Hacker Newsnew | past | comments | ask | show | jobs | submit | haagch's commentslogin

It's not the same system. iDEAL supports banks to implement payment in their online banking websites, while Wero is Google/Apple ecosystem exclusive.


Wero’s goal is to become a European payment system. Like an iDEAL across EU countries. That requires buy-in from major EU banks, some of which are shareholders of EPI, the company behind Wero.

It’s also a response to the ECB’s digital Euro, a way that banks show the central bank “hey, we the banks are actually capable of creating a good EU-level payment system”.


> while Wero is Google/Apple ecosystem exclusive

It's barely launched in more than 5 EU countries. It's not part of the specs or requirements to only be available in the Google / Apple ecosystem.


From their site:

>It is not possible to send Wero payments to friends & family via a web browser or on a computer

https://support.wero-wallet.eu/hc/en-us/articles/25599074240...

So its pretty clear they have no plans to support plain browser access. Which is a very strange decision to me.


It's primarily an online payment system, not a money transfer system. It has worked since forever (20+ years, it's a rebranded Dutch system) from web browser. Still does.


The horse's mouth seems to contradict this. The subject is Wero, not Ideal.


> It's not part of the specs or requirements to only be available in the Google / Apple ecosystem.

but at the moment, it is. so he's right to be nervous. from one american duopoly to another.

but i share your optimism that they eventually allow this to work without them.


The commenter is stating that as a fact, which is spreading information that's not true to others reading that.

Perfect is the enemy of good as always. Having a system that is currently available on the two biggest mobile platforms for the launch (Covering probably 99.9% of consumers) is already much better than piping every single transaction through two US mega corps.


Replies from the German GLS bank on mastodon imply that EPI does not support the use case where banks add it to their web interface

https://ruhr.social/@glsbank/116215341782832097 https://ruhr.social/@glsbank/116125936995037426

> Good morning, it's not "our" fault. Unfortunately, there's nothing we can do about it—Wero is a service offered by EPI, and they've decided to take a "mobile-first" approach for now. Warm regards from Bochum!

As for the prospects of ever seeing banking apps outside of android/ios, there is only https://www.das-parlament.de/wirtschaft/finanzen/wir-bauen-m...

> What about smartphones that run on free and open-source software instead of the commercial operating systems used by the iPhone or Google? > Tanja Müller-Ziegler: This market is still very much a niche one. There are still too few providers, which is why it’s hardly worth offering banking apps for these devices.

> Perfect is the enemy of good as always.

I'm no expert on iDEAL, but being 20 years old, it's older than Android and iOS and presumably supported web based payments from the very beginning. I really don't understand why nowadays people seem to think that app exclusivity is somehow a natural starting point. It's a relatively recent invention.


> they've decided to take a "mobile-first" approach for now

That's hardly a confirmation that it will never be possible ("for now"). It seems like a fair tradeoff for a launch when almost everyone has a smartphone and that's already enforced like that for many parts of life (I'm not saying it's great, but it's a valid tradeoff when alternative options exist) like banking or public transport where the happy path often is a phone app.


You'd think that basic infrastructure such as payment systems had higher standards than just "most" people having access to it.

It's fine as long as we have alternatives, but if online shops were to start to phase out SEPA payments in favor of Wero and Wero-only shops were to start popping it, it would be a real problem.

Btw the solution already exists: It's still relatively small scale but GNU Taler is live in Switzerland. The EU could make regulation to make it easier to adopt at any time it wants.


It's a system which is currently barely live in 5 countries out of 27 EU countries. In most of them < 2 banks are supporting it. It's basically a beta rollout and there's no danger of SEPA, MasterCard or VISA going away and leaving people stranded that don't have a smartphone so there's no need to panic.

Give it some time to mature before writing it off.


iDEAL supports banks to implement payment in their online banking websites

So does Wero, as I cited in another comment:

The Wero app is available only for account holders from the German bank Postbank and the French bank La Banque Postale.

Are you a customer of another Wero-enabled bank? If so, you can easily use Wero within your banking app.

https://play.google.com/store/apps/details?id=eu.epicompany....

It's not the same system.

I said that it is based on the iDEAL system:

Wero is built on the foundation of iDEAL, backed by 16 major European banks – including the Dutch banks behind iDEAL.

https://ideal.nl/en/naar-wero

The European Payments Initiative (EPI) acquired the Dutch payment system iDEAL with the aim of making it the standard payment solution across all European countries. [...] The first step is to make iDEAL the standard in France and Germany because the countries don’t yet have a standard payment system for e-commerce, according to AD. Customers in the Netherlands will notice little of this.

https://nltimes.nl/2023/04/25/dutch-payment-processor-ideal-... / https://www.ad.nl/economie/online-betalingssysteem-ideal-wor...


Really? I frequently use Wero but never installed their app. I use it through my bank application on /e/os


> No account necessary and no private american conglomerates can delete that account.

Officially you need a Google or Apple account to download a wero capable app from their stores, and Google and Apple can always delete all wero capable apps from their stores like for example with Russian sanctioned banks.

Some banking apps work on non - google play controlled android smartphones, but always only accidentally. Some banks like for example Consorbank already crack down on "sideloading" their app at all: https://www.reddit.com/r/Consorsbank/comments/1p909w1/commen...


