish issued id to authenticate in the Netherland would imo
         | be a nice and a big step forward.
        
           | Avamander wrote:
           | > Being able too use a swedish issued id to authenticate in
           | the Netherland would imo be a nice and a big step forward.
           | 
           | That's unfortunately caused by the proprietary solutions
           | chosen, BankID and similar. If Sweden and Netherlands had
           | gone with very widely supported Smart Cards (like Finland,
           | Estonia and Latvia), they would interoperate trivially.
           | Especially with the advent of eIDAS.
           | 
           | Hopefully this legislation forces proprietary implementations
           | to become more open.
        
       | stncls wrote:
       | If you want a horrifying overview of this technology in 3
       | minutes, see this video advertisement by the makers themselves:
       | 
       | https://m.youtube.com/watch?v=PxvNzzgoJX8
       | 
       | For context, the French company Thales Group is "the 8th largest
       | defence contractor in the world with 55% of its total sales being
       | military sales".
       | 
       | https://en.m.wikipedia.org/wiki/Thales_Group
       | 
       | They are proudly proposing that we outsource government functions
       | to them, promoting the _proprietary_ tech they will use to that
       | end.
        
         | francis-io wrote:
         | "...reminding Lucy of her mandatory vaccination" is very
         | chilling.
        
           | Dig1t wrote:
           | Right out of dystopian sci-fi.
        
           | ellopoppit wrote:
           | "#Vaccinepassports are a precursor to Digital ID wallets,
           | offering citizens unparalleled convenience and #security."
           | 
           | https://mobile.twitter.com/ThalesDigiSec/status/142535144657.
           | ..
        
         | baal80spam wrote:
         | > https://m.youtube.com/watch?v=PxvNzzgoJX8
         | 
         | And _of course_ comments are turned off for the Digital ID
         | Wallet movie. No visible dislikes and no negative comments =
         | everyone is happy!
        
         | marcosdumay wrote:
         | Good thing that Lucy lost her passport and not her phone.
        
           | moffkalast wrote:
           | Lucy has lost her phone. Unfortunately she is now not only
           | locked out of her social life, but her job, her bank, and
           | also her identity. How convenient.
        
             | 0xfaded wrote:
             | Don't worry, the government knows where her phone is.
        
         | edmcnulty101 wrote:
         | They just casually threw mandatory vaccines out like it was
         | nbd.
         | 
         | What other mandatory things will I need to do for the
         | government?
         | 
         | Mandatory registration for war! Mandatory birth control!
         | Mandatory drug test! Mandatory lie detector test about how
         | honest you were on your taxes!
         | 
         | How easy it makes it to participate in society...
         | 
         | is a double edged sword...
         | 
         | with how easy it is to shut them out of society with a flip of
         | the switch if they don't comply.
        
         | TacticalCoder wrote:
         | > They are proudly proposing that we outsource government
         | functions to them, promoting the proprietary tech they will use
         | to that end.
         | 
         | Thales is one those supposedly private companies that is
         | actually owned by the french state and french state
         | apparatchiks. The biggest shareholder is the french state
         | itself (26%), then other companies which, surprise, are also
         | partially french state owned. It's all Dassault, Airbus, EADS
         | etc.: they're all basically partially french state owned and
         | own shares of each other. It's the military-industrial complex,
         | french style.
         | 
         | I mean: it's basically the government proposing we outsource
         | government functions to the government.
         | 
         | All that while pretending that Thales is a private company.
        
           | _Algernon_ wrote:
           | >EU digital ID wallet
           | 
           | How is it better that a foreign government has control of my
           | id? Most of the EU isn't France.
        
         | cinntaile wrote:
         | Thales makes passports too, so there is a big chance that your
         | passport was made by them.
         | 
         | A more universal digital ID is a welcome change, now certain
         | services are limited to people living in a certain country
         | because there is no support for foreign digital IDs.
        
           | dane-pgp wrote:
           | > A more universal digital ID
           | 
           | Would you support a global digital ID, based on standards
           | from the UN? It could even be used to store your vaccine
           | data:
           | 
           | https://www.telekom.com/en/media/media-
           | information/archive/c...
        
             | freeone3000 wrote:
             | Yes, this sounds awesome. Way better than having to re-
             | prove myself to every country I enter.
        
               | poo_clown wrote:
               | Distributed consensus of personhood updated in realtime
               | is the wave of the future! Keep those nasty germs at bay.
        
       | durnygbur wrote:
       | Massive oven for a cash solving a problem which doesn't exist.
       | Bureaucrats will hire each other then produce gigabytes of PDFs
       | and half-baked MVP. After the covid masquerade ball, where
       | remotely switched "certificate" determined one's basic civil
       | right (freedom to travel), I'm not installing any app from
       | authorities.
        
         | checkurprivlege wrote:
         | It's a problem when thousands of bureaucrats want to "do a
         | career" spending budgets on things absolutely nobody asked for.
         | 
         | I want society to experiment with firing all these bureaucrats.
         | Then listen carefully at the silence. Are we missing anybody?
        
       | sreeramb93 wrote:
       | Reminds of me Aadhaar in India.
        
       | this_is_not_you wrote:
       | Sounds like the BankID system they have in Norway and Denmark
       | (maybe also Sweden?).
        
         | tmikaeld wrote:
         | Yes, it's also standard in Sweden (BankID is a private entity
         | though, not government controlled), so the swedish state want
         | to create their own [0].
         | 
         | [0] https://feber.se/samhalle/regeringen-vill-ha-en-statlig-e-
         | le...
        
         | yaris wrote:
         | Sweden also, yes. Although it is not similar. As I understand
         | the way BankID works - it is responsibility of the bank that
         | issued your BankID (or another company, as there are a few non-
         | bank companies where one can get "Bank"ID) to identify you
         | physically (using a passport, national ID, driving license
         | etc). The government (in Sweden at least) is not (visibly)
         | involved in the process.
        
           | this_is_not_you wrote:
           | I am not sure what you mean by "to identify you physically".
           | 
           | The way it works in Norway is that, once you have a bank
           | account (which means you had to identify yourself using
           | passport or similar) you can get a BankID which allows you to
           | log in to a lot of online services (health, tax, employment,
           | etc) without having to do anything else.
        
       | mdp2021 wrote:
       | > _It proposed to give every EU citizen a set of strong digital
       | identity credentials that will be recognised anywhere in the
       | zone. These credentials will be accessible from a digital wallets
       | and available to anyone from their mobile device_
       | 
       | Is this thing mandating a mobile device as a document?
        
         | onion2k wrote:
         | The digital wallet could be something like an Yubikey that
         | holds the data and decryption software. The stipulation that it
         | should be available to everyone is that it needs to be readable
         | from a mobile phone (eg NFC). The phone would issue a request
         | for access to some policy, and the device would read the data
         | and issue a true/false response (or more if necessary.)
         | 
         | The wallet holder would have control over what their wallet
         | gives the reader access to.
         | 
         | I imagine a mobile app would be cheaper and simpler though.
        
         | sofixa wrote:
         | The current iteration allows for digital certificates (stored
         | on a USB), so there probably will be a fallback for those
         | without smartphones.
        
           | Avamander wrote:
           | A software-only solution where private keys have the
           | potential of leaving the device, be it an app or an USB-
           | stick, is not really okay in this day and age.
           | 
           | So a proper fallback wouldn't be an USB-stick with some
           | certificates laying around, you can instead just build the ID
           | functionality using SIM-card applets. The keys are securely
           | stored in hardware and you can use them on both smart and
           | feature phones.
        
       | terefooobar wrote:
       | Fully digital is bad, what if I lose my phone or my certs get
       | somehow stolen. In Estonia we have a physical ID card with certs
       | on it and I like that much better.
        
         | mdp2021 wrote:
         | I am not seeing information that this "Digital ID wallet"
         | excludes alternatives. Did you?
        
       | einarfd wrote:
       | I live in one of the countries that have a local variant of this
       | already (BankId in Norway). What it is used for here are services
       | where either you are able to identify and authenticate yourself
       | or if not, there is just now way they can be provided. These kind
       | of services are things like banking, taxation, ownership
       | transfers, health care, and similar.
       | 
       | I'm hard pressed to view allowing people access to these kind of
       | services over the internet as something dystopian.
        
       | nix23 wrote:
       | Excellent, and Europol is the next and worse NSA.
        
       | mihaic wrote:
       | In theory, I think that something like this is way past its due
       | date in many applications on the internet.
       | 
       | In practice, does anyone know how these expert groups are formed
       | and how they operate? The execution feels like the same terrible
       | EU-driven "plan it in excruciatingly useless detail to have
       | everything in the first implementation, and only then realize it
       | sucks".
        
       | dementik wrote:
       | I think this does not look totally bad. I have lots of good
       | experiences on similar digital ID from Estonia. That just works.
       | Banks etc rely there on government-backed authentication.
       | 
       | In Finland its totally opposite. We have 10 or so banks, which
       | all have their own authentication methods and government has
       | outsourced authentication to banks. And every authentication
       | costs 0,10EUR (it was previously much higher amount, something
       | like 0,70EUR but it is now [since 2017] limited by law).
       | 
       | So, I think at least in Finland banks will be the ones who will
       | come up with several reasons why they should not implement this
       | new authentication method.
        
         | proc0 wrote:
         | > competition is what drives societies to become more complex,
         | building more hierarchical armies to fight ever-more-complex
         | wars and organizing increasingly bureaucratic governments to
         | manage diverse resources and growing populations.
         | 
         | This sounds interesting. Having identification be a cost would
         | make people think before engaging with anything that requires
         | it, which would encourage companies to avoid. Also, if people
         | can choose freely which banks to use, then there is also some
         | market pressure on banks to have good privacy and security.
        
         | verisimi wrote:
         | > I think this does not look totally bad.
         | 
         | Phew! But it's not something you wanted, right? This is not
         | something that helps.
         | 
         | It is something that helps those doing the governing though.
         | Tracking you. Why is it planned that we all have these sorts of
         | id/wallet/health pass/etc?
         | 
         | Is it possible that it will be used as in China, with good
         | citizens (uncritical of the government) allowed access to
         | travel, borrowing, schools, etc nevermind the loss of privacy
         | as each purchase, movement is tracked?
         | 
         | To me its plainly about control. Control like we cannot even
         | conceive of. Even if the government is not rule by the worst
         | (and the EU is not a democracy - there's no options to get
         | people out) the change in society will change us. If we know we
         | are always under close scrutiny, you will change your
         | behaviour.
         | 
         | After all we have seen, I hope we are in agreement that this
         | sort of gadget should be roundly refused.
        
           | dementik wrote:
           | > But it's not something you wanted, right?
           | 
           | I am actually not sure if I wanted this. I think this is
           | better than current (specifically comparing to Finnish)
           | state, but still far from optimal (mainly based on privacy
           | concerns).
           | 
           | > Is it possible that [..] is tracked?
           | 
           | Yes. But I have The Great Belief that EU is _still_ one of
           | the Goods. That may or may not last.
           | 
           | Still, it is very easy to exaggregate this (slippery slope)
           | and at the same time it is too easy to understate this.
           | Probably we - as citizens - should raise loudly these
           | concerns and if we are not heard - then roundly refuse.
        
             | verisimi wrote:
             | > Yes. But I have The Great Belief that EU is _still_ one
             | of the Goods. That may or may not last.
             | 
             | Still eh? What happens when that belief has waned? The
             | infrastructure will still be there.
        
               | dementik wrote:
               | > What happens when that belief has waned?
               | 
               | Hard to predict but usually (lost) belief transforms to
               | feelings/actions like resistance. And probably on that
               | point there will be also others who will do the same.
        
               | verisimi wrote:
               | How would you resist, when your energy, travel, money,
               | internet, etc, is micromanaged by your government?
        
               | dementik wrote:
               | The same way I am resisting (in-efficiently) things now
               | in democracy: by voting and trying to raise my concerns
               | on public forums.
               | 
               | Yes, government could do things which prevent me doing
               | so. Still, I am not capable to manage everything by
               | myself and at the same time I think it is better to let
               | things to be managed by (good) government than
               | corporations.
        
       | proc0 wrote:
       | There's something inherently unsettling about government having
       | so much control over people. I know EU is different but history
       | proves EU is more vulnerable to having dictators. It's
       | interesting how people don't see the danger here, and I can
       | almost see history repeating itself, except on a different scale.
       | 
       | Where is this all going? I hope I'm wrong and it means some kind
       | of utopia where people only enjoy the benefits of an all-knowing,
       | all-seeing entity that has full control over your life, with none
       | of the downsides. To me that seems highly unlikely, at least not
       | without some heavy price paid along the way.
        
