logoalt Hacker News

mytailorisrichyesterday at 10:52 AM3 repliesview on HN

Yes all that you wrote is true. But that does not magically change anything to what I previously stated: in the real world all smartphones are either Apple or Android...

I don't know what the eIDAS 2.0 requires in term of security but it may make the choice the implementers made here unavoidable in practice, as hinted by @webhamster.

If so, it seems that a solution, if technically possible, might be to mandate that OSes provide the required security features without tie-in.

The outrage in the comments feels a bit like people yelling at clouds...


Replies

Hackbratenyesterday at 2:59 PM

> in the real world all smartphones are either Apple or Android...

So you're claiming that Mobian doesn't exist? PureOS doesn't exist? PostmarketOS doesn't exist? Ubuntu Touch doesn't exist? SailfishOS doesn't exist?

show 1 reply
taotauyesterday at 12:21 PM

correction. in the real world all smartphones are either apple, android or none/other. in terms of legals, you really do have to cater to all three, which is why we don't have one world government.

show 1 reply
jonathanstrangeyesterday at 3:15 PM

Essential EU government services cannot be devised on the hope that US companies will invent something that - contrary to current US legislation - will somehow provide the attestation services needed in a GDPR-compliant way without forcing EU citizens to provide personal data to US companies.

If it's not possible to create such a system for mobile phones because of legal issues (as you seem to acknowledge and judges have found in the past), then the focus would have to be on creating hardware devices in the EU, ideally with open source hardware and software. These can be made reasonably secure, have been used by banks for a long time, and would enhance digital sovereignty.

What I find unacceptable is the attitude "well, it will violate the law but as a matter of practicality it's the only choice we have right now so we'll just do it."

show 1 reply