If Wero is going to be similar to iDEAL, which it is based on, the payment flow will be through your bank's app. Heck, even the Wero app description says so:

The Wero app is available only for account holders from the German bank Postbank and the French bank La Banque Postale.

Are you a customer of another Wero-enabled bank? If so, you can easily use Wero within your banking app.

https://play.google.com/store/apps/details?id=eu.epicompany....

I have seen quite some people downloading their banking apps through the Aurora store (admittedly, it's a frontend for the Play Store, but you don't need an account or the app). Or you can use something like APKMirror and verify that they have the correct signing keys.

Of course, if they need Play Services or Play Integrity basic, then you need sandboxed Google Play or microG. If your bank does remote attestation through Play Integrity, then it is game over, but it is worth contacting your bank. E.g. some banks have added the GrapheneOS signing keys and added support for AOSP remote attestation.


Im a German with a German Postbank account, living in Switzerland.

Wero app Play Store page: "This item isn't available in your country."

Hard to cheer for a thing when it prevents you to access your own money, and promises to "easily pay" immediately fall flat.

Paypal is bad but at least it doesn't fail at step 0.


To be fair, how is Google blocking you from downloading an app, a Wero problem though?


The publisher, in this case Postbank, decides what countries to allow installs from for an app. Google just enforces the policy the publisher sets.


Country availability is a policy set up by the app publisher, not a Google policy


Which is complete bullshit with the Euro having been specifically invented to be used across the EU.

I had a similar moment of stupidifiedment trying to park in Germany with a phone set to Dutch region. Euro in cash works everywhere Euros are accepted but apps on the freaking Internet? Nah, gotta restrict that to the publisher country only.


Switzerland is not part of the EU nor the Eurozone though. It's still a shortsighted stance of Postbank not to open the app to at least the DACH region, but that specific argument carries little weight.


I accidentally skipped that part :(


I mean, there's some reason for it as EU countries have different laws and regulations, but yes, it's a dumb choice on the publisher's part


I can pay with iDEAL without interacting with a smartphone, using only my laptop and a physical 2FA device provided by my bank. Do you know if this will be possible with Wero?


I am not 100% sure, but I think PSD3 will require that authentication methods without a smartphone are provided:

https://ec.europa.eu/commission/presscorner/detail/fr/qanda_...

Require payment services providers to ensure that all users can benefit from methods to perform SCA which are adapted to their needs and situations and, in particular, that those methods do not depend on one single technology, device or mechanism, for instance on the possession of a smartphone.


It's up to your bank actually. Banks (generally) don't want to pay for your hardware key so you need to do a special dance to trigger their compliance bound neural pathways to send you one.

But then the true bliss will arrive the next year with eidas 3.0 or whatever it is called


In the Netherlands this boils down to the 'system banks' (the big ones like ING, ABN AMRO, Rabobank, etc.) which grudgingly offer hardware devices for people who won't or can't use a smartphone, and the neobanks (like Revolut, Knab, and Bunq) which make an Android or IOS smartphone a hard requirement.


ASN Bank has a website that allows you to set a browser-linked code once, after verifying both your email address and phone number. You can then use that browser+code as the 2FA device. It's pretty neat.


With Nordea, you get a code book full of one-time codes.


I have German bank accounts at two different banks and can send SEPA SCT instant transactions via webinterface and physical tan generator with both of them. Wero however is restricted to mobile apps regardless of what your tan generator is and in fact from what I heard, banks generally force you to switch to mobile app tan generators when opting into Wero.

The GLS bank implies it's not up to them. Generally I feel like implementation details are intentionally not made public. For example so far there is no definitive statement on the public internet I could find about whether iDEAL web based payments will still be available after iDEAL will actually switch to Wero. Statements like "For consumers, the online payment experience will remain largely unchanged, as they will continue to pay through their own bank." are always kept vague.


I'm not sure I understand the question actually. Will it work the same way for consumer as ideal does now? Yes, that the promise. Will the actual protocol and endpoints used be the same? I guess not, but also nothing drastic for integrators to worry about.

What I don't get is -- what will be added on top of what ideal already does.

>The GLS bank implies it's not up to them.

They probably can't make two systems within the bank talk to each other for whatever reason. One reason could be -- we are afraid to touch one side and the other is supplied by a vendor. Or politics, or just a plain skill issue. I'm not them and can't possibly know, but my employer was named in comments already, so I feel like I can extrapolate a bit


Oh wow actual news: https://nos.nl/artikel/2624737-scanner-van-ing-kan-nieuwe-id...

google translate: https://nos-nl.translate.goog/artikel/2624737-scanner-van-in...

This looks like it proves me wrong and at least two dutch banks will not require a smartphone app to pay with Wero, if this actually refers to the upcoming actual Wero transition.

> At Rabobank, "approximately 8 percent of all transactions" are conducted using the Rabo Scanner, says a spokesperson. A spokesperson says that research shows that 15 percent of customers prefer using the scanner instead of the app because they find the Scanner secure.

> There are no problems at Rabobank with the transition from iDeal to Wero, according to a spokesperson. Therefore, nothing changes for customers who use the Scanner with the transition this autumn.