         | barrysteve wrote:
         | If there's a great depression again in the 2030s, like there
         | was last time, then the command economy that's established in
         | the 2040s will use this and any tech like this to reduce
         | unemployment by "force".
         | 
         | The world of Ayn Rand's Fountainhead is looking more and more
         | likely. Where every single thing is revealed and the heroic act
         | is simply to do something different to the slaving public.
         | 
         | This system doesn't treat people like an end in themselves, it
         | treats them like they are a means for everyone else to use
         | them.
        
         | jdasdf wrote:
         | > I know EU is different
         | 
         | How do you know that?
        
           | proc0 wrote:
           | From reading other comments and also I'm just stating the
           | obvious. There are different systems of government, which
           | work differently and is something people must be accustomed
           | to.
        
         | viktorcode wrote:
         | All the papers that can be replaced with this digital ID were
         | issued by the state.
        
           | _Algernon_ wrote:
           | And those papers dont include a gps and internet connection
           | that can silently ping your location to the government every
           | second.
        
         | kybernetyk wrote:
         | While such things can look benign under a democratic and
         | liberal governmentthis all changes when some "bad guy" comes to
         | power. My personal litmus test for things like these is: What
         | if someone like Stalin/Hitler would have had this. And suddenly
         | rounding up a group of people becomes nothing more than a SQL
         | query.
        
         | Ajef wrote:
         | What power does the EU/its governments gain here? Aren't they
         | already the only identity provider (passports, ID cards,
         | drivers license)?
        
           | stingraycharles wrote:
           | And perhaps more importantly, they all have their own
           | versions of digital IDs as well, all with their own quirks
           | and potential vulnerabilities.
        
           | cft wrote:
           | Historically money was not controlled by any government
           | (gold). Gold lasted for tens of thousands of years: private
           | transactions with money whose value was beyond a single
           | government control.
           | 
           | Now we are talking about a single non-elected EU government
           | controlling every transaction, not just the issuance of fiat
           | money.
           | 
           | I personally think that with time this will implode, because
           | the society always evolves towards more freedom, towards less
           | centralization. There are multiple steps now in the reverse
           | direction. However the discrepancy between the views of the
           | government, the ruling classes and the reality is becoming so
           | big that without a grand catastrophe (a global war, a
           | revolution, etc) the inevitable correction seems less and
           | less possible.
        
           | proc0 wrote:
           | The article mentions how this would allow all kinds of new
           | services:
           | 
           | >Our European companies, large and small, will also benefit
           | from this digital identity. They will be able to offer a wide
           | range of new services since the proposal offers a solution
           | for secure and trusted identification services.
           | 
           | It mentions things like going to nightclubs, and I assume it
           | will include many more things that would otherwise not
           | require a mobile app. Because this all now goes through
           | government controlled servers, it follows they will have
           | knowledge of all these new services, and all this new
           | activity on every single citizen. In practice, this means
           | government will know much more because this is now a
           | widespread, mandatory form of ID.
           | 
           | The question for me is, why does government need all of this
           | information, as oppose to how can government intervene and
           | make ID verification more convenient. The scale of this is
           | unprecedented as well, from the amount of people doing it to
           | the granularity of where and how it's going to be used.
        
             | ko27 wrote:
             | Your own example proves how digital ID can be more private
             | and secure. You go to a nightclub, you look a bit younger,
             | person on the entrance asks proof of your age:
             | 
             | Option 1 - You give him your ID card and you expose a
             | wealth of data, including your full name, address and
             | SSN/OIB to that person
             | 
             | Option 2 - He scans your phone app, gets a big green mark
             | which proves your exact age, or even just that you are 18+
             | and nothing more
        
               | lobocinza wrote:
               | Option 2 has all the problems from Option 1 multiplied.
               | 
               | Bouncer can ask for more information and you can't even
               | lie about it. Asking for phone number and address is
               | somewhat reasonable in our current dystopic present on
               | the basis of KYC and "what if there's an emergency". And
               | you can be sure that the data will be stored in local DB
               | with poor oversight and security and it will be used for
               | marketing and eventually leaked.
        
               | proc0 wrote:
               | I think "private and secure" mean two different things
               | here. It may be private and secure from malicious actors
               | trying to steal your ID, but it's probably not private or
               | secure when government decides it needs to coerce you
               | into doing something you don't want to do.
               | 
               | Option 2 is more convenient, but at what cost? I would
               | think the probabilities of the cost being high is
               | proportional to the probability that government will have
               | corruption and abuse the system, which seems high in
               | history and even today in many countries.
        
               | bboygravity wrote:
               | Option 1: one guy gets to see all of your ID data, but
               | most likely won't keep a record of it and will forget all
               | he saw within 10 seconds.
               | 
               | Option 2: the same guy has no idea who you are. Instead:
               | your ID gets scanned, the scan hits a government server
               | for verification. A record is now kept forever of where
               | you went, when and with whom and this information is
               | added to create a profile of you (and your
               | friends/partners). They can know if you were cheating on
               | your partner, whether you where dating, if you went out
               | "with the boys" that night, what political flavor the
               | people you party with prefer, and so on and so forth.
               | 100's of people and algorithms can access these records
               | in the future _in secret_ , including: the NSA (even if
               | you're European, all secret service data is shared with
               | the NSA), local secret services, the police if they want
               | access, the tax-man, any future dictator(s) that rises up
               | and his subordinates, same for others in other countries
               | that are friendly to him, anybody in politics interested
               | in you for whatever reason that may develop in the future
               | when data access rules get weaker (or remain unpoliced),
               | and so on and so forth. Furthermore, if for whatever
               | reason your political preference becomes unwanted in the
               | future, you can fully automatically be banned from public
               | life at the press of a button with 100% efficiency (this
               | already happens in countries such as China as we speak,
               | Canada CAN'T WAIT to have such a system as well).
               | 
               | I pick option 1.
               | 
               | It blows my mind that people don't see where this is
               | going after Snowden.
        
               | moffkalast wrote:
               | Not to mention the fact that they will find a lame excuse
               | to roll this into the credit score system sooner or
               | later, so they can know if you are a "responsible"
               | citizen or something.
               | 
               | And also that government employees are incompenent so
               | they'll send the entire thing through wetransfer or
               | something and it'll be leaked sooner or later.
        
               | gumby wrote:
               | Increasingly, in the US, bars and stores swipe your DL to
               | validate your age. This is in the name of making sure the
               | id was checked and not requiring the bouncer/clerk to
               | recognize all sorts of state IDs.
               | 
               | Really, all the info goes to the establishment and/or the
               | company providing the reader.
               | 
               | The old fashioned "bouncer will forget all the info"
               | doesn't apply any more.
        
               | switch007 wrote:
               | I've never had my id "swiped" in Europe. I'm sorry but
               | your US experience has no relevance to the topic.
        
               | ellopoppit wrote:
               | I'm in the US and have never had my ID scanned like that
               | person is claiming
        
               | toofy wrote:
               | we've had it here in the us for long time.
               | 
               | privacy forums were recommending people run magnets over
               | the stripes on id's at least 10 years ago when companies
               | started swiping them.
               | 
               | is the new digital id terrifying? probably. but honestly
               | from a privacy perspective, the way companies and
               | government working together suck up all of our digital
               | movements is terrifying if privacy matters at all to us.
               | 
               | to me, this was an obvious next step considering the
               | world we've decided to build. we're doing this.
               | government employees. corporation employees.
               | 
               | we're allowing power to consolidate at a rapid pace. we
               | can't decimate the separation of governments and
               | companies, then build company after company after company
               | which heavily rely on human data for their profits, and
               | then simultaneously be shocked when this happens.
               | 
               | either we have privacy from both governments and
               | companies or we don't. particularly in a world where we
               | refuse to hold power to any sort of reasonable standards
               | (and by "power" i mean governments, corporations, wealthy
               | individuals, individuals with power backing them,
               | organizations, etc...)
               | 
               | i guess my ramble really boils down to this: many of us
               | on this exact forum are building the tools. many of us on
               | this forum are directly enabling power _of all kinds_ to
               | consolidate. it isn't clear to me how we can complain
               | about it too.
        
               | roblabla wrote:
               | > your ID gets scanned, the scan hits a government server
               | for verification.
               | 
               | I mean, you're already assuming things work a certain way
               | that is not necessarily true. The ID card could just have
               | all the information stored and signed by the govt. Then a
               | scanner would only have to check that the signature is
               | valid, no need to actually ping the govt server.
               | 
               | I haven't checked the technical details, so I've got no
               | clue. But this is how the EU COVID-19 vaccine
               | verification works IIRC. No pinging of a central server
               | is ever done - the mobile app just checks that the
               | message in the QR code is properly signed with the
               | expected root of trust.
        
               | dane-pgp wrote:
               | > No pinging of a central server is ever done
               | 
               | Until the next time there is a terrorist attack or other
               | scary event, and the opportunistic politicians say "We
               | could have stopped this if only we had been keeping these
               | pings in a database, just like we keep logs of everyone's
               | internet metadata[0]. Don't worry, the database would
               | only be looked at by AI, so it's not even a breach of
               | your privacy."
               | 
               | Then everyone is just a single firmware update away from
               | a completely different regime, and it's too late to
               | boycott the app because everyone assumes you have it and
               | requires you to run the latest version. Of course, you
               | could always try protesting, but you might not get very
               | far.[1]
               | 
               | [0] https://aboutintel.eu/european-metadata-retention/
               | 
               | [1] https://www.reuters.com/world/china/china-bank-
               | protest-stopp...
        
               | tokinonagare wrote:
               | > It blows my mind that people don't see where this is
               | going after Snowden.
               | 
               | The majority may actually approves it, instead of turning
               | a blind eye. During the covid crisis, how much of the
               | population was ok with the government (taking France as
               | example here) excluding from social life, and in some
               | case professional life, 10% of people, on the ground of
               | them not pumping Pfizer et al. stock price? I bet on
               | something like 70%. Those people think because there are
               | in the "winner" side they'll always stay there, and don't
               | realize how fast the wind turns, and the same method will
               | apply to them soon for whatever reason.
        
               | kettleballroll wrote:
               | The question here is whether option 2 is implemented on
               | the edge device (which in turn makes it more likely that
               | someone can steal your identity) or goes over a
               | government owned server (which means the government could
               | soy on you)
        
           | _Algernon_ wrote:
           | The ID is now also a gps tracker that can send its location
           | everywhere you go.
        
         | stncls wrote:
         | > There's something inherently unsettling about government
         | having so much control over people.
         | 
         | The article is way worse than that. It's about _outsourcing_
         | government surveillance to military hardware maker Thales, who
         | is proudly explaining how they 'll do it using their exclusive
         | proprietary technology.
        
           | stingraycharles wrote:
           | Isn't outsourcing incredibly common for this type of thing?
           | Not saying I am particularly fond of Thales (I'm not), but I
           | have extremely low expectations of an EU in-house software
           | development team. All things considered, I'd expect a
           | military contractor to be proficient at security as well.
           | 
           | If your concern is the lack of transparency, then I agree.
           | This needs to be open technology.
        
             | stncls wrote:
             | > If your concern is the lack of transparency, then I
             | agree. This needs to be open technology.
             | 
             | Yes, exactly. My understanding is that openness is not
             | really in Thales' culture.
             | 
             | > I have extremely low expectations of an EU in-house
             | 
             | I agree that modern ergonomics and convenience are not
             | usually the strengths of in-house gov IT in the EU. But
             | sometimes the basics got done right. I'm thinking of some
             | of the smaller countries' digital/electronic IDs. Also,
             | setting aside all ethical questions, the technical side of
             | EU Covid passes was ok, as far as I understood.
        
       | gorbypark wrote:
       | I recently moved to Spain and managed to get a digital identity
       | certificate. It seems to be a fairly open implementation, but has
       | a few weird things. It's just an x509 certificate (in p12 format)
       | that you install into the OS certificate manager and then it is
       | used on various governmental websites to authenticate
       | yourself/sign documents.
       | 
       | First weird thing is that there's no method to recover the key if
       | it's lost, besides starting from the beginning and going through
       | the physical identity verification process again.
       | 
       | The other thing I noticed is that the "configurator" macOS app
       | isn't a sandboxed/signed app. They even have instructions on how
       | to enable opening app from untrusted sources on their website. I
       | feel they should bite the bullet and get a $100/yr developer
       | account. AFAIK, all the app does is generate the certificate,
       | transmits it to a server (to be signed by the CA after your
       | verification happens) and generates a PIN you need to show when
       | you are showing your physical ID. Once you are verified you enter
       | another code that was emailed to you and it spits out your pk12
       | file.
       | 
       | Anyways, it's come in handy so I think an EU wide standardized
       | version could be helpful in day to day life.
        
         | Avamander wrote:
         | Sounds really half-assed not to make it hardware-backed. With
         | that implementation, malware can relatively trivially steal
         | your certificate.
        
