blop
6 days ago
This is the elephant in the room regarding the big "digital sovereignty" talks in the EU. For the moment in the EU institutions the focus is mostly at the post-acceptance stage that everything must eventually migrate off US clouds. There is still some denial and hope that things will go back to "before" because it's going to be extremely costly to migrate, but at least high level EU civil servants start to see the strategic value of moving out.
However there is ZERO talk about mobile platforms... No alternative solution like linux for the desktop, no money or care given to the few alternative that tentatively exist, and zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU.
So whilst the backend guys more or less got the memo about sovereignty, I think there is still a lot of educational work to do regarding end user devices and what kind of digital slavery hole we're digging ourselves in...
zoobab
5 days ago
"zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU."
Complete public datasheets on how to program the hardware should be a requirement fit a DMA2.0.
omnimus
6 days ago
This is not entirely true. I don't have much details but I know people who started to work on two separate free software projects aiming to make supported mobile OS. These projects couldn't get funding before but they do now. Afaik it's still a battle with AI companies lobbying that soverign AI is much more important than mobile OS but there is some growing interest. Imho i don't even think some linux based alternative to Android would be that hard to pull off but it's the hw companies that will be skeptical to build hw for such OS. I would have to be some govs puahing it as secure gov devices first.
AnthonyMouse
6 days ago
Which is all well and good, but who is going to use those projects if the law requires them to use Android or iOS for age verification?
izacus
6 days ago
"The law" requires no such thing and there's nothing preventing those new OSes form providing proper security signals.
But is DOES require work - and it's much easier to complain than to put in work.
AnthonyMouse
5 days ago
> "The law" requires no such thing
It requires age verification and provides code whose development was subsidized by the government, which third parties the user doesn't control will use, that creates a dependency on those platforms.
> there's nothing preventing those new OSes form providing proper security signals.
A network effect, far from being nothing, is a barrier the height of a mountain.
The purpose of attestation is to lock out competing platforms. It security value is a joke. Devices pass attestation with known vulnerabilities and fail it for being competitors, even if the competitors have better security.
Offering to make attestations nobody accepts is a farce. The problem to be solved is how to run existing software that was originally written for other platforms when the new platform is new and doesn't have enough users for third party developers to specifically target it, which is the exact thing that can't do. And without that it can't get enough users for third party developers to specifically target it.
izacus
5 days ago
> The purpose of attestation is to lock out competing platforms. It security value is a joke.
This is kind of your... opinion man.
In reality pretty much all security sensitive applications require attestation from their side.
AnthonyMouse
5 days ago
And what security value does that provide, when millions of attestation-passing devices have public unpatched LPE vulnerabilities? Anyone can get one and run arbitrary code on it as root. It's completely worthless for actual security. Worse, it does the opposite, because a newer third party ROM that patches those vulnerabilities would fail attestation, preventing honest users from updating their device and thereby leaving them vulnerable.
What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.
roundabout-host
5 days ago
It requires a government-authorised "age verification" "app", but it does not require that it is accessible through standard protocols, so that it can work on any platform. In practice, the governments will only make it available for Android and iOS. Plus, you cannot have a free OS providing "attestation"; "attestation" is incompatible with root access and modifying the OS.
hnisnotbenign
6 days ago
Yes, it is much easier to ignore the unelected bureaucrats than to jump through their ridiculous hoops.
UqWBcuFx6NV4r
6 days ago
See, you’re just saying what they’re saying, but with emotive, thought-terminating language. Again, it’s easier to complain. Have you been living under a rock for your entire life? Have never ever been involved in a decision being made about certain “blessed” vendors, and the decision is being made for legitimate technical reasons, not “ridiculous” ones.
If you’re the sort of person that’s unable to distinguish between something that’s legitimately unjustifiable/ridiculous, and something that just upsets you, then you do you, but don’t bring this here pretending that it suffices as a discussion, because it doesn’t.
hnisnotbenign
6 days ago
What?
omnimus
5 days ago
I think the asumption being if there is gov backed mobile OS govs would also support their app ecosystem there. That's kinda the point of funding alternative free mobile OS?
mghackerlady
6 days ago
They could try and put money into funding Jolla/sailfish/whatever
tokai
6 days ago
That wont help anything. Then you are just force to use Android, iOS, or Sailfish. It need to be a platform agnostic thing, else you're just hitching the fulcrum of civil society on private company.
roundabout-host
5 days ago
Exactly. The app is only inclusive if it is accessible over a standard protocol (Web) without "attestation", so that it works for any platform. If I release a GNU/Linux distribution tomorrow, I should be able to use the app on it with only some work on my part.
pjmlp
2 days ago
You mean ChromeOS Platform.