> At ABN Amro, the tool for making payments via online banking is called the E.dentifier. According to a spokesperson, around 250,000 ABN Amro customers are using this device this month, which is 4 percent of the total. The number of users is declining because, according to the bank, more and more customers are switching to the app.

> Although ABN Amro intends to continue offering the internet banking function, including for payments via Wero, the bank will be phasing out the E.dentifier over the coming year. ABN Amro is currently already in the process of informing the first private customers about the switch to the so-called USB Security Key. The E.dentifier will only disappear once all customers have made the switch.

This gives me some hope that this might also be possible in the rest of Europe...


That's encouraging. It also suggests banks recognize that removing hardware authenticators entirely would lock out a non-trivial group of customers. Hopefully the transition ends up being "app-first" rather than "app-only."


Will it work the same only for users who use banking apps for ideal, or also for users who use their banking websites to pay with ideal? It's a rhetorical question, right now people can only give their opinion what their statements mean or not. We'll have to wait until the end of next year to see what's actually going to happen. Unless EPI or banks decide to publish an actual roadmap with actual features.


It’s fine to decouple from US payment and financial infra today and punt on decoupling from US big tech in the future. These changes take time and effort at scale, so it’s about being directionally accurate, not doing all the changes all at once. “You eat an elephant one bite at a time.” Europe is eating the financial infra bites right now. There are other bites to be taken over the next several years.

Similar to Airbus moving critical apps from AWS to France’s Scaleway. Flexing the muscle needed to do the rest, and starting with the most important.

https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...


I heard a loud and solid "fuck US" from the people forming the technical opinion on this matter.

The way selection function for the technical parties in this conversation is going makes it double the fun.


While researching Wero initially, I was confused too that no APK is offered. Maybe we can change that.grbn


But you can use Wero also from your good old desktop PC, right? Sure, paying in a restaurant with Wero for example might need this, but I think this is a really, really great first step in the right direction


I feel the same but I'm starting to think that EPI is right to not care.

Nobody from any tech media seems to be pointing out the Google/Apple smartphone dependency, let alone ask anyone at EPI about it. If they do, at least they're not writing about the results.

The only article I know of that ever asked the question is actually from the press of the German government: https://www.das-parlament.de/wirtschaft/finanzen/wir-bauen-m...

"What about smartphones that run on free and open-source software instead of the commercial operating systems used by the iPhone or Google?

Tanja Müller-Ziegler: This market is still very much a niche one. There are still too few providers, which is why it’s hardly worth offering banking apps for these devices."

Other than that I have seen ZERO pressure on this point from the media.

Obviously I do think EPI should intrinsically care, but I also am starting to see more and more that from their point of view literally nobody cares, so why should they?


The EU's NGI Zero in cooperation with NLNet has been funding quite a bit of postmarketOS

https://nlnet.nl/project/postmarketOS/

https://nlnet.nl/project/MobileSettings

https://nlnet.nl/project/pmOS-23-24

https://nlnet.nl/project/postmarketOS-daemons

https://nlnet.nl/project/pmOS-25-26

I think if NGI Zero had been around when Meego was killed, we might be in a better situation now.

I also get the feeling, that the fact that there is so little reported and discussed about this funding reflects the actual level of interest in alternatives.


> But in many cases there are not any homegrown alternatives to support.

Everyone who says something like this should be forced to use one of the alternatives for at least a couple of months and then reassess why people don't use them.

Personally I'm using a Volla Quintus with Ubuntu Touch (ubports is a German foundation) because I'm a masochist.


Here in Germany everyone who has an ID card, which is basically everyone, already has a secure chip for this purpose.


It's an NFC card that can be read with any NFC card reader, USB or smartphone based.

https://www.ausweisapp.bund.de/en/open-source I just saw that it's available in alpine.

So I tried installing it on my postmarketOS smartphone and it runs out of the box: https://i.imgur.com/nRIAyrq.png

My Shift6mq is listed has not having NFC support in postmarketOS, so I can't actually test it, but I assume the USB card reader option will work once it's supported.


The digital Euro seems still in early planning stages. It seems people want to plan a physical card for it, but whether online payments will work without a platform dependent app is unclear for now.

Wero however is currently only planned as an android/ios app period. There are rumors that a card will come but that's only rumors for now.

In your list of groups to be baffled about I would add journalists. You see many articles about Wero mentioning digital sovereignty, but have you seen any that criticize the required banking apps only being available in google's and apple's app stores?


German citizen here. So why is an implementation going forward when you already know it will not serve all citizens? Why are we not refusing to implement this until we know we can make it work on all devices?

Personally I recently switched from an AOSP based android without Google Play to Ubuntu Touch. In the future with better hardware support I will probably switch to postmarketOS.


also German here, we have to get rid of the 100% perfection at launch expectation its crippling this country


Taxpayer money project being tied to a dependency on Apple google is 100% counter what that money should be used for.

You are copy pasting a “correct” argument against eu bureaucracy in the absolute wrong space


But things not in the launch can easily be deprioritized as budget issues indefinitely. “Oh why spend the money adding support for just a few people??” will be the line moving forward.


It would be cheaper to just buy all of the outliers a bottom of the barrel Android phone for them to use with the tax money.