       | dalke wrote:
       | I don't believe a word. The three scenarios used to promote the
       | benefits have some big stumbling blocks that can't be solved with
       | simple credential storage.
       | 
       | > With the EU Digital ID wallet, the bank can request the
       | necessary credentials from the applicant. He or she selects them,
       | and in seconds they are verified by the bank. The process even
       | includes an eSignature that signals the applicant's agreement.
       | 
       | This seems a bit off.
       | 
       | As a US citizen living in Sweden, my bank also wants to know if a
       | customer is a US citizen, because special regulations apply.
       | 
       | For the above scenario to work, the EU Digital ID wallet will
       | have to store citizenship information, including potentially
       | multiple citizenships.
       | 
       | Sweden recognizes the State of Palestine. Will the EU Digital ID
       | wallet allow storing that information?
       | 
       | > The student can use her EU Digital ID wallet to access, for
       | example, the diploma she gained in one country and have it
       | accepted instantly in any other EU country.
       | 
       | That's ... also odd. That's not how it works now. A diploma in
       | one country doesn't necessarily translate to something directly
       | in another country. Quoting
       | https://www.uhr.se/globalassets/_uhr.se/bedomning/informatio...
       | "A recognition statement is a document that shows what your
       | qualification corresponds to in the Swedish education system. To
       | prepare the statement, we review your education documents."
       | 
       | An app storing credentials isn't enough.
       | 
       | > With the EU Digital ID wallet, the person can provide trusted
       | proof of age and nothing more.
       | 
       | Bars and nightclubs also gather names to help spot people who
       | have been banned, and will also share a list of banned people
       | with other bars. They also gather this information to spot VIP
       | customers.
       | 
       | They are't going to want to give it up.
       | 
       | In practice it will be like a a go-away-cookie-banner button. The
       | bar's system will ask for more information, people will press the
       | "confirm" button w/o reading, and the bar will still get
       | demographic information. Those few who do read and say "no" will
       | not be allowed entry.
       | 
       | If preventing this sort of information leak is important, then
       | make it illegal to collect more information than is needed to
       | verify age, or restrict what can be done with that information.
       | 
       | > Billions of people regularly use mobile apps, so the process
       | will be familiar to the vast majority of citizens and businesses.
       | 
       | An odd statement. The population of the EU is less than 1
       | billion, so this refers to the world-wide population. But world-
       | wide, billions of people _don 't_ regularly use mobile apps.
       | 
       | A better statement would be the number of people in the EU who
       | regularly use mobile phones.
       | https://newzoo.com/insights/rankings/top-countries-by-smartp...
       | says for Italy that's about 75% penetration.
       | 
       | I assume that more direct comparison wasn't used to avoid talking
       | about what to do for the people in the EU who don't have or don't
       | want smartphones.
        
       | an9n wrote:
       | What could go wrong?
        
       | [deleted]
        
       | throw7 wrote:
       | "THALES - building a future we can all trust"
       | 
       | Well, that's ominous.
        
       | tomjen3 wrote:
       | And I bet it won't work as an ID in Apple Watch. However it will
       | probably make some company a boatload of money to develop.
       | 
       | Meanwhile there is an entire standard of government certificates
       | or FIDO that is made for this use case.
        
         | Avamander wrote:
         | FIDO and relatives are really not designed for such one-to-one
         | identity use-cases, it was intentionally designed in a way to
         | limit cross-provider tracking. National ID's are the exact
         | opposite.
        
       | Markoff wrote:
        
       | diebeforei485 wrote:
       | People should have this option.
        
       | [deleted]
        
       | qwerty456127 wrote:
       | > Proving your identity matters
       | 
       | In many cases when it is meant to, it should not.
       | 
       | > whether you are a citizen opening a bank account, renting a
       | flat or a business registering a new service.
       | 
       | I never had to prove my identity to rent a flat in the EU. Good
       | people trust each other.
       | 
       | Why is it considered OK to take a bus or eat at a restaurant
       | anonymously but renting an apartment or paying humble sums of
       | money is not?
       | 
       | > How do you even know they are human?
       | 
       | You never know anymore. Give this up. Just keep in mind it may be
       | a bot.
        
         | Keirmot wrote:
         | > I never had to prove my identity to rent a flat in the EU.
         | Good people trust each other.
         | 
         | For how long was this rent, and WHERE? Every time I rented for
         | living spaces, the contract had to signed, marked on every
         | sheet that had text, and taken to a notary to be considered
         | valid. This is because all the info is then used to calculate
         | taxes at the end of the year.
        
           | qwerty456127 wrote:
           | For years. In some places I didn't even had to sign a
           | contract, in other places I would sign it but nobody ever
           | checked my ID. Apparently nobody really cares much as long as
           | you look and sound nice and pay them a deposit. They would
           | only ask for the ID in hotels (which I'd vote to abolish as
           | well).
        
       | judge2020 wrote:
       | I just want to comment that this was a very strategic HN post.
       | 3AM EDT/12AM PDT for the US, so pretty much all comments are from
       | EU-located posters.
        
         | sixhobbits wrote:
         | Or people in the EU tend to submit stories about the EU when
         | the EU is awake... I love how US centric the internet is
         | sometimes that an American staying up late to suubmit an
         | article about the EU is somehow more top of mind than, you
         | know, an actual EU person.
        
       | Aaronstotle wrote:
       | I hope there is a lot of pushback, this will undoubtedly be
       | accompanied by some type of social credit system. I don't think
       | it will be as extreme as the one in China, but worrying
       | nonetheless.
       | 
       | On the other hand, it would be nice if states in the U.S. offered
       | some type of digital equivalent, been in situations where I don't
       | have my physical ID and the counter-party refuses to accept a
       | picture as proof.
        
       | rockbruno wrote:
       | This is great (I'm from Sweden which already has this), but you
       | need to be careful as this also makes it really easy for you to
       | fall into scams. I'm at this moment fighting a company who
       | required me to login with BankID when using their website's
       | contact form, and as soon as I was done with my inquiry they
       | tried to blackmail me by saying "nope, when you logged with
       | BankID, you technically signed (extremely unfair contract that
       | says I need to pay them obscene amounts of money for simply
       | reaching out to them) and we will sue you if you don't pay"
       | 
       | Fortunately I'm fine in this case as the law states that you
       | cannot be tricked into signing a contract that was never
       | presented to you, but I think most people don't make the
       | connection that your BankID logins are considered legit
       | signatures by law and that you can be held accountable for what
       | you use it for.
        
         | tmikaeld wrote:
         | While BankID is nice, it's owned and operated by a private
         | entity and not controlled by the government, which the
         | government want to change [0].
         | 
         | [0] https://feber.se/samhalle/regeringen-vill-ha-en-statlig-e-
         | le...
        
           | dijit wrote:
           | ^ this
           | 
           | It's a fantastic system, especially when I compare how it
           | used to work when I lived in the UK with how it works in
           | Sweden: it feels like the UK is 50 years in the past.
           | 
           | It should be government owned, definitely, but Sweden has a
           | very poor history of securing it's IT systems in government.
           | Like.. very poor.
           | 
           | So, maybe I'm not 100% on-board. There needs to be oversight
           | for sure.
           | 
           | https://www.holmsecurity.com/resources/the-1177-leak
           | 
           | https://www.bitdefender.com/blog/hotforsecurity/sweden-
           | leaks...
        
       | scoutt wrote:
       | > In short, companies will have much more control of the data
       | they wish to share.
       | 
       | What does that even mean? Even in that context.
       | 
       | > Most users will access the EU Digital ID wallet in the form of
       | a smartphone app.
       | 
       | Why the EU thinks, presumes or pretends I have a smartphone? If
       | they want me to use a smartphone and obligate me to purchase one,
       | then they should also provide a free or super cheap alternative
       | phone + line contract.
       | 
       | Every time I read something like this it urges me to put together
       | some ESP32 plus a Modem, write an email and chat client, and
       | throw away my current phone. When they'll ask me about my phone,
       | I would pull out some ugly 3d printed case.
       | 
       | > A key aim of any EU wallet is therefore to give EU-based
       | businesses a strong, secure and powerful tool for authentication.
       | 
       | And all this should be safe until someone steals Thales
       | encryption keys, as already happened in the past (Thales was
       | formerly known as Gemalto).
        
         | Barrin92 wrote:
         | >Why the EU thinks, presumes or pretends I have a smartphone?
         | 
         | They don't. As the site says any traditional form of ID still
         | works. This isn't mandatory.
        
         | xxs wrote:
         | Actually I'd hope the standard plastic ID cards would work just
         | fine via a usb card reader.
        
       | gobengo wrote:
       | lets go web5
       | 
       | If you wanna study this stuff, participate in
       | 
       | * https://w3c-ccg.github.io/
       | 
       | * https://trustoverip.org/
       | 
       | * https://identity.foundation/
        
       | iasay wrote:
       | What happens if I don't want to identify myself?
       | 
       | What happens if poverty does not allow me to carry a digital ID?
       | 
       | What happens if I lose my digital ID wallet or it is compromised?
       | 
       | Also judging by dealing with the average citizen on a daily
       | basis, even securing an iOS device and remembering the iCloud
       | password is beyond their level of care.
        
         | kabes wrote:
         | > What happens if I don't want to identify myself?
         | 
         | The same thing as what happens in the offline world when you
         | try to open a bank account or board a plane without ID: You're
         | refused. Like it or not, for some services you need to identify
         | yourself.
         | 
         | > What happens if poverty does not allow me to carry a digital
         | ID?
         | 
         | While this is an issue, the issue is with a service being
         | available only online. That issue already exists. Most
         | governmental stuff is obligated by law to be available offline
         | as well, but for private companies its more difficult. E.g. If
         | I want to open a bank account and I don't have a phone or
         | computer, some banks already make it hard to do it in person.
         | 
         | > What happens if I lose my digital ID wallet or it is
         | compromised?
         | 
         | The same thing as what happens in the offline world. Procedure
         | depends on where you live. Here you have to file a record to
         | the local police and you get a new ID card a couple of days
         | later. Now it can probably actually be blocked and you get a
         | new id immediately.
         | 
         | > Also judging by dealing with the average citizen on a daily
         | basis, even securing an iOS device and remembering the iCloud
         | password is beyond their level of care.
         | 
         | It's up to the government to educate people and make a
         | foolproof system. That's easier said than done but a lot of
         | countries already have digital ID systems and it's worked well
         | for almost 2 decades now.
        
           | mdp2021 wrote:
           | > _some banks already make it hard to do it in person_
           | 
           | It is called a good market that you avoid them.
        
         | d8c6c050cb0a4d7 wrote:
         | > What happens if I don't want to identify myself?
         | 
         | It is already an offence in several EU countries to fail to
         | present official ID documents when asked by the police.
         | 
         | If you don't want to identity yourself the outcome will likely
         | depend on the mood of the police office. They may give you a
         | verbal warning and send you on your way or they may choose to
         | arrest you until they can ascertain your identity.
        
           | [deleted]
        
           | iasay wrote:
           | Yes the police for sure, but this is normalising full ID
           | verification everywhere.
           | 
           | At some point there will be a situation where you cannot do
           | anything because you are in the 0.01% of the system that is
           | broken.
        
             | d8c6c050cb0a4d7 wrote:
             | That's already the case. Since you must be able to identify
             | yourself when asked, you have an obligation to carry your
             | identification with you.
             | 
             | I believe the obligation to carry identification, and to
             | have identification are enforced differently in different
             | countries / states. But there is more information here:
             | 
             | https://en.wikipedia.org/wiki/Obligation_of_identification
             | 
             | https://en.wikipedia.org/wiki/National_identity_cards_in_th
             | e...
             | 
             | > At some point there will be a situation where you cannot
             | do anything because you are in the 0.01% of the system that
             | is broken.
             | 
             | Not wanting to identify yourself and not being able to
             | identify yourself are two seperate topics. I sympathise
             | with people who fall outside of the system, but e-identity
             | is currently a matter of convenience for people who already
             | have identity documents and are seeking easier ways of
             | accessing services online.
        
             | xxs wrote:
             | >Yes the police for sure, but this is normalising full ID
             | verification everywhere.
             | 
             | The UK is not a part of the EU any longer, for pretty much
             | all of the rest member states, that has not been an issue
             | for quite some time... save for Ireland.
             | 
             | >At some point there will be a situation where you cannot
             | do anything because you are in the 0.01% of the system that
             | is broken.
             | 
             | The issued ID plastic cards would be as useful when you are
             | present in person.
        