mghackerlady
5 days ago
I don't disagree, but the eu needs their own mobile OS alternative in general so if they absolutely need to rely on a private company, it isn't an american one
account42
5 days ago
This doesn't follow. Why is public infrastructure no longer a possibility as soon as computers get involved? We aren't talking about cutting edge innovation here anymore, mobile phones are boring standard devices.
mghackerlady
5 days ago
It is a possibility, just not one I see as likely to happen. Could the EU fund a public phone company? Probably. Will it happen? Most likely not
izacus
6 days ago
Private companies providing public services is really not a rare thing.
pessimizer
6 days ago
Who do you think said it was?
mytailorisrich
6 days ago
Because this is all a political move. This so-called "EU sovereignty" drive is in fact aimed at further reducing sovereignty of the member states via further transfer of power and control to the EU.
These digital ID wallets do exactly that. Member states lose control of the ID infrastructure, which will now be controlled by the EU. There isn't much sovereignty left at national level...
reloadtak
6 days ago
Each member state has to implement the system themselves. Where is the loss of control?
AnthonyMouse
6 days ago
The US federal government has been doing that to the states for a while now. They don't have the constitutional authority to do something, so instead they shove a lever under something they nominally are allowed to do and tell the states "do the thing we're not allowed to, the way we tell you to, or else." Where the "or else" is something like, they collect billions of tax dollars from your constituents that you then can't use to provide them with services, and return them to only the states that bend the knee.
(The US constitution originally required federal taxes to be apportioned for exactly that reason.)
izacus
6 days ago
This isn't how EU works though (EU can actually directly order states arouns :P), so I'm not sure how that's relevant here?
AnthonyMouse
6 days ago
That doesn't appear to be accurate:
https://citizens-initiative.europa.eu/faq-eu-competences-and...
Moreover, it's ignoring the context of the thread. The relevance is obviously that coercing someone to do something against their will and then saying they're still in charge because they're the ones doing it is a sham.
izacus
5 days ago
Can you highlight what part of that FAQ doesn't make it accurate? EU directives are a thing.
AnthonyMouse
5 days ago
US federal laws are also a thing. In both cases, they're supposed to be limited to specific categories.
In the EU this appears to be classified into "exclusive", "shared" and "support" "competencies":
> the EU has competence to support, coordinate or supplement the actions of the Member States (article 6 TFEU) – in these areas, the EU may not adopt legally binding acts that require the Member States to harmonise their laws and regulations.
So for example, one of the areas in that category is industry.
The common trick to look out for in cases like that is that when they want to regulate something like "industry" they instead categorize the rules as something else, e.g. the US infamously regulates non-interstate non-commerce as "interstate commerce".
blackqueeriroh
5 days ago
Please provide examples, because this sounds highly speculative, and also straight up incorrect!
optimalquiet
5 days ago
A major example is the US drinking age. Federal highway funds, which provide money for interstate highways, major US routes, etc, are partially contingent on states (who are given authority over alcohol laws both by the general police power and the 21st Amendment) setting the minimum age for the legal purchase of alcohol at 21. The National Minimum Drinking Age Act withheld 10 percent of highway funds from states that didn't comply. The fact that it wasn't 100% let the Supreme Court allow it to slide, but eventually all the states did comply, and effectively the US has a drinking age set by the Federal government instead of the states even though the states technically have the power to set an age themselves.
The Federal government using the withholding of funds to get the states to do what it wants is a well-documented phenomenon.
AnthonyMouse
5 days ago
As an obvious example, regulating education isn't one of the enumerated powers of the US federal government, but there are numerous -- often controversial (e.g. NCLB) -- federal laws that take tax revenue from every state's constituents and return it to the state only if they comply with federal requirements the federal government has no power to impose on its own.
mytailorisrich
6 days ago
Where is control in being mandated to implement and EU-wide, EU-defined system? This is a net loss.
My previous comment should be taken in its entirety. The loss of sovereignty of individual countries is comprehensive across all domains and this is just one brick in the wall.
This is nothing new, this is what "European integration" means. I wanted to point out the very newspeak-esque use of the term "sovereignty" in Europe at the moment.
reloadtak
4 days ago
The spec/design leaves a lot for the member states to decide on their own. You do understand how the EU and the member states roles work?
I would think the idea is to make services and ID documents more uniform across the union. I don’t see what the individual members state lose here? Apart from the cost of implementation. The individual EU citizen would seem to benefit from standardized documents accepted by all companies and governments, do you disagree?
joe_mamba
6 days ago
This is totally not the EU version of China's social credit score system and WeChat SSO system.
It will totally not be used to sanction you the moment you become a nuisance to the EU elites by saying "wrong speech" that goes against their mandated doctrine or pointing out their acts of corruption or dismantling of democracy.
The EU building in Brussels even has the word "DEMOCRACY" plastered on the front in large bold letters[1], in case you forgot.
[1] https://audiovisual.ec.europa.eu/en/media/photo/P-069521
wolvesechoes
4 days ago
"This is the elephant in the room regarding the big "digital sovereignty" talks in the EU"
The elephant in the room is that it is just talk, as always in case of EU.
pjmlp
2 days ago
Yes, spot on, the talk is always around Office and co.
JodieBenitez
5 days ago
The sovereignty thing is a theater. Many french unis use Google cloud because they're broke and can't maintain in-house services, and none gives a damn.
cbg0
6 days ago
Isn't AOSP a thing?
jchw
6 days ago
This app requires Google Play. AOSP alone won't cut it.
roundabout-host
6 days ago
In fact, it requires attestation: even if you install Google Play on some Android in an emulator/container/VM, on an alternative Android distro or in a rooted device, the app will not accept it.
literalAardvark
5 days ago
Wth. Does it at least have the decency to use aosp attestation? Or are they just happy to give the keys to the kingdom to Google and require Play Protect?
izacus
5 days ago
How would you "use AOSP attestation"?
The point is that the signatures are compared against a database of certified builds - and that exists on Google servers.
If you want AOSP attestation, you need to build your own database to compare against.
literalAardvark
5 days ago
https://grapheneos.org/articles/attestation-compatibility-gu...
It exists on Google's servers for lock in reasons alone.
izacus
5 days ago
GrapheneOS guy went on a very extensive rant on Mastodon when someone wanted to create an independent, European, list that could be used by apps to verify attestation. They want apps to hardcode theirs specifically.
Which makes sense for them - after all, that makes their competitors break and their ROM doens't.
roundabout-host
5 days ago
Even with the "independent European" list, you would still be unable to use a custom OS not in it.
roundabout-host
5 days ago
Even if they did that, it would not be OK. Free software is no longer free if it has to be on a list.
notabotiswear
6 days ago
Writings on the wall can’t be clearer on AOSP’s future…
snottynose
6 days ago
It is true that Google (de facto) controls the platform and made themselves (de facto) essential to utilizing the platform by integrating their proprietary services so deeply into the OS that you need to be a behemoth of Samsungs caliber to even attempt to meaningfully re-purpose the AOSP, and this was a brilliant strategy because it has allowed Google to solidify their spot in the duopoly / oligarchy while seeming "open". But. I do believe that Google will continue to publish the AOSP source code under a permissive license and that this code will be indispensible to a European Manhattan project for tech sovereignty, should policymakers ever see the light.
notabotiswear
6 days ago
Have to throw in this 13 year old Ars Technica article as a follow up:
https://arstechnica.com/gadgets/2018/07/googles-iron-grip-on...
Still amazes me how everyone isn't cynical-by-default about anything Google (or big tech in general) open-sources yet...
hnisnotbenign
6 days ago
Yes, I remember feeling that way in 1995-2005 about Microsoft. Imagine my surprise to learn that people still to this day trust and believe in Microsoft.
spwa4
6 days ago
You mean giving China control over it?
(because you still need the hardware made, and it's not like the EU commission is even prepared to fix BSPs for that hardware)
The EU has endlessly sold critical infrastructure to US, India and China while actively sabotaging efforts to rebuild it and now want it back - for free. This is criticized as having a low chance of success, as well as being a pretty unreasonable demand.
api
6 days ago
Mobile is the UI/UX equivalent of… I don’t even know… a moon landing? A wonder of the world?
I’m not saying it can’t be duplicated. I’m saying if you want to build a mobile platform you need to approach it with appropriate respect for the incredible difficulty of making something that usable.
rpdillon
5 days ago
Indeed. Power management alone is a massive research area with never-ending complexity across a bunch of domains. And nailing the ecosystem correctly is very hard (both devices and software). Security is another bottomless pit of research and improvement. When trillion-dollar companies like Amazon and Microsoft ceded mobile to Google and Apple, it was a good demonstration of how hard a successful mobile platform is to get off the ground.
literalAardvark
5 days ago
Nah that's complete bull. It's been a solved problem since Android 2.0.
The only thing they're improving on mobile these days are addictiveness and data collection.
roundabout-host
5 days ago
There are experimental mobile platforms, and they work fine. They won't appeal to the mass-market but there's really no reason to disallow them.
account42
5 days ago
UI/UX is not the problem at all, app compatibility/availability is.
tistoon
6 days ago
Ok we get new HN articles every week now about migrating to EU solutions and digital sovereignty. At this point EU should just do as China, please: have EU their own cloud providers, softwares, hardwares, phones and also its own closed-EU only mini-internet barrier by a big EU digital policy border. Just like China, NKorea and Russia. They would be finally at peace with themselves.