Elektrine lite

← Feed

@lumi@snug.moe

Post #2843601

2026-02-21 14:20 UTC

@fruitchypear@owo.cafe @greatlaketrout@noc.social @IvanSanchez@mastodon.social @jdelacueva@mastodon.social @EUCommission@ec.social-network.europa.eu requiring drm for a digital identity wallet... yikes ​:neocat_facepalm:​ apps attesting the hardware and software they run on is fundamentally drm and is awful. it's also just completely backwards, apps shouldn't even have the capability to do that the os should be attesting this, not the apps

Replies (4)

  • @riley@toot.cat 2026-02-21 17:09

    @lumi@snug.moe Pretending that this is a good use for DRM has been a grift thirty years in the making. :blobcatsad: https://web.archive.org/web/20141129042827/https://www-03.ibm.com/press/us/en/pressrelease/2016.wss @jdelacueva@mastodon.social @IvanSanchez@mastodon.social @EUCommission@ec.social-network.europa.eu @fruitchypear@owo.cafe @greatlaketrout@noc.social

    Open ##2843602

  • @asltf@berlin.social 2026-02-22 16:10

    @lumi@snug.moe @jdelacueva@mastodon.social @IvanSanchez@mastodon.social @EUCommission@ec.social-network.europa.eu @fruitchypear@owo.cafe @greatlaketrout@noc.social thas has nothing to do with "drm" It is there because remote service needs assertion, your generated private key is bound to your device and can't be copied to another phone. And to assert that, a trusted party (google/Apple) asserts the complete chain from hardware up to the os it is ronning on - so no MITM sits within. Currently there is no other way, other than not using mobile os's https://berlin.social/@asltf/116104851486148728

    Open ##2843603

  • @yacc143@mastodon.social 2026-03-01 17:50

    @lumi@snug.moe @jdelacueva@mastodon.social @IvanSanchez@mastodon.social @EUCommission@ec.social-network.europa.eu @fruitchypear@owo.cafe @greatlaketrout@noc.social If it was the apps it would okay, but it is literally the hardware & OS in cooperation with a 3rd party that is doing the attestation, on behalf of the app. And you cannot even argue that PCs are “less safe”; Microsoft & Apple have quietly added game console-level security to their ecosystems in the past decade.

    Open ##2843629

  • @grepe@ieji.de 2026-06-09 12:34

    @lumi@snug.moe @jdelacueva@mastodon.social @IvanSanchez@mastodon.social @EUCommission@ec.social-network.europa.eu @fruitchypear@owo.cafe @greatlaketrout@noc.social i agree this is bad. government infrastructure should not be locked into a private vendor. but i do not agree with the stance in principle... just because the system can run an app it doesn't mean it should. we learned that lesson when logging into secure services on shady internet cafe computers... something like your banking app or, indeed, ID wallet might want to set some conditions on where you can use it to prevent possible abuse. that being said, the condition absolutely shouldn't be "we can only run in a place where a foreign private entity can track you".

    Open ##3226702