         | misja111 wrote:
         | Replace 'digital ID' with 'passport' in any of your questions
         | and you will find the answer.
         | 
         | > Also judging by dealing with the average citizen on a daily
         | basis, even securing an iOS device and remembering the iCloud
         | password is beyond their level of care.
         | 
         | The EU digital ID is based on EIDAS, a technology that is
         | already in use by banks in the entire EU. You can be sure it is
         | safe, otherwise any bank in the EU would have been hacked
         | already.
        
           | wfn wrote:
           | Just to clarify, eIDAS is an EU regulation
           | (https://en.wikipedia.org/wiki/EIDAS). Regulation means it's
           | law in all EU member states.
           | 
           | Organisations can implement eIDAS-conforming technology to
           | provide eID services if they get certified; e.g. our company
           | provides such services (remote onboarding without video
           | conference need + qualified electronic signature signing):
           | https://www.zealid.com/en/
        
         | moffkalast wrote:
         | > What happens if I don't want to identify myself?
         | 
         | You get arrested until the police can figure out who you are,
         | at least that's how it works presently in most of the EU.
        
         | yourusername wrote:
         | >What happens if I don't want to identify myself?
         | 
         | That's already illegal in many countries. You'll be fined and
         | possibly arrested until you can prove who you are.
        
           | iasay wrote:
           | When you book a hotel you will be fined and arrested until
           | you can prove who you are? That's the use case being
           | promoted.
        
             | sofixa wrote:
             | In some countries/cities it's already mandatory to provide
             | ID when booking.
        
             | Keirmot wrote:
             | That's a strawman if I ever saw one. If you don't provide
             | ID to the hotel they may refuse sell you their services.
             | 
             | If you don't provide ID to the police, however, that's
             | another issue altogether.
        
               | mdp2021 wrote:
               | The poster is probably just trying to build a cases tree.
               | "What if I will not have electronic devices to buy
               | prescribed medicines? // Then you will probably present a
               | paper copy of the presctiption // Will it be allowed
               | tough?".
        
         | threeseed wrote:
         | None of these questions are new.
         | 
         | Verifying your identity without a global ID is done today
         | through a combination of primary and secondary identifiers. For
         | example a passport and bank statement. Or a driver's license
         | and recent tenancy agreement. So if you don't want to verify
         | yourself using the above combination then companies and the
         | government will simply not choose to interact with you.
         | 
         | And not sure if you've used a phone before. But you don't need
         | the full iCloud password to unlock your phone and access a
         | digital ID. You just need FaceID, TouchID or a 4/6-digit PIN.
        
           | iasay wrote:
           | The issue is more what happens when you buy a new phone or
           | lose the old one. Then you need the full iCloud details and
           | password. More than one person I know has got to that state
           | and have no idea what it was. They don't even know what their
           | own email address is to start with.
           | 
           | Incidentally I know how it works. I work next to the sector.
           | The issue is that these are all legitimate questions that we
           | have to work with daily and the abstract "we will arrest you
           | until you ID yourself" does not work when you book a hotel...
        
         | onion2k wrote:
         | _What happens if I don 't want to identify myself?_
         | 
         | This is the proposed solution. The point is that the ID system
         | only gives someone the information that they need. If you only
         | want to prove something like "age > 18" then you can do that
         | without giving up your name, address, ethnicity, etc. Every
         | existing solution to that requires you have over more than a
         | boolean answer that your age is above a minimum threshold.
         | 
         | This is effectively "attribute-based access control" (eg IAM)
         | for the real world.
        
         | [deleted]
        
         | raverbashing wrote:
         | The digital ID is optional
         | 
         | Requirement of carrying ID varies country by country
        
         | ranguna wrote:
         | > What happens if I don't want to identify myself?
         | 
         | That's a non issue in the EU.
         | 
         | > What happens if poverty does not allow me to carry a digital
         | ID?
         | 
         | Governments will probably pay this for you.
         | 
         | > What happens if I lose my digital ID wallet or it is
         | compromised?
         | 
         | Same as the current EU eIDs in use right now or a passport.
         | Revoke and reissue.
         | 
         | > Also judging by dealing with the average citizen on a daily
         | basis, even securing an iOS device and remembering the iCloud
         | password is beyond their level of care.
         | 
         | True, but that's probably something that needs to be improved
         | with education.
        
           | _Algernon_ wrote:
           | >That's a non issue in the EU.
           | 
           | For now
        
           | closewith wrote:
           | > That's a non issue in the EU.
           | 
           | Maybe in your EU country. ID cards are not mandatory in mine
           | (Ireland) - a national ID card has been rejected by the
           | electorate multiple times.
           | 
           | Be careful not to generalise your own experience to the
           | entire bloc - it's not a homogeneous entity.
        
             | timeon wrote:
             | I would welcome this ID but also think that this needs to
             | be optional.
        
             | xxs wrote:
             | Actually I can think of only Ireland...
        
               | tomjen3 wrote:
               | Dane here, I am not required to provide id, only to
               | identify myself if asked by a police officer.
        
               | dalke wrote:
               | https://en.wikipedia.org/wiki/Identity_documents_in_Swede
               | n: "There are several identity documents used in Sweden.
               | None are compulsory by law, meaning that there is no
               | formal penalty for not possessing one."
               | 
               | In practice things are more difficult without one one.
               | (Mine expired in January. I didn't notice until I needed
               | to pick up a package a few weeks ago. Ended up using my
               | US passport instead.)
               | 
               | https://en.wikipedia.org/wiki/Identity_document says "A
               | number of countries have voluntary identity card schemes.
               | These include Austria, Belize, Finland, France (see
               | France section), Hungary (however, all citizens of
               | Hungary must have at least one of: valid passport, photo-
               | based driving licence, or the National ID card), Iceland,
               | Ireland, Norway, Saint Lucia, Sweden, Switzerland and the
               | United States."
               | 
               | Checking Finland,
               | https://en.wikipedia.org/wiki/Finnish_identity_card says
               | it's about the same as Sweden: "Possession of an ID card
               | or any ID document is non-compulsory in Finland, though
               | interactions with officials and companies, like voting,
               | picking up a parcel from Posti offices or buying alcohol
               | when a salesperson suspects buyer to be under 18 or 30
               | years old, can be difficult or impossible without an ID
               | card, a passport or a driving licence."
               | 
               | As I recall, in Sweden to vote without id you need
               | someone who does have an id and knows you to vouch for
               | you.
        
               | wink wrote:
               | To sum it up, it's a complete mess and every country has
               | different rules and also enforces them differently.
               | 
               | After all these years I still have no clue what is
               | actually an official ruling of anything because I've had
               | no problem showing my driver's licence when officially
               | I'd needed my id card (in Germany). Then there's the
               | decade old widespread rumour that you need to _carry_ any
               | form of id, which is completely wrong (with a few
               | exceptions).
        
               | Asooka wrote:
               | Freedom is messy.
        
             | andrewshadura wrote:
             | > a national ID card has been rejected by the electorate
             | multiple times
             | 
             | However there's a passport card, which is nearly
             | indistinguishable from an identity card:
             | 
             | https://en.wikipedia.org/wiki/Irish_passport#Passport_Card
        
               | closewith wrote:
               | It's nearly indistinguishable from a passport, not a
               | national ID card (at least as implemented in other EU
               | states).
               | 
               | The closest thing in Ireland was the "mandatory but not
               | compulsory" Public Services Card and the related MyGovID,
               | until it was ruled unlawful to require a PSC for access
               | to government services.
               | 
               | There really is nothing like a mandatory national ID card
               | in Ireland.
        
         | Keirmot wrote:
         | Please forgive me if I'm jumping to conclusions here, but I'm
         | guessing you're American.
         | 
         | > What happens if I don't want to identify myself?
         | 
         | In some countries that is not an option. For example, in
         | Portugal when in a public space, the police has the ability to
         | ask for ID if they have a reason. They must first identify
         | themselves, and list the reasons to ask for identification. If
         | you have no valid ID with name and photo, someone that knows
         | you and can attest to your ID can do it, IF they themselves
         | have ID. If you're alone, you can either ask someone to take
         | your documents to where you are, or ask the police to go with
         | you to where you have them. If that is still not possible for
         | whatever reason, they you can be taken into a police station
         | until you're properly identified and your fingerprints are
         | taken.
         | 
         | After all that, if the reason why you were identified lead to
         | nothing you can request for the info on you to be eliminated.
         | 
         | > What happens if poverty does not allow me to carry a digital
         | ID?
         | 
         | Most countries have state issued ID cards. Note, I wrote most,
         | not all.
         | 
         | > What happens if I lose my digital ID wallet or it is
         | compromised?
         | 
         | Same thing that happens when you lose your wallet, I guess. Go
         | to the nearest police station, tell what happened. Then go on
         | from there.
         | 
         | > Also judging by dealing with the average citizen on a daily
         | basis, even securing an iOS device and remembering the iCloud
         | password is beyond their level of care.
         | 
         | People take government stuff more seriously than they do other
         | things. For example, my mother that can't remember her router
         | password knows her hexadecimal password to the IRS website by
         | heart. My in-laws kept the letters from the IRS with the
         | password in a well known place just to use it once a year when
         | they need to fill their forms.
         | 
         | I'm not saying there's implicit trust in governments in the EU,
         | but from the discourse on the internet, it's clear to me that
         | most (western) european citizens trust their government more
         | than Americans, overall.
        
           | verisimi wrote:
           | > I'm not saying there's implicit trust in governments in the
           | EU, but from the discourse on the internet, it's clear to me
           | that most (western) european citizens trust their government
           | more than Americans, overall.
           | 
           | This is absolutely right. And they are fools to do so! The
           | government can write legislation such as the police have the
           | right to see your id, and everyone is meant to show it! This
           | is nothing to do with right or wrong. It can be couched as
           | 'protecting people' whilst being tyrannical.
           | 
           | At least in the US they have access to weaponry to give those
           | government officials pause for thought of they attempt to
           | implement tyranny. Europe is already defanged though - who
           | could fight back, even if they wanted to?
           | 
           | The prospect is rigid stasis - governed by an unelected
           | elite, who have the mechanism of fine grained control over
           | every citizen. Its neo-feudalism via technocracy.
        
             | blitzar wrote:
             | Funnily enough people in the US that bang on about tyranny
             | and guns tend to also bang on about making anyone that
             | looks like a foreigner present documents.
             | 
             | Freedom for me and stazi for thee
        
           | iasay wrote:
           | I'm actually from UK and travel a lot in the EU.
           | 
           | Having been in a police station in Portugal they'd probably
           | laugh at you for getting your wallet ripped off and run you
           | to the airport.
           | 
           | And then there's the smaller towns in Germany. They don't
           | even accept cards out there yet. Cash or fuck off.
           | 
           | I think this is far off the status quo across Europe.
        
       | donquichotte wrote:
       | Am I being cynic here or is this just another attempt at total
       | surveillance? It solves a problem that does not exist, will
       | likely be mandatory at some point and is executed by a defense
       | company.
        
         | woodpanel wrote:
         | I'm guessing more like a/multiple "recently privatized" ex-
         | national telecommunications provider (ie blue chip company with
         | the state as majority stakeholder). You know, "plausible
         | deniability" and stuff...
         | 
         | Edit: I stand corrected, with Thales writing this article, we
         | can expect conglomorates such as Thales or Siemens to build
         | this as well (corporations that due to their long standing
         | national prominence are de-facto state-entities, although not
         | de-jure).
        
         | silversmith wrote:
         | You just have a very US centric view. Here's the situation in
         | Latvia: Full, searchable (by government institutions) digital
         | registry of citizens. Your income is being recorded for tax
         | purposes. There's centralised data on what vehicles you own,
         | and firearms are registered too. Medical data is also being
         | centralised, to handle prescriptions digitally, and share test
         | results between labs and doctors. Any criminal offences are
         | centrally registered too. The information is there, and most
         | likely being cross-referenced already.
         | 
         | What this would add is a more comprehensive log of where proof
         | of identity has been used. In my case, the last non-digital,
         | non-already-trackable request to display proof of identity was
         | last summer, when I was trying to buy a case of beer with a
         | mask, sunglasses and a hat completely obscuring my face. Guess
         | the police will now know I visit grocery stores.
         | 
         | What's more, that's already been sort of centralised, with a
         | single identity broker latvija.lv being run by the government,
         | that then relies on other "blessed" identity sources such as
         | banks or digital signature providers. The logs on who requested
         | the identity verification and who got verified are surely
         | there. If they cut the banks out of the loop, I see that as a
         | net positive.
         | 
         | As for me, I'm not overly bothered by this. I trust the
         | government to not wilfully abuse the data far, far more than I
         | trust any for-profit entity.
        
           | swader999 wrote:
           | What if Russia were to overtake Latvia in the coming months
           | via direct force or through installing a puppet regime? Trump
           | in 2024 for our American counterparts. Would you be okay with
           | the new masters having all this data and history on you?
        