And force them into the Google surveillance, https://news.ycombinator.com/item?id=26639261


[flagged]


It really doesn't matter. When you power on an android smartphone with google play installed for the first time you are presented with a gate screen that asks you to consent to google's privacy policy. You can't use the phone without accepting. (for example https://forum.fairphone.com/t/finalising-the-setup-wizard-wi...)

Using smartphones with such a setup should not become required by a European government on a fundamental level.


It really does. Just calling everything racism makes racism acceptable to a lot of people.

Telemetry/tracking feels a more appropriate wording than “surveillance”. Exaggeration (in case it was one, not sure) also does not make an argument more compelling – quite the apposite with me at least.

And I use AdGuardHome, uBlock, VPNs, etc. I HATE tracking. But it’s not what the Chinese government does to their citizens for example, it’s not comparable.


Are you a lobbyist for Google, Apple, Meta, or the adtech industry? Because if you aren't, you are parroting their bullshit.


Save your keystrokes. I think I've seen that nickname express anti-consumer, pro-corporate, freedom-violating viewpoints in dozens of different threads on a pretty wide variety of topics at this point. Not once have I seen them take the pro-consumer stance.


The pro consumer standpoint is overly represented on this platform so often I can simply upvote points I agree with.


I am not a lobbyist, but I do recognize the great value the adtech industry provides to society and I am familiar with the common arguments and strategies people try and use to undermine it and sow distrust.


>but I do recognize the great value the adtech industry provides to society

Ok, so you're trolling then.


> I do recognize the great value the adtech industry provides to society

good one, very funny.


Genuinely curious to hear what great value you think is being delivered to society by adtech.


Any articles highlighting the great value?


So please tell us what the difference is.


With surveillance a person gets surveilled with telemetry a person doesn't. Telemetry is collecting information about the operation of the device. The goal of telemetry is to understand how the device is operating where with surveillance it is about seeing what a person is doing.


The types of data that's collected for these two purposes have a significant overlap.

Sufficiently detailed telemetry is indistinguishable from surveillance because even if the goal isn't to target you right now, they will still have the secondary option of going back and inspecting all that data you sent them if they ever are interested in you. Another secondary use of telemetry is selling it to someone else to squeeze out a bit more money. There's no downside to doing this, so any business that collects a lot of varied telemetry and likes making money might as well do it. And once the data is in the hands of adtech businesses, it becomes a whole lot more like tracking you personally than just collecting some data for development. In Google's case, you don't even need to hand it over to anyone else, everything stays in-house.


Do you imply that it's not possible for the US intelligence agencies to request this data from google per person of interest and deliver some information from the metadata?

I heavily doubt that.


What does it matter in practice? Do you seriously think Google, the targeted advertisement company, does not use that Telemetry for targeted advertisements?


Yes, I do seriously think that Google does not use anonymous telemetry for ad targeting.


Do you have any reason to think this? Why would Google refuse to earn more money?


Yes just like it’s cheaper to just provide people who can’t afford a phone in the US a phone by taxing other cell phone users - and I don’t have a problem with that.


Refusing to send all your private data to the US to benefit their megacorps, using the tax payers' money, is not "perfection". It is the only reasonable and legal choice.


This is not about 100% perfection at launch, this is about civil equality. Launching without broad support for use cases creates a two-tier society.


A 10% goal would be a good first step. Now excuse me while I read some tea leaves to find out if my trains will be on time tomorrow ( spoiler: they wont).


surely 10% of DB digital offerings work as expected, just not the 10% that is essential for train travel.


I love how just ordering a ticket is already a minefield for anyone not aware of how crappy german services are integrated. Pick one route, you will get a list of fully customized tickets that cover everything you need, pick another and you will get a list of tickets that will get you fined unless you carefully read through each and pick both a ticket that comes close to what you need and buy more tickets to cover any additional options.

The only thing near 100% perfection when it comes to german services is the full assery with which they are implemented.


So much hate.

Some time ago my "25% DB Card" ran out and was not active anymore, but the app did not display a warning. Even when buying a ticket from the app, it still had the "25% off" option activated by default.

Result: huge fine (something like 200 euros) on the train + I had to buy a completely new ticket (another 100+ euros) because the ticket I had bought ( which was 75% of original price) was considered completely invalid. I tried in all possible ways to get this fine reduced, as it was an honest mistake and arguably caused by their UX, but they did not budge.

I hate hate hate Deutsche Bahn with a passion, yet I still use it cause I'm an idiot who doesn't want to fly for short routes.


> it will not serve all citizens

This is an understatement. Better phrasing would be "when it allows two unaccountable foreign companies to lock citizens out of the digital market".

There are plenty of horror stories of tech giants frivolously banning people. We shouldn't be adding state support to that. I don't want to lose access to digital banking because of some deliberately vague "community guidelines" violation, or because I got mass-reported to some "e-safety" provider that both Apple and Google outsource to.

Sibling comments see this as a good solution, just not a perfect one. I see it as making a bad problem worse.


> Why are we not refusing to implement this until we know we can make it work on all devices?

Simply put: this will never happen. Way too many devices implementations to make this a reality.


It's just a matter of creating a web app.


And what attestation services does your web app use? Do we lock that web app behind having Secure boot enabled, along with a Java applet for the fun of it?

If your answer is "none", you missed the point.


