logoalt Hacker News

mradalberttoday at 8:20 AM3 repliesview on HN

Look at reference implementation. Maintainers resist removing google dependency for no good apparent reason. An if there is persistence without reason - there is a reason.

https://github.com/eu-digital-identity-wallet/eudi-app-andro...


Replies

darcciotoday at 11:03 AM

I don't feel they resist. Quoting them:

> We understand your concerns and truly appreciate your suggestions. As previously mentioned, this is not something that is enforced by the reference implementation — these are simply recommendations, not requirements, for any wallet implementer. That said, we recognize that this is a sensitive topic, and we may need to revisit it, even at the level of recommendations.

> The README files for both the iOS and Android Wallets have been updated to mention only OWASP MASVS compliance, without referencing any specific APIs.

I understand their position, but I also get the concern, especially around existing implementations like the Italian app. I think it's mostly that they have different priorities than ensuring that the reference implementation is a perfect guideline for member states.

This looks like a good vector for a European Citizen Initiative around removing all technological dependency on non-EU providers.

show 1 reply
stingraycharlestoday at 8:57 AM

Why would this be? Bureaucracy / inability to change?

show 3 replies
michaelttoday at 11:04 AM

Operate European tech infrastructure without a dependency on America challenge (Impossible)

For 99% of smartphone users, you can't get apps onto their phones without Apple and Google signing the app and letting you into their store, and users can't install the app without an Apple/Google account.

Why remove a dependency on Google, when you'll still be 100% dependent on Google?

Anybody working on "Digital ID" has already made peace with the fact that it can be turned off overnight if Trump says so.

show 6 replies