             | ciupicri wrote:
             | If Russia takes over any country, it's game over anyway
             | like it was after WW2. The lack of an ID won't protect you
             | from rape, robbery, murder, a trip to gulag, etc.
        
             | mrtksn wrote:
             | Europeans have a rich history of bad regimes and their
             | removal. It's not like the puppet regime would be like "Oh
             | no, we can't do anything about this person who tweets nasty
             | things about us because we can't look him up in the central
             | registry". It's going to be like "hey Twitter give us the
             | ip address of this person or you loose your money and
             | access to our market" and then they will phone the ISP and
             | tell them to give the ID and address of the user with that
             | ip address.
             | 
             | So in reality, central registry of information doesn't
             | really protect you from anything but saves the bad actor a
             | few phone calls. On the other hand, it saves you a lot of
             | phone calls and office visits every time you need to deal
             | with the government.
             | 
             | If Russians install a puppet regime, the existence or lack
             | of central registry wont actually change much. It will
             | require popular uprising to make a difference, which
             | Europeans are actually accustomed to.
             | 
             | Riots and protests happen all the time everywhere and
             | taking down the governments is a thing too. Of course it
             | depend on the specific country but in general governments
             | in European countries resign all the time and when the
             | refuse to resign despite popular demand they end up removed
             | by riots.
        
               | swader999 wrote:
               | Indeed they do have a rich history of bad regimes. That's
               | kind of the point.
        
               | mrtksn wrote:
               | So they also have bad history of greedy private
               | enterprises on which they don't have a say.
               | 
               | The idea is that there's a value in having an
               | enterprise(the government) with centralised record
               | keeping because they own that government and have the
               | power to change managers on predefined reviews(elections)
               | and they have a history of forcefully changing managers
               | who try to stick around despite not being wanted.
               | 
               | What do you do when a private enterprise misbehaves? Mind
               | you, the governmental duties are often monopolistic by
               | nature. What do you do then? Sniper the CEO?
               | 
               | It's much more socially acceptable to riot against the
               | government and burn government building than assaulting
               | company HQ.
        
             | silversmith wrote:
             | Russia is indeed the main threat in our neck of the woods.
             | And with the regimes they tend to run, lack of easily
             | accessible digital registry is not something that will save
             | you from falling down the stairs and accidentally landing
             | on couple of bullets with the back of your head.
             | 
             | More importantly, we already have these registries! There's
             | already a digital identity verification service in place
             | that, according to our law, is sufficient to identify a
             | person to the same degree an ID card / passport would in
             | person. It's there, I've used it as an end-user, I've set
             | up integrations with it for my clients. The issue is that
             | if I want to identify myself to a German institution for
             | whatever reason, the only way I know of involves burning a
             | whole lot of dead dinosaur juice to get to Berlin, standing
             | in an orderly queue for a while, and presenting my passport
             | in person. And probably filling out couple forms along the
             | way somewhere.
        
           | maxwell wrote:
           | > You just have a very [U.S.] centric view. [...] I trust the
           | [Latvian/EU] government to not wilfully [ _sic_ ] abuse the
           | data [ _sic_ ] far, far more than I trust any for-profit
           | entity.
           | 
           | If unclear why no one in the U.S. trusts federal, state, or
           | local governments:
           | 
           | * The U.S. federal government now mostly acting in service of
           | for-profit entities, due to legalized bribery of elected
           | officials ( _Citizens United_ ) and inadequate representation
           | (the Judiciary Act of 1869 for the Supreme Court and the
           | Permanent Apportionment Act of 1929 for the House).
           | 
           | * History defeating the most powerful empire in world
           | history, emerging as the first nation to ever overthrow a
           | colonial oppressor.
           | 
           | * U.S. law enforcement officers extrajudicially killing more
           | Americans than mass shooters in 2019 and police departments
           | across the country taking in billions USD every year in
           | unconstitutionally seized assets.
           | 
           | * More Black Americans in the "justice" system in the 2020s
           | than were enslaved in the 1860s.
        
           | mrtksn wrote:
           | > I trust the government to not wilfully abuse the data far,
           | far more than I trust any for-profit entity.
           | 
           | The prime difference between American/British world view and
           | continental European one and I'm loving it.
           | 
           | Sure, it's very nice to think that the government doesn't
           | track you and doesn't know where you live. Then they build
           | these giant systems to covertly track everyone and listen to
           | everything.
           | 
           | Essentially, everything that the Americans believe that the
           | government wants to do to them is already being done - just
           | clandestinely.
           | 
           | On the European approach, we assume that the government is
           | competent enough and is ours, therefore we give them the
           | information needed to provide services and security. If the
           | governments misbehave we will simply burn their palaces and
           | drag them on the streets.
           | 
           | IMHO, both approaches have merits and I'm happy that they
           | exist at the same time. It kind of keeps the institutions on
           | track as scandals happen and fixes are implemented in attempt
           | of self preservation.
        
           | raverbashing wrote:
           | Americans love complaining harshly whenever someone mentions
           | "contry-wide" ID like it's literally the thing of the Devil
           | while ignoring that every other place illegally uses their
           | SSN as an ID number
        
         | snypox wrote:
         | It solves on problem for me. Since the introduction of Apple
         | Pay I hate taking my wallet anywhere and 95% of the time I
         | don't. But my ID and driver's license is in there and it's
         | needed sometimes. This gets me closer to the goal.
         | 
         | Let's say, travelling to a different country without a wallet
         | would be amazing to me.
        
         | kabes wrote:
         | It does solve a problem that exists. In fact the use cases are
         | listed in the article: filing tax reports, opening/accessing
         | bank accounts, etc. Basically the stuff where in the offline
         | world you would've needed to show your ID.
         | 
         | However, many (all?) EU members already have developed their
         | own national system. So this tries to unionize those systems so
         | dealing with other member nations becomes easier. Today I often
         | have to mail a bunch of documents if I want to prove my
         | business ownership to foreign companies.
        
           | sathishmanohar wrote:
           | and eventually those tax reports and credit ratings will be
           | tied to super market checkout systems. So governments can
           | pick and choose which tax payers can eat what.
           | 
           | Any data that is aggregated is open to abuse by the
           | aggregator and it will be definitely abused if the aggregator
           | is a government body.
        
             | dane-pgp wrote:
             | > tied to super market checkout systems
             | 
             | Norway is one step closer to that:
             | 
             | https://www.lifeinnorway.net/norway-to-track-all-
             | supermarket...
        
             | malermeister wrote:
             | I'd much rather have my government have info about me than
             | Facebook.
             | 
             | Even in your contrived dystopia, I'd rather have a
             | democratic government be the Big Brother than some
             | unelected tech CEO.
        
               | sathishmanohar wrote:
        
               | malermeister wrote:
               | Could you please elaborate your argument instead of just
               | doing drive-by insinuations?
        
               | closewith wrote:
               | That's a false dichotomy. We can create a world where our
               | right to privacy is respected by both governments and the
               | private sector.
        
               | malermeister wrote:
               | It doesn't change the fact that our government is voted
               | in, while private CEOs are moneyed in.
               | 
               | I trust the former more to have my best interests in
               | mind.
        
               | jiveturkey42 wrote:
               | The user consents to using a product, but not being born
               | into a particular location
        
               | malermeister wrote:
               | https://www.cnet.com/news/privacy/shadow-profiles-
               | facebook-h...
               | 
               | Come again?
        
               | mdp2021 wrote:
               | Why do you have to bring FB into the equation? It seems
               | you are mentioning it as a relevant alternative - what is
               | that?
               | 
               | When somebody says "This may be controversial // Well,
               | much better than being crushed under a rock", the latter
               | is supposed to be rhetoric, here somebody seems to treat
               | it like a real alternative, as if you went into the
               | current events to avoid that!
        
         | mordae wrote:
         | > Am I being cynic here or is this just another attempt at
         | total surveillance?
         | 
         | I don't think so. The idea is to make the wallet offline.
         | 
         | > It solves a problem that does not exist,
         | 
         | I does exist. Automatically checking identity is hard. Some
         | counties apparently issued certificates to their citizens and
         | enabled them being verified by anyone, simplifying several
         | online businesses patterns.
         | 
         | > will likely be mandatory at some point
         | 
         | More like fast lane. But eventually (30 years) probably yes.
         | 
         | > and is executed by a defense company.
         | 
         | Every country is responsible for their own part. There are
         | going to be ETSI standards for interoperability.
         | 
         | The actual trouble here is that (at least in my country) the
         | officials responsible believe that rooted phone is higher
         | security risk than automatic updates from Chinese government.
        
           | closewith wrote:
           | > Automatically checking identity is hard.
           | 
           | This seems like a feature, not a bug.
        
             | stubish wrote:
             | Every single non-cash transaction you make every single day
             | needs to check your identity. Currently it is outsourced to
             | banks, multinationals like visa, thousands of different
             | government departments providing trusted docs (usually a
             | few different ones per country). And a lot of fraud happens
             | because we do a bad job at it. Or for-profits, doing 'good
             | enough' where 'better' isn't profitable, because they get
             | to pass on the trauma of identity theft to the victims.
        
         | threeseed wrote:
         | I can't see much of a difference compared to a passport or
         | driver's license.
         | 
         | The quiet explosion in CCTV cameras across Europe is far more a
         | threat than some unique identifier.
        
           | mdp2021 wrote:
           | > _passport or driver 's license_
           | 
           | Physical documents. This is an electronic system, with
           | potential for issues as you (in this crowd) should suspect.
           | 
           | > _is far more a threat_
           | 
           | Which definitely concerns us in its own turn - who the
           | daughter is dating will take its own slot.
        
             | isbvhodnvemrwvn wrote:
             | The data on the document is just a snapshot of the data in
             | electronic systems. These systems are used every single day
             | when you use physical documents in healthcare or any other
             | government-related scenarios to double-check on that
             | physical document.
        
               | mdp2021 wrote:
               | > _The data on the document is just a snapshot of the
               | data in electronic systems. These systems are used every
               | single day_
               | 
               | The issue is not with the governmental database, taken
               | for granted. It is with the consequences brought by the
               | electronic system on the user side.
        
         | scrollaway wrote:
         | Just because you don't see the problem it is solving doesn't
         | mean the problem does not exist.
         | 
         | Some context: I'm French, I live in Belgium. I have two e-IDs
         | cards: one french, one belgian. When I need to identify myself,
         | depending on the government I have to deal with, I have to use
         | either my "FranceConnect" credentials, or my Belgian e-ID card.
         | 
         | When using my Belgian eID, there is a government login called
         | CSAM, but a lot of people here use a private company called
         | "itsme" (https://www.itsme-id.com/). ItsMe does not support
         | Linux. CSAM does, but not every service that supports or even
         | requires eID login here supports CSAM.
         | 
         | FranceConnect is even more of a mess. French government has a
         | plethora of online services, several with their own logins and
         | not all support FranceConnect.
         | 
         | Making a digital wallet won't increase surveillance...
         | surveillance is already possible on all of this, quite easily
         | so. What it will do is greatly simplify life for people dealing
         | with these systems; especially for expats and new arrivals into
         | a country, who might get stuck in the loop of "You need a bank
         | account to get your ID" "You need an ID to open a bank account"
         | 
         | Not to mention all the services that do their own shitty KYC
         | and would be better served by using automated ID checking
         | instead. Unless you think it's better and "more private" to
         | email a photocopy of your ID and passport to somebody who will
         | forward it three times, save it on their computer, and share it
         | on Slack with the tech team because there's a problem with
         | their shitty KYC system.
        
           | _Algernon_ wrote:
           | >Making a digital wallet won't increase surveillance...
           | 
           | There is no reason to believe that. You are installing a
           | government app on a gps device with a constant internet
           | connection. Even if it doesn't send such data initially,
           | there is no way for a regular user to know that some forced
           | update in the future wont introduce it. At least before they
           | would have to go through the courts to get a warrant to get
           | it from google or apple.
        
           | TacticalCoder wrote:
           | > When I need to identify myself, depending on the government
           | I have to deal with, I have to use either my "FranceConnect"
           | credentials, or my Belgian e-ID card.
           | 
           | That you even have to identify yourself as often as you do in
           | the EU is a problem the EU countries created. So basically
           | they create a problem (people needing to identify for
           | basically everything: vaccine, going to the restaurant, going
           | to nightclubs, maybe going to the toilet in the future, etc.)
           | and then come up with a solution: _" Look, it's going to get
           | easier to identify yourself!"_ and everybody applauds.
           | 
           | But, wait, why do I need to be identified all the time yet?
        
             | scrollaway wrote:
             | Yeah. No. I identify myself when I log in to my utilities
             | providers, my bank, when I do my taxes or handle some other
             | government related stuff.
             | 
             | I have no idea what you're on and I'd love to know where I
             | can get some.
        
             | drawfloat wrote:
             | This might shock you but none of those things need ID in
             | most EU countries.
        
           | judge2020 wrote:
           | > a government login called CSAM, but a lot of people here
           | use a private company called "itsme"
           | 
           | It probably doesn't help that the CSAM term has an overlap
           | with another english abbreviation.
        
             | scrollaway wrote:
             | Belgium is not an English speaking country.
        
           | woodpanel wrote:
           | > _Making a digital wallet won 't increase surveillance...
           | surveillance is already possible on all of this,_
           | 
           | Sure, because a little minority of people has _" the burden"_
           | of managing multiple IDs, lets tear down one firewall between
           | citizenry and big-brother for the rest of us.
        
             | malermeister wrote:
             | What's the "firewall" in this case? eIDs already exist all
             | over the place, as demonstrated in parent. They also
             | clearly have their use, even though they are currently
             | frequently broken.
             | 
             | Is the brokenness the firewall?
        
               | woodpanel wrote:
               | The firewall is who is accountable, who is responsible to
               | the electorate. "Broken" no, a feature yes, because
               | exploiting technical flaws in a country's digital ID for
               | an attacker becomes more troublesome if each country has
               | a (an even slightly) different implementation.
               | 
               | Labeling it "broken" - we all are using the same password
               | for every account anyways, aren't we?
        
               | malermeister wrote:
               | But we're talking about the EU here, the second largest
               | democracy in the world. Of course they're accountable to
               | the electorate. This isn't a dictatorship.
        
               | woodpanel wrote:
               | Totally democratic. Of course. Europeans love it.
               | 
               | From Berlin xHainers to Parissienne Bobos, from Munich
               | Schwabing to Noord Amsterdam, there isn't a single
               | citizen in the EU with discomfort of his vote becoming
               | dilluted from a x-millionth to an x-hundredmillionth.
               | 
               | That's why Ursula von der Leyen is so popular.
        
               | illiac786 wrote:
               | Diluted? EU has significantly more power than any single
               | country. More than the sum of the power of each country
               | taken individually. Hence, mathematically, your vote has
               | more power in the EU.
        
               | malermeister wrote:
               | But thats just... yknow, how democracies work. More
               | voters = less power/vote.
               | 
               | Are you just unhappy the electorate is so large? What
               | would the appropriate size be? Mayoral? Households?
               | That'd really maximize the power of your vote.
               | 
               | But then, how would we organize at the level beyond that?
               | Warring tribes? Go back to when Germany and France were
               | constantly at war?
               | 
               | I don't love vdL either. I think the EU is in need of
               | reform. But I still think it's fundamentally a good idea
               | and I think vote dilution is just inherent to a large
               | democracy.
        
               | potatototoo99 wrote:
               | There's not much democracy in the EU, and that's by
               | design.
               | 
               | I'm only surprised they haven't got rid of the ability of
               | countries to secede the union yet. I'm guessing all these
               | pushes for further integration are an attempt at de facto
               | making it impossible to secede, even if not legally.
        
               | malermeister wrote:
               | > There's not much democracy in the EU, and that's by
               | design.
               | 
               | [citation needed]. Please don't just throw out wild
               | claims without any proof. As far as I'm aware, every
               | single element of the EU is democratically legitimized in
               | one way or another. Do you have any evidence to the
               | contrary?
               | 
               | > I'm only surprised they haven't got rid of the ability
               | of countries to secede the union yet.
               | 
               | Why would they? If you don't want to be on our boat, feel
               | free to sink on your own. We don't need the dead weight.
        
               | timeon wrote:
               | > and that's by design.
               | 
               | And that design is there to keep sovereignty of
               | membership countries - so it is strange that you are
               | surprised that there is still the ability of countries to
               | secede the union. Most powerful entities in EU are
               | national governments of countries. Who is appointing
               | Commissioners? Member states. Similar like national
               | governments are appointing its ministers. Then there is
               | veto and of course, who has last word in everything?
               | Heads of states / prime ministers.
        
               | rjzzleep wrote:
               | Ah yeah, just like how Von der Leyen, Macron said that
               | they want to abolish the consensual vote, when Hungary
               | didn't play along with sanctions being a landlocked
               | country. Totally democratic and totally designed to keep
               | sovereignty.
        
               | toyg wrote:
               | Macron can say what he wants, he has not written any
               | treaty yet. The Hungarian government is still free to act
               | as they see fit.
               | 
               | This said, majority-rule can only increase in European
               | mechanisms, because a continent cannot be paralized by
               | the needs of a tiny minority on every possible choice.
               | Does the US Senate (effectively the equivalent of
               | EuroCouncil, with almost-equal representation for each US
               | state) require unanimity on every choice? Obviously not,
               | or it would never get anything done (and even like that,
               | it struggles massively to approve anything these days).
        
               | jules wrote:
               | From my vote to this decision there are so many layers of
               | abstraction that I wouldn't even begin to have a clue who
               | to vote for and in which election if I do or do not want
               | this E-ID.
               | 
               | At least in national elections there are parties
               | campaigning with a platform and then I can decide which
               | platform I like best. How often the platforms of the
               | elected parties get translated into reality is another
               | question, but it can at least plausibly be described as
               | demos kratos. Maybe the EU is "democracy" in some modern
               | sense of the word, but in the original sense of the word
               | it is not. (I'm not even saying that's a bad thing. Maybe
               | it is in fact better to have elites deciding.)
        
               | toyg wrote:
               | _> At least in national elections there are parties
               | campaigning with a platform and then I can decide which
               | platform I like best._
               | 
               | I fail to see how you cannot do that in European
               | Parliament elections. If anything, EUP elections are more
               | democratic than average, by way of using a proportional-
               | representation system that matches voters' preferences
               | more closely than almost any European voting system.
               | 
               | And if you're saying, "but it's the Commission proposing
               | laws!", they don't pull stuff out of thin air: the
               | Commission effectively tries to implement an agenda that
               | European Council members agree together. And who is
               | EuroCouncil? National governments, whom you vote for.
               | Also, the Commission doesn't work alone - directives are
               | effectively drafted in concert with Parliament
               | committees, because in the end they have to be approved
               | by such Parliament.
        
               | argentier wrote:
               | The EU is not a democracy. Its only democratic organ is
               | toothless.
               | 
               | It is an association of democracies, led by an
               | undemocratic executive that is increasingly out of
               | control. At the moment it is busily destroying its own
               | economy in a way that is baffling to many of its
               | citizens.
               | 
               | If it doesn't evolve into something more democratic it
               | probably hasn't long to go.
        
               | malermeister wrote:
               | The executive is appointed by democratically elected
               | officials. Y'know, the same way the US president is
               | elected by electors, or Prime Ministers are elected by
               | parlaments. Most democracies work this way.
        
               | argentier wrote:
               | In fact it's quite different.
               | 
               | The US president campaigns before a democratic election.
               | The people know who they can choose before they vote.
               | Same with the UK.
               | 
               | There is no democratic vote, with or without proxy,
               | before the appointment of the Commission.
               | 
               | Why the downvote btw? This isn't reddit.
        
               | M2Ys4U wrote:
               | >There is no democratic vote, with or without proxy,
               | before the appointment of the Commission.
               | 
               | Err, yes there is. The directly-elected European
               | Parliament first elects the President of the European
               | Commission, and then has to vote to appoint the entire
               | Commission.[0]
               | 
               | And before they do they they hold hearings with each of
               | the different commissioner-nominees to evaluate their
               | suitability for the role, demanding that people are
               | replaced or given different portfolios if they are not
               | suitable.
               | 
               | Nominations for the role of President must take in to
               | account the results of the election,[0] and the European
               | Council nominates somebody from the largest party in
               | Parliament. I wish that Parliament had stuck to its guns
               | in 2014/2019 and rejected the nominees that weren't
               | spitzenkandidaten but hopefully the new proposals tabled
               | by Parliament creating transnational lists for Parliament
               | will change this.[1]
               | 
               | [0] Article 17(7) of the Treaty on European Union
               | 
               | [1] https://www.europarl.europa.eu/news/en/press-
               | room/20220429IP...
        
               | raverbashing wrote:
               | > with or without proxy, before the appointment of the
               | Commission.
               | 
               | Of course there is. The commission is chosen by the
               | countries elected representatives (and confirmed by the
               | directly elected EU Parliament)
               | 
               | The downvotes are justified
        
               | mantas wrote:
               | Too many abstraction layers and too much happening behind
               | closed doors withotu elected politicians present. As a
               | citizen of EU member, I find it very hard to define EU as
               | a democracy.
               | 
               | We need Swiss-style referendums-on-everything. Now it
               | feels like oligarchy managed by lobby groups no matter
               | what you vote for.
        
               | scrollaway wrote:
               | > _We need Swiss-style referendums-on-everything._
               | 
               | Ah, yes, nothing like asking 450M people for their
               | opinion on something they know nothing about.
               | 
               | This is how Brexit happened, isn't it?
        
               | mantas wrote:
               | Do we want democracy? Or ruling by oligarchs, hoping that
               | oligarch you like will end up ruling?
               | 
               | Obviously democracy needs educated citizens who don't
               | take the responsibility lightly. That's why citizenship
               | shall be a big privilege with even bigger
               | responsibilities. We have to have a lively discussion.
               | Otherwise it's people who cry loudest win.
               | 
               | I love Brexit as a democratical move. People voteds and
               | government followed through. Now citizens will live out
               | consequences, for better or worse. And they can make next
               | decision accordingly. That's so much better than
               | enlightened oligarchy guarding the masses from their own
               | wrong feelings.
               | 
               | That's like raising kids. If you guard kids from their
               | own painful decisions, they'll never learn. Eventually
               | they'll be adults and they'll keep doing dumb decisions.
               | You have to let them experience some pain to teach them a
               | lesson.
        
             | [deleted]
        
           | kabes wrote:
           | What do you mean itsme does not support linux? It's a phone
           | app, you don't need to install anything on your linux
           | machine...
           | 
           | However, it's not a good situation that a private company
           | gets such a central role. In fact, Belgian government
           | yesterday announced they're going to make their own
           | implementation. Surely there's already eID login, but that's
           | too cumbersome compared to itsme because it's from the pre-
           | smartphone days.
        
             | scrollaway wrote:
             | Are you talking about this?
             | 
             | https://www.brusselstimes.com/belgium/246070/federal-
             | governm...
             | 
             | The Belgian government already has an implementation:
             | https://www.csam.be/en/egov-profile.html
             | 
             | I don't use itsme, only CSAM, because itsme does not
             | support Linux: I can't log in with Firefox or Chrome on
             | Linux with my eID. But CSAM is not universally supported.
             | Example of a site that does not support it:
             | https://www.proximus.be/ - Major ISP in Belgium)
        
               | sam_lowry_ wrote:
               | Itsme is an authentication token, like eID.
               | 
               | You can login to CSAM protected websites on Linux with
               | Firefox or Chromium and with Itsme token running on
               | Android or iPhone.
               | 
               | You can also login on Linux with Firefox or Chromium and
               | with your eID card inserted in a properly configured card
               | reader such as ACR-38U.
        
               | seszett wrote:
               | I'm not sure because I don't use itsme anymore (it
               | stopped working on jailbroken devices a while ago, so I
               | just switched to TOTP auth with CSAM) but if I remember
               | correctly the _initial setup_ of itsme doesn 't work on
               | Linux, as it requires a browser plugin for the card
               | reader that doesn't run on Linux. CSAM uses a different
               | browser plugin that does work on Linux.
        
               | scrollaway wrote:
               | Yes that's exactly right.
        
               | sam_lowry_ wrote:
               | I set up itsme on my android phone using linix. This was
               | a couple years ago, so things likely changed for worse
               | since then.
               | 
               | P.S. If you use a JB device, you should also use Magisk
               | and be ready to troubleshoot.
        
               | ploum wrote:
               | Worth mentioning that itsme is a private consortium of
               | several banks and phone operators which explicitely says
               | that data collected will be used for marketing purpose
               | and "research".
               | 
               | That you can't even think of using it if, like me, you
               | are not using a phone operator or one of the few banks
               | which are part of the consortium.
        
               | seszett wrote:
               | That's not true, in my experience you can even use it if
               | you only have a French phone number and no Belgian bank.
        
               | ploum wrote:
               | Indeed, they added the ability to create an account with
               | your eid. It was not the case a couple of years ago.
        