Attestation of what? It's none of your business how I secure and configure my phone. I use a smart card on my Librem 5 btw. See also: https://news.ycombinator.com/item?id=47647047


My business, no. Your government however, has a few reasons to want to ensure that the ID you're going to use to vote, to prove your identity to any service, etc, etc, does not get passed from device to device.

Configure your phone however you want, then use your physical ID because your phone isn't supported. They're not taking it away. In the same way that you can file your taxes. Having an online filing service doesn't mean you're being "excluded" because your i386 running BeOS isn't part of the supported hardware. Send a letter. It'll still work.


I second the question, attestation of what? I have a Solo key that I use with webauthn for several services already. Is that not good enough and even if not, there surely are sufficient alternatives, least of all the actual electronic id on the national id card via nfc?


You are assuming it will not be possible to add support to other OS. Why?

What would be “knowing it can work on grapheneOS” for example, in your view?


It will be possible but simply won't be done.

And as of now it won't work on GrapheneOS, it doesn't pass anything except MEETS_BASIC_INTEGRITY


That’s not what the parent wrote though.

And why is it so bad that they start with a smaller subset of feature and target the 99% of the population using either google or apple?


This is a misleading way to put it.

Re: Android.

Goggle can supports AOSP attestation like any other vendor who wants to support it. They invented it.

So instead of immediately locking down everyone using android to ONLY Google-dependent method, I'd developers could go the vendor agnostic way, but consciously decided not to.

It's untrue to claim that supporting AOSP attestation only serves GrapheneOS and leaves out everyone using Google-surveiled handset.

Nb, mixing it up with Apple is a conscious way to further the false claim, and I believe it's not accidental since these ecosystems are naturally completely separate.


You are misleading in fact, you use terms such as:

“it won’t work on GrapheneOS” “locking down everyone using android to ONLY Google-dependent method”

which make it sound like it’s a permanent and definitive limitation.

It is not, they can add support later, as they stated already.

> It's untrue to claim that supporting AOSP attestation only serves GrapheneOS and leaves out everyone using Google-surveiled handset.

hmmm, what do you have in mind? Publish it to F-Droid but not to the google app store?


I indeed said "locking down everyone (...) to only Google-depended method"

It is a permanent limitation until it's resolved by the vendor, isn't?

You are phrasing it like it was untrue that on non-Google Androids it will work.

It's false - it will not, until it's fixed (changed).

They CAN add the alternative methods later but until they added they're not there.

So it's a permanent failure until (not unless) until it's resolved by either removing the hard dependency on Google Play Integrity or adding alternative attestation methods.

And your last comment about FDroid is a little bizarre to be honest - if it's meant to be available it must be on the Google Play too.

I was just objecting the suggestion that ADDING alternative methods of attestation somehow precludes devs from using Google play integrity as well.


What’s a temporary failure then for you, I’m curious? Everything is permanent, following your definition.

You didn’t answer my question. I don’t understand what you are suggesting. You want them to do AOSP at the same time rather than afterward? You simply disagree with they prioritisation? They stop using words like lockdown, it’s misleading. Say “I wish they had included AOSP support in the initial release” then everyone understand what you want.


You have the totally wrong expectations here. Some service that requires citizens to buy and bring their own devices in order to use a service will by definition always be exclusive. Whining about lacking compatibility with some niche sbowflake devices is just inappropriate in this context. The only solutiin is to require an actually convenient fallback for those otherwise excluded from that service.

The limited selection of attestation providers can be criticized for many other reasons, though.


Your disdain isn't helpinh you here either as you're just as wrong as parent.

Such public utilities ought to always prioritize privacy, platform-independence, and empowering market competion long- and short-term. And to achieve that you need to start at the design level.

In this case, clearly, you either have to avoid relying on app attestation or lay the foundation for an unrestricted number of independent chain of trust frameworks.

The latter, of course, is a policy-level issue, but the ones responsible for the design and development are the ones who need to pass such concerns up the chain.


You have the right starting point, but the wrong conclusion. Government services need to be inclusive of everybody. But you simply cannot build technical solutions that put technical requirements on devices owned by the users in a way that the service is sufficiently inclusive. That is just a fact.

If you want to be critical of the outcome on compatibility grounds, forcing a grind to increase technical compatibility is the wrong thing to ask for. That must necessarily always leave some people behind. The only honest alternative positions on that front are (a) the government issues the tech to everybody itself or (b) the government doesn't build advanced systems at all.

The German government offices rely on a lot of quaint-looking paper based processes, but they have one thing going for them: working through them can be done with pen and paper - tools that are available for cheap and broadly compatible. It's probably not such a bad thing after all?


Inclusivity is secondary here. Moreover, it's just fallacious to argue the nation has to give up on its own rights and principles and be content with whatever the market provides.


Do all German hospitals serve vegan food?

If you were averse to carrots (without any health restrictions on eating them), would every government institution in Germany be required to serve you carrot-free food?

If not, why should they be forced to accommodate every smartphone brand in existence, even if there's only 3 people in Germany using it? THe list has to end somewhere.


> Do all German hospitals serve vegan food?

Can't speak for Germany, but they do in the UK. It would be illegal discrimination against a belief for them not to.


[flagged]


Would you say the same if they refused to serve kosher/halal meals for Muslim/Jewish patients?

