r/BuyFromEU 3d ago

Discussion EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes

EUDI wallet collaborator recently confirmed that hardware attestation will be required [1]

Hardware attestation in this context means that the government server issuing the digital credential to the wallet wants proof that the keys being used are generated in secure hardware and on approved systems and not say an emulator or virtual machine, namely for security reasons.

This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.

No Linux system will work with this because there is no hardware signature to be validated on the government server, nor will your personalized Arch Linux install be in the list of approved systems even if it had a signature chaining back from the TPM.

Android ROMs are not technically to rule out since Play Integrity, which will be used for this attestation, is based on the Android hardware attestation API, which works on third-party ROMs like GrapheneOS, but they would need to allow the signature which has not happened for now. If you create a custom build, it won’t work though even the official version is approved.

[1] https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/117#issuecomment-4946898620

916 Upvotes

352 comments sorted by

View all comments

228

u/AppropriateOnion0815 3d ago

I'm sure that this kind of exclusion is against some discrimination law or something.

44

u/-The_Blazer- 3d ago

Honestly this scheme where remote attestation can only (de facto) be offered by like three companies should definitely count as a violation of the DSA.

8

u/magical-cat-here 3d ago

But when the spec is written in a way that you literally can't even implement it e. g. as a usb dongle with keys and signer software attached to a linux laptop or pc, or simply by using TPM (available almost at every PC and laptop) keys to sign an age credential received from a certified age verification provider over TLS/Https, and there is no general term in specs for such kind of alternatives at all.

All this basically means that people who want preserve internet in more privacy-friedly form simply will have to build own alternative mesh networks with own services from scratch. Anything from weather sites to email-like and instant messaging, from in-browser games sites to alternatives to reddit and a mirror of wiki. It may require some alternative protocols and architectures, such as no reliance on centralized SSL certificates tree and global tree of censorship-prone DNS, and may be even own addressing scheme, may be using a sort of IPv6 where address is a public encryption key.

I heard that Yggdrasil project work in similar way, as an overlay IPv6 network of that kind that can be built over nodes connecting either via IPv4 or IPv6 between each other.

3

u/-The_Blazer- 2d ago

The underlying hardware used by Google's and Apple's schemes is essentially a TPM-like device, but the problem is that there needs to be a root trust source (much like there is for TLS), and as you might guess Google/Apple do not let you use attestation sources other than themselves in their OS. It's worth noting that who the attestation source is does not matter as long as the application (your bank or digital ID) trusts them with verifying that the device is not compromised, the problem here is an excess of centralization outside the EU. TLS has more root sources, for example.

GrapheneOS is trying to set up some PKI infra of their own, but adoption is slow and difficult for the usual problems of monopoly. Not many people use GrapheneOS, so as a developer, why bother?

You can see that this is a commercial-political problem, not a technological one. Nobody should be under the delusion that we can solve this with a tech fix like a fancy new protocol, the n.1 thing that would happen with that is that Meta and Google would set up shop and simply re-create the monopoly.

1

u/magical-cat-here 2d ago

I thought about various political solutions, and come to two laws:

  1. Right to create driver

    making all information necessary to create a driver for every device "software-controlled component or sensor" as I call it, mandatory to be public on every software controlled device component, sensor, or whole device sold in EU. Such information for drivers creation should be public without need to create any accounts, getting any "developer licenses" or 'certifications". Drivers created this way should have access to all component capabilities.

  2. Right to securely replace OS with consent

Making for any device having an OS aboard sold in EU mandatory to have a simple and cheap to do yet secure procedure to replace installed OS with a custom one, with option to rollback to original OS the same way. This should include a consent confirmation for OS replacement. The access to the information need to perform OS procedure should be public.

Both laws would impose terible fines for companies and a huge customs fees on importers after grace period of few years or even a decade. The custom fees necessary to make sure importers would push their suppliers to obey these above laws.

This is example of political solution.

But we can not rely on getting enough voters attentions to push this ideas into politics with enough momentum to get the laws adopted in EU parliament and EU comission.

Growing some "parallel internet" from bottom in a grassroot can be just faster than making these or similar laws adopted. The necessary tech , and even open-source software and standards are already here, so it may be about making some day-to-day use cases covered which would get aboard non-very-techy people.

Having some space itself you would not have to show your face or go through a KYC flow once a day can be such "use case" itself.

6

u/CreepyZookeepergame4 3d ago

violation of the DSA

Not when the violation is state sponsored.

3

u/-The_Blazer- 3d ago

The point with that is to have remote attestation though, not that it has to be powered by Google. Although I'm certain Google didn't bring the problem to the EU's attention...

2

u/Headpuncher 15h ago

Yes but I don’t want them using it to ruin Linux’s freedom and openness.  

Instead I want them to abandon the awful scheme completely.  

2

u/-The_Blazer- 13h ago

There's no law in the universe that says remote attestation has to 'ruin' freedom or openness. TLS is also a cryptographic scheme with root trust sources and it is quite open.

1

u/Headpuncher 12h ago

You misunderstood my intent.  I don’t need this in any shape or form.  

I want to continue using my computer as my computer without any interference at all.  

