Post #3526662
2026-07-01 05:45 UTC
Replies (2)
-
@mindaugas@mastodon.0011.lt 2026-07-01 10:22
@karmalakas@mastodon.social @anthroposamu@mastodon.social @digitaleu@ec.social-network.europa.eu 1) EU is a big ship, and no one has enough power to quickly change course of this big wallet project, or those who can change, don't take responsibility, or likely don't know the solution, and don't care enough. 2) Important problem: solution is not clear. Article says these things for a solution: „We do have a choice. A more open alternative to Google Play Integrity exists but is being ignored: Android's Hardware Attestation API. It provides hardware-based security checks but without enforcing Google’s ecosystem policy. “ - „EU [...] mandate open, hardware-based attestation mechanisms“. - „User [...] contact the developers of your country's EUDI Wallet app and demand independence from Google and Apple attestation (for the Dutch wallet, go to the contact page of the Ministry of Foreign Affairs' EDI website)“ - „citizen [...] contact your elected representatives to demand making ID wallets independent from Google and Apple.“ - „journalist [...] follow the political and design process.“ The most problematic question is technical side. Fediverse is a place of technologists, we suppose to be better informed. I myself don't understand solution clearly yet. I see solution rarely being talked about. If we don't understand it, why we suppose the government should understand what to do exactly. The best and thorough technical article I have seen is from GrapheneOS: https://grapheneos.org/articles/attestation-compatibility-guide Who claim: "Android's hardware attestation API provides a much stronger form of attestation than the Play Integrity API with the ability to whitelist the keys of alternate operating systems. It also avoids an unnecessary dependency on Google Play services and Google's Play Integrity servers." But it looks like GrapheneOS specific with all those keys. And what technical solutions does @e_mydata@mastodon.social @murena@mastodon.social @gael@mastodon.social promote in their articles? /e/OS have most influence and stake in the game, because were funded by EU. Some idea: /e/foundation could follow such posts on fediverse and point to their solution (but right now I am unaware they have one 🤷🏻 yet). GrapheneOS is super secure, and they often claim /e/OS is not https://eylenburg.github.io/android_comparison.htm. Is /e/OS up to the task to begin with to ensure its OS integrity? If I have those questions, why the government would not? Good idea may be to spread the knowledge and improve common knowledge of the fediverse technical people on what the technical solution is, so to have more clarity, and be able more clearly advocate the governments on what can be done.
-
@gytisrepecka@social.gyt.is 2026-07-01 11:18
@karmalakas@mastodon.social I wouldn't be surprised if Google and Apple lobbyists are walking corridors of EU government bodies and convincing to stick to their "easy to use and very secure" attestation solutions, because, you know, "we are all working for safety of the children!" :blobcatrollingeyes: @anthroposamu@mastodon.social @digitaleu@ec.social-network.europa.eu