← Back to context

Comment by jonathanstrange

12 hours ago

We're talking about an essential government service, not just another weather app. You have to look at this through the lense of national security, the debate about EU digital sovereignty, and the requirements of the GDPR in light of the US CLOUD Act, as well as prior decisions of EU courts about these issues.

Yes all that you wrote is true. But that does not magically change anything to what I previously stated: in the real world all smartphones are either Apple or Android...

I don't know what the eIDAS 2.0 requires in term of security but it may make the choice the implementers made here unavoidable in practice, as hinted by @webhamster.

If so, it seems that a solution, if technically possible, might be to mandate that OSes provide the required security features without tie-in.

The outrage in the comments feels a bit like people yelling at clouds...

  • > in the real world all smartphones are either Apple or Android...

    So you're claiming that Mobian doesn't exist? PureOS doesn't exist? PostmarketOS doesn't exist? Ubuntu Touch doesn't exist? SailfishOS doesn't exist?

    • Don't be disingenuous. All of what you mention are rounding errors in term of market share.

      This discussion feels unreal, really.

  • correction. in the real world all smartphones are either apple, android or none/other. in terms of legals, you really do have to cater to all three, which is why we don't have one world government.

    • This is about a digital wallet, so people who don't have a smartphone are out of scope.

      Now, "other" than Apple/Android is so small as to be negligible and governments also have a duty not to waste taxpayers' money, which means not spending hundreds of thousands to cater for an ultra small number of people who have an easy access to an alternative.

      To have government apps work only on iOS and Android is perfectly reasonable in the current state of the world where this covers 99% of smartphones.

      2 replies →

  • Essential EU government services cannot be devised on the hope that US companies will invent something that - contrary to current US legislation - will somehow provide the attestation services needed in a GDPR-compliant way without forcing EU citizens to provide personal data to US companies.

    If it's not possible to create such a system for mobile phones because of legal issues (as you seem to acknowledge and judges have found in the past), then the focus would have to be on creating hardware devices in the EU, ideally with open source hardware and software. These can be made reasonably secure, have been used by banks for a long time, and would enhance digital sovereignty.

    What I find unacceptable is the attitude "well, it will violate the law but as a matter of practicality it's the only choice we have right now so we'll just do it."

    • > Essential EU government services cannot be devised on the hope that US companies...

      I don't disagree. I am just pointing out that this is wishful thinking right now.

      As said, Europe has zero footprint in hardware or software so the choice is either not to develop any digital services or to accept that they will run of foreign hardware/software because everything is either Android or Apple and runs on hardware that is from US/Taiwan/China.

      Developping honegrown alternives is pie in the sky or a 20 year project if we are optimistic (which I am not)...

      Frankly, many comments, and the reactions to mine, show how out of touch and idealistic or naive the HN crowd can be.