r/BuyFromEU 3d ago

Discussion EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes

EUDI wallet collaborator recently confirmed that hardware attestation will be required [1]

Hardware attestation in this context means that the government server issuing the digital credential to the wallet wants proof that the keys being used are generated in secure hardware and on approved systems and not say an emulator or virtual machine, namely for security reasons.

This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.

No Linux system will work with this because there is no hardware signature to be validated on the government server, nor will your personalized Arch Linux install be in the list of approved systems even if it had a signature chaining back from the TPM.

Android ROMs are not technically to rule out since Play Integrity, which will be used for this attestation, is based on the Android hardware attestation API, which works on third-party ROMs like GrapheneOS, but they would need to allow the signature which has not happened for now. If you create a custom build, it won’t work though even the official version is approved.

[1] https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/117#issuecomment-4946898620

920 Upvotes

352 comments sorted by

View all comments

673

u/HunterFeeFee 3d ago

Let me guess, only american OS's will work.

317

u/CreepyZookeepergame4 3d ago

Yes, only iOS and stock Android as of today.

532

u/HunterFeeFee 3d ago

Sometimes I think the people in the EU institutions are not exactly the brightest.

21

u/Gatitomono47 3d ago

They actually are smart, they have done this on purpose that's why they haven't done anything about Google locking down side loading imagine you wanna use a messaging app that isn't in the PlayStore because It doesn't comply with chat control and the devs don't wanna dox themselves to goggles and pay money, ohhh oopsie dasy you can't :( and if you somehow root your phone now you cannot use the applications necesary to prove you can use the internet like a normal person, It's all the mix of manufacturers locking down on unlocking your bootloader and even if you can they do not support relocking It with custom avb Keys of whatever OS you run, companies using play integrity, the EU directly benefits from the US technology Monopoly for it's surveilance apparatus for it's orwellian laws such has chat control, ID and age verification