UK law protects some philosophical beliefs equally to religions. (what qualifies is a bit of a mess as it's all case law)

(On a practical note, I imagine it's easier for hospitals to just serve vegan food for anyone who is vegetarian/Muslim/Jewish rather than have specific kosher/halal meals)


Actual yes since I think all religions are illogical…


Religion tends to be more constitutive to a person's self-identity than purity signalling dietary trends.


Setting aside the fact that there are multiple very old, very large religions that are nearly or actually vegan (e.g., Jainism), or that people raised vegan can't easily digest meat or animal products, why on earth do you feel that you or a hospital worker are qualified to determine the beliefs making up someone's identity, when you know absolutely nothing about them?


It took Western government institutions hundreds of years of violent conflict to embrace religious tolerance. I don't recall any major intense violent conflict being fought over dietary preferences.


Lol at eating just plants as being expensive. You do know where animals that are eaten get their food right?


Mostly from plants that humans can't or at least wouldn't want to eat.


Actually the subsidies mostly go to diary farming. Vegan food is cheap to produce but mostly not subsidised. This, plus the (no) economy of scale makes the shelf prices sometimes slightly higher, eg soy milk vs defatted milk.


Vegetables, legumes, nuts, and grains are not expensive, and veganism is a protected class in the UK.


Yeah but when you're mad at a nation not force-feeding meat to vegans you have to come up with some reason why the vegans are bad.


Having a separate option is however not free.


You are forgetting that by not allowing more open platforms they effectively force you to accept Apple/Google EULA's essentially forcing you to give your private data to Google/Apple.


Lots of hospitals don't even serve healthy food in any sense, so expecting a good coverage of dietary options is optimistic...

But to answer the question in a real way: Veganism is often regarded as just a dietary choice like any other, when in reality courts in several countries have more or less agreed to classify it as a matter of conscience, which would give adherents some right to it. Though it seems German courts have been reluctant to draw much legal consequence from it - so far at least.

So in that sense, I don't think people have been talking about digital sovereignty and abstaining from proprietary software under another country's jurisdiction much as a matter of conscience yet. We can thank Trump that it might actually become a thing though.


The ones I’m aware of do, yes


They do.


While the example your provide is reasonable fair, the comparison is not.

For it to be fair comparison, the carrots would have to be grown by a foreign company, known for using unsafe growing practices, causing contamination. Eg, poison carrots. This same company would have to be under the control of a very hostile, very actively aggressive and threatening nation.

Such as one currently threatening to annex allies, among other things.

With the US literally tapping and spying on heads of foreign states:

https://en.wikipedia.org/wiki/German_Parliamentary_Committee...

and there being lots of ways to spy, such as push notifications:

https://www.reuters.com/technology/cybersecurity/governments...

Only insane people would objectively decide to use Google or Apple anything for any form of ID. Those platforms should literally be outlawed. Any use of push notifications or identity attention should be looked at as utter fantasy.

Here's a secret for you. There really isn't any urgent requirement to have an electronic identification method. It can wait. Supporting legislation can be passed first. There are lots of ways to do so.

For example, the entire EU could pass legislation stating that all cell phones have open source code available, including all binary blobs for drivers. And that all phones are unlockable, and that (for example) the phone has a version of the rom you can download without any Google services.

(If Apple isn't able to compete here, well... too bad)

The phones would not be legal to sell, unless the open source firmware was compiled in front of regulators. The point of this is another pet-peeve of mine, it would allow people to support their own phones, for that source code would be released the day that phone was no longer supported.

And yes, it's trivial to have open source firmware blobs. There just isn't a market for it. Pass a law, and sellers of SoC and other ICs will capitulate, or maybe more punitive laws will be passed against them. As someone once said, yes companies can have a lot of sway.

But governments have police, courts, and armies.

Right now, Android and Apple devices are a literal arm of the US government's spying apparatus, even if those two companies actively work against it.

Do not trust Google Play. Do not trust Firebase. Do not trust Google. At all.

Are Germans just too trusting? I remember 15 years ago, when nuclear power plants were closing, concerns were raised about the reliance on Russian natural gas. These were waved away. Russia? What's wrong with Russia! They're almost allies, they're capitalists now!

Don't do this again.

Do NOT trust Google. Don't. Don't make it a core part of any identity management.

Imagine, needing an active Google account to even bank! Or to file your taxes, or even to prove who you are!? Google cancels accounts with no recourse, no reason why, won't help anyone, and this is to be the core of identity management for Germany?

The average person won't even be able to install any German Government designed apps, unless they are on the Play store! Are you going to teach Grandma how to use ADB to install an app? Without an active Google Account, will you even be able to use push notifications?

Why would a government even allow ID to be blocked by the requirement that a company with terrible, horrible, inane customer service, which just kills accounts without recourse, be a gatekeeper?

No Google account, no ID! Wha!?

It's literally not sane.


I think it falls under the article yesterday about male German citizens having restrictions on their travel. Electronic ID is a step toward “papers please”.

Germany at least seems to feel international war is only a few steps away and from how militant the Chinese and Russians have been treating their “territory” I am not sure it is a bad call.

America has likewise turned bad preferring violence over dialogue and loves tracking “hostile influences on the American way of life”. Those influences being anyone who would call out the toxic culprits making America into a cesspit.

