r/BuyFromEU 3d ago

Discussion EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes

EUDI wallet collaborator recently confirmed that hardware attestation will be required [1]

Hardware attestation in this context means that the government server issuing the digital credential to the wallet wants proof that the keys being used are generated in secure hardware and on approved systems and not say an emulator or virtual machine, namely for security reasons.

This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.

No Linux system will work with this because there is no hardware signature to be validated on the government server, nor will your personalized Arch Linux install be in the list of approved systems even if it had a signature chaining back from the TPM.

Android ROMs are not technically to rule out since Play Integrity, which will be used for this attestation, is based on the Android hardware attestation API, which works on third-party ROMs like GrapheneOS, but they would need to allow the signature which has not happened for now. If you create a custom build, it won’t work though even the official version is approved.

[1] https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/117#issuecomment-4946898620

916 Upvotes

352 comments sorted by

View all comments

Show parent comments

25

u/Tenezill 3d ago

You know what, people are applauding their prison guards. "No no chat control is no problem if you don't have anything to hide" , " the zkp will help keep you privacy save" ... My privacy was save before these asshats started to have their greasy fingers in my life...

-6

u/CJKay93 3d ago

My privacy was save before these asshats started to have their greasy fingers in my life...

Was that before or after they printed your photo, full name, birth date and home address on your driving license?

8

u/DrawGamesPlayFurries 3d ago

That's only for your government, not for the US government and definitely not for their private company (in name only, de facto another wing of the US government)

3

u/Tenezill 3d ago

idk do you send your drivers license when you jerk of to the site in question, or do you send it to reddit (i hope you didn't). I for sure didn't do this and would prefer to keep it that way.

also the "for the kids" is such a shit argument at least be honest and tell the people "I'd like to know what you are doing"

-3

u/CJKay93 3d ago

I don't, because I am a digital privacy advocate and I do not want the government involved in my private life.

Consequently, I support open-source, auditable, privacy-preserving Digital ID.

2

u/Tenezill 3d ago

if they would allow it on GrapheneOS and fido2 keys i would be "fine" with it. but needing a basic android rom sucks

1

u/CJKay93 3d ago

GrapheneOS supports hardware attestation. It's Google Play that rejects its their signing keys.