               | thepangolino wrote:
        
               | kabes wrote:
               | > Are you talking about this?
               | 
               | Yes, that's what I'm talking about, although
               | brusselstimes seems to report it weirdly (sounds like
               | they want to extend itsme).
               | https://www.standaard.be/cnt/dmf20220627_97617861 -> They
               | want to replace itsme with something build by the
               | government.
               | 
               | > The Belgian government already has an implementation:
               | https://www.csam.be/en/egov-profile.html
               | 
               | You're confusing a couple of things here. CSAM isn't an
               | identity provider. It's like a gateway/umbrella to
               | multiple identity providers like eID and itsme. You can
               | have eID authentication without CSAM and vice-versa.
               | 
               | It doesn't make sense to claim itsme doesn't support
               | linux. It's only a phone app, you dont need desktop
               | software. I can login to proximus.be using itsme on
               | linux.
        
               | sam_lowry_ wrote:
               | The worst part af all this government id story that no
               | one talks about is that Belgian government lost control
               | of its Root Certificate Authority.
               | 
               | It is now handled by Digicert, a US company.
        
               | fazgha wrote:
               | Do you have any source for this ? I know that current
               | root certificates are self signed. [0]
               | 
               | [0] https://repository.eid.belgium.be/certificates.php
        
               | throw10920 wrote:
               | > It doesn't make sense to claim itsme doesn't support
               | linux. It's only a phone app, you dont need desktop
               | software. I can login to proximus.be using itsme on
               | linux.
               | 
               | I think you're seriously confused. It's _perfectly_
               | reasonable to claim that itsme doesn 't support Linux.
               | Phone have operating systems too, you know - and some
               | phones run a Linux userspace (e.g. the Pinephone and
               | Purism).
               | 
               | "Does not support Linux" means "itsme can't run on a
               | Linux userspace" (as opposed to a Linux kernel but Google
               | userspace, which is what Android is).
               | 
               | The author explicitly says this: "I don't use itsme, only
               | CSAM, because itsme does not support Linux: I can't log
               | in with Firefox or Chrome on Linux with my eID."
        
             | mariusor wrote:
             | Is it so difficult to conceive that are people out there
             | using phones that run something else instead of Android or
             | iOS? Even linux.
        
         | the_biot wrote:
         | Of course it is. Note this line from TFA:
         | 
         |  _Something the customer is (fingerprint, iris, face)_
         | 
         | Right there, trying to normalize the idea that the government
         | needs our fingerprints, iris etc. And that ship has sailed,
         | lots of laws getting passed that will _require_ this from
         | citizens.
        
         | radicalbyte wrote:
         | I'm involved in a group who come into contact with this. It's
         | not about surveillance, it's about providing European
         | governments, European economy and citizens with electronic ID
         | in all situations without having to rely on
         | Google/Apple/Facebook. So you can have a secure way to login to
         | websites, with many personas, without having to share your GAF
         | (and thus be tracked by GAF / share GAF data with yet another
         | party).
         | 
         | Thales on the other hand are not what I would describe as a
         | good actor but rather one of the "usual suspects".
        
           | mdp2021 wrote:
           | > _without having to rely on G. /A./F. So you can have a
           | secure way to login to websites_
           | 
           | Said perspective is insanity: for those websites relevant to
           | an anagraphic identity it would be dramatically abnormal to
           | use any supposed private company related account. It would be
           | sheer absurdity to suppose a "need" for accounts with private
           | entities to log on to nominal services.
        
           | Asooka wrote:
           | The number of websites where I would willingly use my real id
           | is no more than five. I almost never want to have anything I
           | write online attached visibility to my actual public
           | identity. Anonymity is the whole point of the internet!
        
             | swader999 wrote:
             | Any functioning society needs anonymous dissent, especially
             | a democracy.
        
           | radicalbyte wrote:
           | Personally I have a dim view of the companies working in this
           | area / the working groups because so far they've not
           | delivered anything yet have been working on it forever. You'd
           | expect there to be a vibrant community on Github sharing Open
           | Source implementations. Or at least speaks. Or at least
           | something.
           | 
           | Also there are so many bullshitters and snake-oil merchants
           | in this field; makes you think that most of the "security"
           | industry is a confidence game.
        
           | woodpanel wrote:
           | > _So you can have a secure way to login to websites, with
           | many personas, without having to share your GAF_
           | 
           | Let's manage the beloved and accountable Eurocrats in
           | Brussels our private Auth-infrastructure, because its not
           | like this problem would be solvable otherwise:
           | 
           | https://news.ycombinator.com/item?id=31836922
        
             | blitzar wrote:
             | Let's give the beloved and accountable Google / Facebook /
             | Microsoft in the US of A our private Auth-infrastructure,
             | because its not like this problem would be solvable
             | otherwise, and its not like they have ever done anything
             | with our data before that would make you wonder if they can
             | be trusted.
        
               | woodpanel wrote:
               | FIDO is an open standard, that by definition doesn't
               | store your data at GAF.
        
               | blitzar wrote:
               | I look forward to being able to pick up the phone to
               | Google / Facebook / Microsoft, talk to a human and have
               | them troubleshoot why they have locked me out of
               | everything in the world.
        
             | hourago wrote:
             | > accountable
             | 
             | That's the key. European politicians are accountable to
             | European citizens. Big corporations are not. This seems a
             | step in the right direction.
        
               | woodpanel wrote:
               | > _European politicians are accountable to European
               | citizens._
               | 
               | That joke made my day. I'm guessing Ursula von der Leyen
               | is a real people's champ then.
               | 
               | > * Big corporations are not. This seems a step in the
               | right direction.*
               | 
               | So let big corporations develop the technology?
               | Especially those that are intertwined with the state? In
               | otherwords, entitites where the state has created
               | plausible deniability for itself? Great, what could go
               | wrong?
        
             | malermeister wrote:
             | This might be a shock to you, but people here would rather
             | have their democratic government in charge of identity than
             | some unelected, for-profit foreign company in a country
             | that specifically does _not_ have any privacy protections
             | for non-citizens.
        
               | Asooka wrote:
               | I would rather not have online identity at all.
        
               | fvdessen wrote:
               | Then don't use the system ?
        
               | swader999 wrote:
               | It's telling that both you and I opted to choose a
               | username that is somewhat anonymous on this system. We
               | both saw this as preferable.
        
               | malermeister wrote:
               | This system isn't designed for writing comments on Hacker
               | News.
               | 
               | It's designed for things like filing your taxes or
               | applying for a passport.
        
               | swader999 wrote:
               | Won't be hard to use it for everything, especially
               | purchases. That's the main issue.
        
               | malermeister wrote:
               | It would be hard from an operational and customer
               | satisfaction perspective.
               | 
               | Does the grocery store ask you for your passport? If not,
               | why should the online store ask you for your online
               | passport?
        
               | woodpanel wrote:
               | This might be a shock to you, but people in Europe
               | already have _their_ democratic government - you may
               | google  "national elections" ;-)
               | 
               | And again, FIDO is an open standard, that by definition
               | isn't run or dependend on the servers of "for profit
               | private companies".
               | 
               | But gee, I must be total noob then. Open-Source can be
               | bad, as can be accountability.
               | 
               | For the greater good I guess.
        
               | malermeister wrote:
               | > This might be a shock to you, but people in Europe
               | already have their democratic government - you may google
               | "national elections" ;-)
               | 
               | People _in Europe_ don 't. People _in the various
               | countries_ do. This is just a level above, just like you
               | don 't say "oh why do we need the german government,
               | can't the mayors do everything?".
               | 
               | Different levels of organization need different
               | democratic governments. Tribalism is not the solution.
        
               | argentier wrote:
               | What is democratic about the European Commission?
               | 
               | Having an executive made up of people selected by other
               | politicians for political reasons is all very well as
               | long as they understand that they do not have much
               | legitimacy.
               | 
               | JC Junker, for all that he was a bit of an old sot,
               | understood this very well.
               | 
               | Von der Leyen, either because of her immensely privileged
               | background, or because of her inability to communicate in
               | any diplomatic way, has revealed the undemocratic
               | abomination at the heart of the European Project.
               | 
               | Her press conference with Stoltenberg (and Belgian
               | nonentity Michel) at the outset of the Ukraine war
               | deprived the EU of any room for manoeuvre in relations
               | with Russia. She unilaterally committed hundreds of
               | millions of people to a diplomatically absolutist
               | position. Furthermore, she actively spun against attempts
               | by Macron and Scholz to moderate that position.
               | 
               | The EU cannot continue like this: already I'm quite
               | dubious as to whether it will survive the winter, with
               | double digit inflation and mass industrial layoffs in
               | prospect.
               | 
               | If Putin wants to play divide et impera with Russian
               | fossil fuel supplies, she has certainly created the ideal
               | conditions for him to do so.
               | 
               | She is corrupt (see Pfizer SMS) and unaccountable.
        
               | malermeister wrote:
               | The commission is appointed by democratically elected
               | heads of government, the same way the US president is
               | appointed by democratically elected electors or the Prime
               | Minister of the UK is appointed by democratically elected
               | MPs.
               | 
               | Are all of those undemocratic, too?
               | 
               | > Her press conference with Stoltenberg (and Belgian
               | nonentity Michel) at the outset of the Ukraine war
               | deprived the EU of any room for manoeuvre in relations
               | with Russia.
               | 
               | Russia's war of aggression on our neighbor deprived us of
               | any room for manouvre. We've seen what appeasement brings
               | in the 30s, no need to play that game again.
        
               | argentier wrote:
               | Not every enemy is Hitler: not every attempt at a
               | diplomatic settlement is appeasement. That's
               | childishness, and lamentably common at the moment.
               | 
               | The game we are playing is resulting in mass death and
               | destruction in Ukraine, and slowly throttling the
               | European economies. What's the point?
               | 
               | Perhaps if you expanded your frame of historical
               | reference you might see more clearly.
        
               | malermeister wrote:
               | Not every enemy is Hitler, but the one trying to find
               | more Lebensraum for his volkisch ideology certainly is
               | :-).
               | 
               | Perhaps if you educate yourself more about the era you
               | might see the parallels more clearly.
               | 
               | You say "slowly throttling the economies", I say finally
               | giving us a reason to accelerate investment in renewables
               | before climate change kills us all.
        
               | yaantc wrote:
               | FIDO allows to authenticate to _an_ identity, which
               | ideally is securely stored in a token and cannot be
               | cloned or stolen. This identity is only an large,
               | arbitrary number and that 's all. This is not enough
               | here.
               | 
               | The example provided (bank account, university
               | registration) make it clear that we're talking about
               | authenticating against a person real, legal entity here.
               | It's not needed in all cases, and when it's not FIDO is
               | fine, but when it's needed in the end the root of trust
               | in Europe is one's national state anyway.
        
           | cm2187 wrote:
           | Every time you create an entry into a log file you have
           | surveillance. It doesn't matter whether someone is currently
           | watching the CCTV in your bedroom if it's all on tape.
        
           | closewith wrote:
           | Providing governments with a de facto mandatory electronic ID
           | for every citizen is inherently providing the means to
           | surveil, though.
           | 
           | I also wonder how this will be regarded in countries like
           | Ireland, which doesn't have a national ID card and where a
           | recent attempt to make a similar digital ID system mandatory
           | was ruled unlawful (PSC/MyGovID).
        
             | slartibardfast0 wrote:
             | Ireland can't really do a national id scheme without mutual
             | agreement with the UK due to the common travel area &
             | mutual residence rights (including voting at parliamentary
             | level upon taking residence) that are dealt with in an ad-
             | hoc manner for many reasons. due to this, Ireland has
             | default opt-out on justice & home affairs issues.
             | 
             | however, as an EU citizen, I can see immediate advantages
             | to a cautiously administered digital id. as it is, many
             | states within the EU demand a national tax id on
             | registration for services as simple as bike rental, such a
             | digital id would presumably supersede such nonsense and
             | help further the single market everyone is working towards.
        
             | herbstein wrote:
             | > Providing governments with a de facto mandatory
             | electronic ID for every citizen is inherently providing the
             | means to surveil, though.
             | 
             | But this suggestion ain't it. Most EU countries already
             | have a de facto mandatory electronic ID for every resident.
        
               | closewith wrote:
               | > But this suggestion ain't it.
               | 
               | What's your basis for this claim? From the declared
               | strategy, it seems perfect for abuse as a surveillance
               | tool.
               | 
               | > Most EU countries already have a de facto mandatory
               | electronic ID for every resident.
               | 
               | As stated elsewhere, my country (Ireland) does not. It's
               | attempt at a mandatory electronic ID (MyGovID/Public
               | Services Card) was ruled as unlawful (it's still
               | available, but cannot be required to access government
               | services).
               | 
               | Strategy link: https://ec.europa.eu/info/strategy/priorit
               | ies-2019-2024/euro...
        
             | radicalbyte wrote:
             | The regulation will have to make that illegal - there are
             | several countries who would block the regulation it if it
             | wasn't.
             | 
             | So the situation will be better for us than today - there
             | will be more options providing the ID (and wallets),
             | including highly privacy-preserving tech based on modern
             | encryption techniques. That will make it much harder to be
             | tracked by commercial players and much harder to be tracked
             | legally by governments.
             | 
             | For the blackhat / illegal security agencies: you might
             | make it a little harder because the US-compromised
             | companies (FAANG + MS) aren't (always) involved.
        
           | swader999 wrote:
           | If that's all it is then fine. But it seems to be just the
           | first step to what many fear will become a system tied to
           | digital currency, speech and social credit.
        
           | cmroanirgo wrote:
           | ...and yet because there's only Apple and Google providing
           | hardware that's used by the masses, exactly how is this going
           | to work? If the environment we're using is completely
           | contained (pwned) then how will this not be a draconian
           | system of control?
           | 
           | What happens when I buy debian mobile? I presume it will not
           | be accepted because there will be no safe app. No app, no
           | identity? No identity means you're suddenly locked out of
           | society.
           | 
           | What phone theft? Most people's phone security is almost non
           | existent.
           | 
           | What about luddites who have no mobile at all?
           | 
           | It seems like it's 100% about control of people. And that's a
           | privacy matter. My body, my life, my choice.
        
             | mdp2021 wrote:
             | > _mobile_
             | 
             | In theory, you should be able to go on using a passport for
             | your actual needs. In practice, it is to be seen whether
             | this initiative will cause or not cases where "options"
             | become "constraints".
        
         | asdajksah2123 wrote:
         | It's surveillance to the extent any ID system is surveillance.
         | 
         | This is a digital form of all the IDs you get from the state
         | already.
         | 
         | There are genuine concerns about the scale at which digital IDs
         | can potentially be exploited and/or the scale of monitoring
         | this can enable, but in functional societies and governments
         | you can build laws and systems to mitigate such issues.
         | 
         | The alternative are low quality ad hoc systems that offer
         | convenience, but have no incentive for privacy and/or security.
         | 
         | For example, consider the massive Experian hack in the US. A
         | credit score is basically required if you want to be a
         | functioning member of American society. And yet they barely got
         | a slap on the wrist and continue with their pathetically poor
         | security practices. And it's not like they (or any US entity,
         | for that matter) will not make their data available to the
         | government.
         | 
         | In fact, with a government controlled DB the voters can have
         | far more say on what the govt can do with that data, as opposed
         | to Apple or Google owning that data (which is what's happenign
         | in the US with Apple providing digital ID for states, and I'm
         | sure Google will get into that as well), which becomes their
         | private data and as a member of society you have no say on what
         | can be done with that.
        
         | nix23 wrote:
         | >just another attempt at total surveillance?
         | 
         | Well yes, have you seen what europol can do now? Safe and
         | analyze data even from unsuspected people.
         | 
         | German:
         | 
         | https://www.heise.de/news/Europols-Mandat-zur-Massenueberwac...
        
         | cm2187 wrote:
         | Most of the examples mentioned in the article already require
         | your identity (opening bank account, tax return, etc).
         | 
         | Others are outright creepy. You can't access medecine without
         | verifying your ID? That locks lots of people out of access to
         | healthcare (illegals, tourists, etc). Age verification? So porn
         | websites will store the real id of all their visitors (or
         | alternatively a central EU age verification system will be
         | notified every time you visit such a website)?
         | 
         | In France for instance it is illegal to identify people by
         | their social security number in a system (at least it was 20
         | years ago). That's a safeguard to prevent it from making it too
         | easy to correlate an identity across many systems. This ID
         | scheme will go around that. To be honest I think that law was
         | passed at a time where surveillance was still considered evil.
         | I think governements of most liberal democracies today are
         | actually entertaining stasi-style surveillance as a greater
         | good.
        
           | M2Ys4U wrote:
           | >Others are outright creepy. You can't access medecine
           | without verifying your ID? That locks lots of people out of
           | access to healthcare (illegals, tourists, etc).
           | 
           | Does it not make sense that prescription medication can only
           | be picked up by somebody who has been prescribed that
           | medication (or somebody who has been delegated that authority
           | by the prescribee)? As long as there's an offline mechanism
           | available for verification I don't see the problem here.
           | 
           | >Age verification? So porn websites will store the real id of
           | all their visitors (or alternatively a central EU age
           | verification system will be notified every time you visit
           | such a website)?
           | 
           | Presenting a token verifying that one is over 18 is not the
           | same thing as presenting one's _entire identity_ so that the
           | service can verify one is over 18.
           | 
           | The way it could work is this: You try and access an age-
           | restricted service (ARS). It returns a request for age
           | verification including a unique ID. You then pass a hash of
           | that request to the age verification service (AVS), and get
           | back a token which is signed by the AVS. That token is then
           | presented to the ARS, which validates that the signature and
           | that the hash of their request are valid.
           | 
           | Boom, you have just verified that you are over 18 without
           | leaking your identity to the ARS and without leaking the
           | ARS's identity to the AVS.
        
             | cm2187 wrote:
             | All you have done is to move the juicy log file to the AVS,
             | haven't you?
        
               | M2Ys4U wrote:
               | All the AVS knows is that you're asking for an age
               | verification token for _something_ , but it doesn't know
               | what the token will be used for as that information was
               | collapsed in to a hash by you.
               | 
               | I'm sure there could be some sort of more elaborate
               | protocol that would preserve privacy in the case of a log
               | breach, the one I sketched out just shows that (assuming
               | logs remain private and there's no collusion) that the
               | ARS doesn't need to know the user's identity and the AVS
               | doesn't need to know the ARS's identity in order to
               | validate the user's age.
        
           | wewxjfq wrote:
           | Age verification already works with the current digital IDs
           | and it's made in a way that doesn't leak your personal data.
           | In general you get to see what personal data is being
           | requested before you agree to transmit it. The IDs can also
           | create pseudonyms, so different systems don't know that you
           | are the same person.
           | 
           | I opted out of the digital functions of my ID, but I plan to
           | have them activated, because it's better than video
           | identification or uploading scans of my documents. That being
           | said, I hope that only serious processes will adopt this.
        
             | zeeZ wrote:
             | In the context of German ID cards, this is mostly correct.
             | 
             | For age verification requests, the service provider can set
             | the amount of years, and the ID card will simply answer
             | with a yes or no.
             | 
             | The pseudonym isn't created, but calculated from the ID's
             | private key and the service provider's public key, so even
             | a new card means new pseudonym, which makes it slightly
             | less useful for login long term.
        
         | ccbccccbbcccbb wrote:
         | You're being straight up realist here.
        
         | ekleraki wrote:
         | I live in Denmark, I have an "easyID" (NemID), along with a
         | social security number that allows me to connect to all
         | government websites. The system allows people to use physical
         | passcodes mailed to people, or send a push notification to
         | their phone, to trigger the NemID application to approve or
         | disapprove the entry.
         | 
         | As others have mentioned, similar stuff exist in other
         | countries as well.
         | 
         | So to me, I'd rather have a single common, shared and
         | opensource system for both Denmark, and all of EU.
        
         | Poppys wrote:
         | The problem of digital identity theft/fraudulent identities
         | exist very much, you can't get rid of crime by individuals or
         | nations. So it seems that this would be a solution.
         | 
         | Most EEA countries issue physical identity cards already, so a
         | digital one would seem a logical step.
         | 
         | Not that I don't disagree with the concerns about it.
        
       | nathias wrote:
       | this is bad because it will be useful and more web will be
       | KYC/AML compliant which serves nothing except surveillance
       | 
       | a good global ID system with zero knowledge is possible of
       | course, probably even with this system, but no goverment will
       | pass free up free control ...
        
       | sirnicolaz wrote:
       | Any hint on what technology they are going to use?
        
         | tagyro wrote:
         | It's based on [eIDAS](https://ec.europa.eu/cefdigital/wiki/disp
         | lay/CEFDIGITAL/2019...)
        
         | woodpanel wrote:
         | Since they mention trust and wallet all the time: Bet on a
         | government-run blockchain. What could go possibly wrong?
        
           | mordae wrote:
           | Wallet because European ID is a tabu.
        
         | mordae wrote:
         | As far as I remember, mostly COVID certificate tech. I don't
         | think the standards are done yet.
        
       | DocTomoe wrote:
       | This is not the first attempt to set something like this up in
       | the EU (in fact, the directive is some 10 years old), and it
       | won't be the last. In the end, it will die like all the projects
       | that come before it, because with 27 member states all having
       | different structures, the complexity will kill it.
        
         | happyweasel wrote:
         | I hope you're right on this
        
         | londons_explore wrote:
         | It will die because it's in Thales strong financial interests
         | to have it die a slow death with many contract revisions and
         | cost increases.
         | 
         | Source:. I have been in meetings where defence contractors
         | discuss how to corner the customer (the government) to force
         | them to pay for more work. Up to 300x the original contract
         | value over 7 revisions in one case!
        
           | ChuckNorris89 wrote:
           | Also, Thales is basically a sweatshop in Eastern Europe.
           | They'll charge the EU several times what the work is worth in
           | Western European dev wages, then nearshore the actual work in
           | their Eastern European offices. Similar to what IBM, Oracle
           | and other consultancies and bodyshops are doing.
           | 
           | I wish I was a Western European manager there. Make huge
           | wages without doing much work other than churn out PowerPoint
           | presentations to the tech illiterate C-suite and boss around
           | some Eastern European juniors.
        
         | snypox wrote:
         | The EU digital covid certificate works quite nicely and I used
         | it at multiple countries. This might be a bigger challange but
         | still.
        
           | fer wrote:
           | The EU covid certificate is nothing more than a signed piece
           | of data with a PKI behind, the complexities between that and
           | the eWallet proposal are orders of magnitude away.
        
         | mordae wrote:
         | It won't die this time. They are utilizing the momentum and
         | tech lessons from COVID passes. This is happening.
        
           | MonkeyClub wrote:
           | I'm of the same opinion, this is definitely happening,
           | nobody's asked whether they want it, it's just the next
           | necessary thing.
           | 
           | In theory, it's bad for "democracy". But I'm more worried
           | that social existence will necessitate a digital existence.
           | 
           | I'm connected, therefore I exist?
           | 
           | No way.
        
       | spinny wrote:
       | A very similar system has been in place in Portugal for some
       | time.
       | 
       | The Portuguese EU id card (probably like all other EU id cards)
       | can be used access multiple government web services. There is
       | also a mobile app to go along with it.
       | 
       | The card contains 2 tls certificates (rsa 2048 bits) and are pin
       | protected (signing operations).
       | 
       | One is used for authentication (there is a public api available
       | IIRC), the other is used for signing (that digital is considered
       | a legally binding signature)
       | 
       | Not sure about the mobile app but i assume the same functionality
       | without the inconvenience of owning a card reader
       | 
       | Vending machines that sell things for 18+ like smoking papers and
       | lighter are required to have a card reader to verify the buyer
       | age
        
         | sweden wrote:
         | The Portuguese implementation of this is quite poor and widely
         | unused. They started to improve it recently but nothing beats
         | the implementation of BankID in Sweden, it is definitely a
         | killer feature.
        
         | Avamander wrote:
         | > for authentication (there is a public api available IIRC)
         | 
         | If it's anything like what Estonia has had for ~10 years, it's
         | probably the usual mTLS for authentication.
         | 
         | You can also very likely use it anything that has smart
         | card/PKCS#11 support - that includes SSH, logging in to your
         | PC, and depending on the certificate S/MIME in Thunderbird or
         | Outlook.
         | 
         | > rsa 2048 bits
         | 
         | Curious choice.
        
           | spinny wrote:
           | And the cert chain on those is valid. i took a peek when i
           | got mine the certificates (at the time) were issued by a sub-
           | ca which by the name seems to be a gov entity and issue id
           | card certs only. don't remember which company owned the root
           | cert of the signing chain (it was a one of the common root
           | cert used by browsers)
           | 
           | The choice of rsa2048 is probably because of the card specs.
           | it couldn't handle 4096 keys (this was maybe 10+ years ago)
           | from what i've read at the time
        
           | upofadown wrote:
           | 2048 bit RSA is probably the most conservative choice
           | available at this point in time. For a thing like that you
           | want conservative.
        
       | Proven wrote:
        
       | dariosalvi78 wrote:
       | this is excellent news and I hope they will do it right (reliable
       | technologies, secure, privacy-minded etc.). I need to deal with
       | public administration in 3 EU countries and managing 3 different
       | byzantine digital IDs is a pain in the ...
       | 
       | Of course many people here will scream at "government control"
       | and "dictatorship", while happily sharing all their lives with
       | unaccountable US corporations.
        
       ___________________________________________________________________
       (page generated 2022-06-30 23:03 UTC)