Tying to Apple and Google? It is a terrible idea. Both are prone to freeze devices for financial or social issues.

However, a fix I would accept is to force the device makers to support multiple accounts out of box on every device to keep separate what the corporations have proven time and again they cannot be trusted to combine. Also for those companies to be forced to make a cheap credit card sized device which must be held to power on for the few that truly hate the ecosystems.


> cheap credit card sized device

I don't understand why this is not the default to be honest, and why people are not advocating for that


The first thing to go in every major war, will be the reliably of electronic anything.

What's wrong with ID cards and cash?


Because you can’t please all of the people. And before someone likens it to the ADA. Even with accommodations you have to make, car makers aren’t for instance required to make cars that blind people can drive.

You chose to use a non mainstream platform. Thats on you.


Sure.

Something I forgot to mention is that the UBPorts foundation whose mobile operating system I currently use is a German organization.


Do we have stats how many germans use something else than Google Android, Samsung Knox or Apple? I recon it should be less than 1% which quite honestly is in fact „all“ citizens.


Sure, let's just arbitrarily exclude ~1million people because they're not running the government's preferred American spyware.


This is a very, VERY stereotypical Tech Product Manager viewpoint: "N% of users are hard to support edge cases, so we should exclude them." You see this justification everywhere in business. "We'll drop support for [old OS] once it gets to 1% of our user base." "Only 1% of our users have non-Latin characters in their usernames so it's OK to not support that." "1% of our users are on 3G or slower Internet connections, so we don't have to consider them in our performance metrics."

It's a pragmatic, profit-oriented point of view, but not one that makes sense when your mission is to be inclusive of everyone.


This is an unfair and a straw man argument, is it not? Are you also unhappy that in a democracy the 51% choose how the other 49% are going to be governed?

Why device attestation is required is quite well explained by this github comment [0]. I am in the industry and I agree fully with it, because it is a fact a problem for most smart phone users in terms of security.

0 - https://github.com/eu-digital-identity-wallet/eudi-app-andro...


I think your analogy is flawed. I can be part of the losing 49% and still be entitled to receive the same services as the 51%, whereas people who chose a privacy-oriented OS are essentially going to be excluded from essential governmental services. That's a whole different kind of thing.

I'm not going to replace my 1200 EUR smartphone with a device that forces me to have an account with Apple or Google. I've been issued a German identity card, which is its own computer that includes a digital identity already. I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need. They should just stop excluding me already.


>I' ve been issued a German identity card, which is its own computer that includes a digital identity already.

Then keep using it, instead of the not-mandatory app?

> I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need.

Sure. In the mean time, do we tell the other few dozen millions that don't have an expensive card reader to go fuck themselves, or can we get to work on a solution that, even if not ideal, makes their lives easier?

> They should just stop excluding me already.

They aren't. You said it yourself, your ID is in your pocket.


Government services are going to drop support for the old scheme the minute they start supporting the new one.


Sure, that's why they stopped receiving paper letters for tax declarations once they setup Elster.

Oh, wait, they didn't, my bad. You can still declare your taxes with good old paper. The only people that can't are self employed, and that's because they have a different set of obligations with higher demands


Telecoms shut down 3G once 4G had rolled out. TV networks killed DVB-T after DVB-T2 went live. Banks have abandoned FinTS for app-based 2FA.

Your comment compares a paper-based, non-digital process with a digital one. My criticism, however, is about abandoning an old digital (but vendor-neutral and inclusionary) process in favor of a new (and discriminatory) one.


> privacy-oriented OS

Well, in all seriousness what examples could you give me here in terms of device hardware attestation? Even GrapheneOS does use Google root certificates to attest your device. There is indeed an option for EUDI to keep a list of keys and I bet this is probably the way they are going to go for Android in the future. We shouldn't forget this is still in the planing phase.

> to have an account with Apple or Google.

True for Google, not true for Apple. Device attestation on iOS does not require you to have an iCloud account or sign into some Apple services. It works entirely using device hardware ids.

> I also own an expensive card reader, which together forms a system that is completely capable of supporting any attestation anyone would need.

Nope. This is eID and verifies your identity, it does not attest the security of your hardware. These are two different problems we talk about here.


> in all seriousness what examples could you give me here in terms of device hardware attestation?

My Librem 5 runs an FSF-endorsed OS and has a smartcard.

> True for Google, not true for Apple. Device attestation on iOS does not require you to have an iCloud account or sign into some Apple services.

This is extremely misleading. Even if true, you must have an account in order to install any app on an iPhone.


> My Librem 5 runs an FSF-endorsed OS and has a smartcard.

Ok, so how does that help with device attestation? If I am an app developer how does it tell me that your OS has not been tempered with or actually that my app has not been tempered with? Are there any cryptographic keys stored in a secure place on the device that the Librem vendor can verify?

> This is extremely misleading.

But it's not. It's an architectural difference between how Google and Apple implemented attestation. Apple stores the generated keys in a secure part on your device and certifies them. The rest is your job as an app developer. And as a user, you do not have your iCloud or iTunes account used for device attestation. In contrast Google and its Play services are an integral part of the attestation workflow.

For Apple it's evident from their docs. As a side note: I do try to learn more about this, because of an incoming project concerning it.