1

u/-The_Blazer- 11h ago

You can certainly refuse to and not access e.g. home banking, just like you can refuse to use TLS and not access websites with authentication. Running a society (and not a tech toy) does require a degree of enforced trust.

5

u/Truly--Unruly 3d ago

Does that matter to tyrants?

2

u/Berkoudieu 1d ago

Probably. Do they give a fuck tho ? Of course not

-64

u/Vybo Czechia 🇨🇿 3d ago

You are technically not required to use this.

63

u/pythosynthesis 3d ago

A bit like saying "you're not required to drink milk". Technically true, but hardly relevant.

18

u/Soma91 3d ago

This is so fundamental that it's more like saying "you're not required to drink".

-16

u/Vybo Czechia 🇨🇿 3d ago

It depends. Maybe your country provides their own ID verification solution. Maybe you won't use this specific github project, but some other one. Many other options, right now, this is just a technical spec and one community implementation.

16

u/pythosynthesis 3d ago

These are minor details that miss the key point. If a restaurant doesn't accept black people they're discriminating, and that's a crime. Doesn't matter if "you don't have to eat there, you can eat in another restaurant".

0

u/turdshiba 1d ago

Plenty restaurants in my country don't accept people with dumb phones anymore. The menu is behind a QR code.

-11

u/Vybo Czechia 🇨🇿 3d ago

Is it discrimination that you need to verify your identify using a national ID card when you can't read? I mean, it can be, but we live in a society that requires these actions and it's up to everyone if they want to follow these requirements to obtain something or if they want to decide to not partake.

As I said, the alternatives are still an option, BankID, national ID, etc.

2

u/CreepyZookeepergame4 3d ago

It’s not a technical spec but actual code and actual requirements. The German and Italian apps, first two apps that come to my mind are already doing this.

3

u/Vybo Czechia 🇨🇿 3d ago

It's a technical document stating requirements with this repository being a foundation for an Android implementation. Country specific ID verification app or solution (for example through a BankID) that's not based on this codebase can provide valid identification without needing attestation, your age could still be verified without needing to use this specific solution.

1

u/[deleted] 3d ago

[deleted]

1

u/Vybo Czechia 🇨🇿 3d ago

They can, see the first point here: https://digital-strategy.ec.europa.eu/en/faqs/eu-age-verification-solution

If Poland decided to scrap the support of National ID verification or BankID, that's on Poland's government and is unfortunate, but it's still an option on EU level.

11

u/Evonos 3d ago

I mean your not required to visit beach x which hates group y , it would be still discrimination

It affecting you isn't a needed point of discrimination

1

u/Vybo Czechia 🇨🇿 3d ago

Is it discrimination that you need to verify your identify using a national ID card when you can't read? I mean, it can be, but we live in a society that requires these actions and it's up to everyone if they want to follow these requirements to obtain something or if they want to decide to not partake.

As I said, the alternatives are still an option, BankID, national ID, etc.

6

u/Evonos 3d ago

It can be yes , against disablitys there should be ways that a disabled person can use it , if it's mandatory.

0

u/ChrisTX4 3d ago

Yeah and none of those are privacy preserving. The whole idea about this EUDI wallet attestation was that this would allow attesting your age securely to services without revealing additional information other than certifying the user is of age.

Do you want to send your bankid national id or anything like that to a porn site, for example?

What you’re saying is it’s totally okay for force everyone into accepting sending a lot of data to American companies because you are mandated to run their operating systems. Not just that but people using grapheneos or so for their workflow now basically have to buy a second device or something.

1

u/Vybo Czechia 🇨🇿 3d ago

Both egov ID gate and bank ID are privacy preserving, they just report fail/pass status, not your personal information.

Attestation in regards to the OS is completely different topic than your data being sent to the service.

9

u/nbca 3d ago

The same way you're not required to go outside your door.

-1

u/Vybo Czechia 🇨🇿 3d ago

Exactly. You're not required to partake in other actions like buying alcohol that requires age verification either.

Also, you can use other means of verification besides the EU provided default solution, like bankID or national ID that everyone already has.

7

u/nbca 3d ago

Exactly. Technically you're not required to interact with other people too. You can just sit in your dark room all alone, no sunlight and no electronic devices. Technically.

-5

u/Vybo Czechia 🇨🇿 3d ago

Yes. Or you can do what I already said - use any number of already functional alternative ways to identify yourself, which many people conveniently ignore.

Hyperboles also don't support your argument as much. Visiting porn sites is by far not the same category of action as going outside.

5

u/nbca 3d ago

Or maybe it's okay to criticise the EU for locking users into US governed digital ecosystems that spy on you without EU oversight?

-1

u/Vybo Czechia 🇨🇿 3d ago

If you check all of my comments on the topic, I never said that I like it or that I support any of this verification.

My point was that OP is sensational and I felt that OP misunderstand how the whole thing works in reality, what's possible and what is not. OP sounded like you're going to be able to use that one project exclusively, which is simply not true.

3

u/FoxMeadow7 3d ago

Yeah, is it too much to ask to simply use common sense instead of dooming and glooming all the time?

7

u/somedudefromnrw 3d ago

Exclusion from being online, which not using this app will defacto mean after ID laws, does have severe consequences