> You can’t rely on your app’s logic to perform security checks on itself because a compromised app can falsify the results. Instead, you use the shared instance of the DCAppAttestService class in your app to create a hardware-based, cryptographic key that uses Apple servers to certify that the key belongs to a valid instance of your app. Then you use the service to cryptographically sign server requests using the certified key. Your app uses these measures to assert its legitimacy with any server requests for sensitive or premium content.

Source: https://developer.apple.com/documentation/devicecheck/establ...


> If I am an app developer how does it tell me that your OS has not been tempered with or actually that my app has not been tempered with?

This is not your business to verify and control what can run on my phone. I can do it with my smart card, which securely stores cryptographic keys.

> And as a user, you do not have your iCloud or iTunes account used for device attestation.

It does not matter. An account is necessary to make the phone usable at all. The attestation is useless on a phone that can't install apps.


> Nope. This is eID and verifies your identity, it does not attest the security of your hardware.

The reader and its firmware is already certified by the federal IT security agency BSI for use with eID and banking. Why shouldn’t I be allowed to use that for whatever digital identity wallet thing the EU is cooking up?


Correct me if I’m wrong please, but this is a mobile Wallet app, an enclave, for government issued documents: Ausweis, Diploma, etc. How does a card reader come into the workflow here? I don’t quite get your point.


Currently, the card reader is the only thing that allows me to do banking and use government services on Linux. If at some point, governmental services decide to drop support for the physical-card-plus-reader systems and move everything to mobile wallets instead (like many banks already did), then I can’t do shit anymore without Apple or Google.


That's a silly argument, not only because many important changes require a 2/3 majority.

My point was that the government and its services (German or otherwise) should be available to all citizens/residents, regardless of their choice (or lack) mobile device.


If it requires a Google or Apple account, then it also requires those companies never cease an account, either. Or vulnerable people will be harmed.


> Are you also unhappy that in a democracy the 51% choose how the other 49% are going to be governed

Yes of course. That is one of it’s fundamental issues.


And backup software should also remove the "restore" option because hardly anyone needs that, right?

Same here, the government shouldn't build a system where two American mega-corporations have the keys to everyone's lives.


There's a big difference between having to run a particular company's OS and being forced to share private data (whether that's merely your DNS requests or your ID documents and full financial history). with said organization.


In fact „all“ citizens who are willing to be surveilled by Google and Apple, unless German government provides each citizen with similar eID hardware there won't be any digital equality any time soon. Maybe they should pay to some subsidiary company of IBM (like RedHat) to do this, they already have such a good track record of storing nationality on their machines /s

https://en.wikipedia.org/wiki/Dehomag#Holocaust


because then it will never get done. There are still people using old Nokia phones, for those there will never be a solution.

The usual 80/20 rule applies here as well.

And if you really are a German citizen, you know how slow the wheels of government already turn in Germany, I assume next week you would be the one complaining that "Germany is so far behind" and that "other countries are so much faster at implementing stuff" :)


Nah, I'm that one idiot who uses alternative open software and just accepts when services aren't offered to me. The older I get, the easier it feels to not give a fuck anymore.

Can't buy any single fare public transport tickets online here in Stuttgart? Sure, I'll use the DeutschlandTicket NFC card. Can't view the EPA? Fine then I don't. Can't pay with Wero? Fine, I don't actually need to use shops that don't offer SEPA Vorkasse or Lastschrift (only without a dodgy "identity verification" fintech startup of course.


You are not alone.


We are not talking about old Nokia phones, but perfectly modern phones like those with GrapheneOS, that can be run on cutting-edge hardware, with a secure enclave, does not use Google Play Services by default, and has a high probability of being more secure than iPhone or any Android phone.

It is exactly the kind of alternative that European countries should embrace to become less dependent on US tech.

I am not sure if you are European, but why people are still supporting the GMS Android/iOS duopoly after the US revoked the Google accounts, Office 365 accounts, credit cards, Amazon accounts, etc. of ICC judges is beyond me. Supporting only iOS/Google GMS Android in a government app basically gives the US all the means to blackmail you and/or disrupt your digital infrastructure.

It seems there are still people working for European governments (including developers) who seem to have missed 2025 and the first few months 2026?

We are repeating the same mistakes as depending on Russian oil/gas again.


Then maybe it shouldn't be done? What??


Yeah, let's burn the witches who care about privacy! Jokes aside, in a democracy, the systems must be designed so that everyone can participate. We manage to do it with voting, with income tax declaration, but for some strange reason, with ID we want to achieve 1984 nirvana, and crush the voices who tell us that the surveilance society we are building is just setting us up for the next Hitler.


> There are still people using old Nokia phones

No one wants support for toasters and washing machines. We're talking general purpose compute hardware. TCP is also supported on all these devices. Quite frankly, it's probably easier to implement, if you are not fighting a locked-down OS like iOS.


> but you can use a physical card reader with your debit card for an OTP to use as well and do it in your bank's online environment in the browser.

That's nice for ideal users, but Wero here in Germany is completely exclusive to mobile banking apps.

I have yet to see any actual confirmation in any way that ideal will keep the alternative web based payment once they fully merge with Wero. On the one hand, EPI never puts out any concrete info, on the other hand no Journalist ever seems to ask EPI representatives the important questions.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: