Hacker News new | ask | show | jobs
by blop 16 days ago
This is the elephant in the room regarding the big "digital sovereignty" talks in the EU. For the moment in the EU institutions the focus is mostly at the post-acceptance stage that everything must eventually migrate off US clouds. There is still some denial and hope that things will go back to "before" because it's going to be extremely costly to migrate, but at least high level EU civil servants start to see the strategic value of moving out.

However there is ZERO talk about mobile platforms... No alternative solution like linux for the desktop, no money or care given to the few alternative that tentatively exist, and zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU.

So whilst the backend guys more or less got the memo about sovereignty, I think there is still a lot of educational work to do regarding end user devices and what kind of digital slavery hole we're digging ourselves in...

11 comments

"zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU."

Complete public datasheets on how to program the hardware should be a requirement fit a DMA2.0.

This is not entirely true. I don't have much details but I know people who started to work on two separate free software projects aiming to make supported mobile OS. These projects couldn't get funding before but they do now. Afaik it's still a battle with AI companies lobbying that soverign AI is much more important than mobile OS but there is some growing interest. Imho i don't even think some linux based alternative to Android would be that hard to pull off but it's the hw companies that will be skeptical to build hw for such OS. I would have to be some govs puahing it as secure gov devices first.
Which is all well and good, but who is going to use those projects if the law requires them to use Android or iOS for age verification?
"The law" requires no such thing and there's nothing preventing those new OSes form providing proper security signals.

But is DOES require work - and it's much easier to complain than to put in work.

> "The law" requires no such thing

It requires age verification and provides code whose development was subsidized by the government, which third parties the user doesn't control will use, that creates a dependency on those platforms.

> there's nothing preventing those new OSes form providing proper security signals.

A network effect, far from being nothing, is a barrier the height of a mountain.

The purpose of attestation is to lock out competing platforms. It security value is a joke. Devices pass attestation with known vulnerabilities and fail it for being competitors, even if the competitors have better security.

Offering to make attestations nobody accepts is a farce. The problem to be solved is how to run existing software that was originally written for other platforms when the new platform is new and doesn't have enough users for third party developers to specifically target it, which is the exact thing that can't do. And without that it can't get enough users for third party developers to specifically target it.

> The purpose of attestation is to lock out competing platforms. It security value is a joke.

This is kind of your... opinion man.

In reality pretty much all security sensitive applications require attestation from their side.

And what security value does that provide, when millions of attestation-passing devices have public unpatched LPE vulnerabilities? Anyone can get one and run arbitrary code on it as root. It's completely worthless for actual security. Worse, it does the opposite, because a newer third party ROM that patches those vulnerabilities would fail attestation, preventing honest users from updating their device and thereby leaving them vulnerable.

What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.

It requires a government-authorised "age verification" "app", but it does not require that it is accessible through standard protocols, so that it can work on any platform. In practice, the governments will only make it available for Android and iOS. Plus, you cannot have a free OS providing "attestation"; "attestation" is incompatible with root access and modifying the OS.
Yes, it is much easier to ignore the unelected bureaucrats than to jump through their ridiculous hoops.
See, you’re just saying what they’re saying, but with emotive, thought-terminating language. Again, it’s easier to complain. Have you been living under a rock for your entire life? Have never ever been involved in a decision being made about certain “blessed” vendors, and the decision is being made for legitimate technical reasons, not “ridiculous” ones.

If you’re the sort of person that’s unable to distinguish between something that’s legitimately unjustifiable/ridiculous, and something that just upsets you, then you do you, but don’t bring this here pretending that it suffices as a discussion, because it doesn’t.

What?
I think the asumption being if there is gov backed mobile OS govs would also support their app ecosystem there. That's kinda the point of funding alternative free mobile OS?
They could try and put money into funding Jolla/sailfish/whatever
That wont help anything. Then you are just force to use Android, iOS, or Sailfish. It need to be a platform agnostic thing, else you're just hitching the fulcrum of civil society on private company.
Exactly. The app is only inclusive if it is accessible over a standard protocol (Web) without "attestation", so that it works for any platform. If I release a GNU/Linux distribution tomorrow, I should be able to use the app on it with only some work on my part.
You mean ChromeOS Platform.
I don't disagree, but the eu needs their own mobile OS alternative in general so if they absolutely need to rely on a private company, it isn't an american one
This doesn't follow. Why is public infrastructure no longer a possibility as soon as computers get involved? We aren't talking about cutting edge innovation here anymore, mobile phones are boring standard devices.
It is a possibility, just not one I see as likely to happen. Could the EU fund a public phone company? Probably. Will it happen? Most likely not
Private companies providing public services is really not a rare thing.
Who do you think said it was?
Because this is all a political move. This so-called "EU sovereignty" drive is in fact aimed at further reducing sovereignty of the member states via further transfer of power and control to the EU.

These digital ID wallets do exactly that. Member states lose control of the ID infrastructure, which will now be controlled by the EU. There isn't much sovereignty left at national level...

Each member state has to implement the system themselves. Where is the loss of control?
The US federal government has been doing that to the states for a while now. They don't have the constitutional authority to do something, so instead they shove a lever under something they nominally are allowed to do and tell the states "do the thing we're not allowed to, the way we tell you to, or else." Where the "or else" is something like, they collect billions of tax dollars from your constituents that you then can't use to provide them with services, and return them to only the states that bend the knee.

(The US constitution originally required federal taxes to be apportioned for exactly that reason.)

This isn't how EU works though (EU can actually directly order states arouns :P), so I'm not sure how that's relevant here?
That doesn't appear to be accurate:

https://citizens-initiative.europa.eu/faq-eu-competences-and...

Moreover, it's ignoring the context of the thread. The relevance is obviously that coercing someone to do something against their will and then saying they're still in charge because they're the ones doing it is a sham.

Can you highlight what part of that FAQ doesn't make it accurate? EU directives are a thing.
Please provide examples, because this sounds highly speculative, and also straight up incorrect!
A major example is the US drinking age. Federal highway funds, which provide money for interstate highways, major US routes, etc, are partially contingent on states (who are given authority over alcohol laws both by the general police power and the 21st Amendment) setting the minimum age for the legal purchase of alcohol at 21. The National Minimum Drinking Age Act withheld 10 percent of highway funds from states that didn't comply. The fact that it wasn't 100% let the Supreme Court allow it to slide, but eventually all the states did comply, and effectively the US has a drinking age set by the Federal government instead of the states even though the states technically have the power to set an age themselves.

The Federal government using the withholding of funds to get the states to do what it wants is a well-documented phenomenon.

As an obvious example, regulating education isn't one of the enumerated powers of the US federal government, but there are numerous -- often controversial (e.g. NCLB) -- federal laws that take tax revenue from every state's constituents and return it to the state only if they comply with federal requirements the federal government has no power to impose on its own.
Where is control in being mandated to implement and EU-wide, EU-defined system? This is a net loss.

My previous comment should be taken in its entirety. The loss of sovereignty of individual countries is comprehensive across all domains and this is just one brick in the wall.

This is nothing new, this is what "European integration" means. I wanted to point out the very newspeak-esque use of the term "sovereignty" in Europe at the moment.

The spec/design leaves a lot for the member states to decide on their own. You do understand how the EU and the member states roles work?

I would think the idea is to make services and ID documents more uniform across the union. I don’t see what the individual members state lose here? Apart from the cost of implementation. The individual EU citizen would seem to benefit from standardized documents accepted by all companies and governments, do you disagree?

This is totally not the EU version of China's social credit score system and WeChat SSO system.

It will totally not be used to sanction you the moment you become a nuisance to the EU elites by saying "wrong speech" that goes against their mandated doctrine or pointing out their acts of corruption or dismantling of democracy.

The EU building in Brussels even has the word "DEMOCRACY" plastered on the front in large bold letters[1], in case you forgot.

[1] https://audiovisual.ec.europa.eu/en/media/photo/P-069521

10000 basis points agree.

Add here shared border control since 2027 in eu, and chat control now.

And prominent names like democratic republics of Kongo and North Korea.

They're already unpersoning left-leaning journalists, look up Hüseyin Doğru.
Russian actors*
China made its own linux distros almost immediately. And as far as I know it is widely in use (Kylin etc.?).

Some nations in the western sphere seem to gladly outsource such critical infrastructure. Thinking about the Korean defence manufacturer whose contact mail was something@gmail.com in an advert I saw a few days ago. Perhaps Google will integrate some fast reply function for some instant AA ordnance delivery?

I don't think that we should want some locked-down insolution forced upon everyone, European or not.
"This is the elephant in the room regarding the big "digital sovereignty" talks in the EU"

The elephant in the room is that it is just talk, as always in case of EU.

The sovereignty thing is a theater. Many french unis use Google cloud because they're broke and can't maintain in-house services, and none gives a damn.
Yes, spot on, the talk is always around Office and co.
Isn't AOSP a thing?
This app requires Google Play. AOSP alone won't cut it.
In fact, it requires attestation: even if you install Google Play on some Android in an emulator/container/VM, on an alternative Android distro or in a rooted device, the app will not accept it.
Wth. Does it at least have the decency to use aosp attestation? Or are they just happy to give the keys to the kingdom to Google and require Play Protect?
How would you "use AOSP attestation"?

The point is that the signatures are compared against a database of certified builds - and that exists on Google servers.

If you want AOSP attestation, you need to build your own database to compare against.

https://grapheneos.org/articles/attestation-compatibility-gu...

It exists on Google's servers for lock in reasons alone.

Even if they did that, it would not be OK. Free software is no longer free if it has to be on a list.
Writings on the wall can’t be clearer on AOSP’s future…
It is true that Google (de facto) controls the platform and made themselves (de facto) essential to utilizing the platform by integrating their proprietary services so deeply into the OS that you need to be a behemoth of Samsungs caliber to even attempt to meaningfully re-purpose the AOSP, and this was a brilliant strategy because it has allowed Google to solidify their spot in the duopoly / oligarchy while seeming "open". But. I do believe that Google will continue to publish the AOSP source code under a permissive license and that this code will be indispensible to a European Manhattan project for tech sovereignty, should policymakers ever see the light.
Have to throw in this 13 year old Ars Technica article as a follow up:

https://arstechnica.com/gadgets/2018/07/googles-iron-grip-on...

Still amazes me how everyone isn't cynical-by-default about anything Google (or big tech in general) open-sources yet...

Yes, I remember feeling that way in 1995-2005 about Microsoft. Imagine my surprise to learn that people still to this day trust and believe in Microsoft.
You mean giving China control over it?

(because you still need the hardware made, and it's not like the EU commission is even prepared to fix BSPs for that hardware)

The EU has endlessly sold critical infrastructure to US, India and China while actively sabotaging efforts to rebuild it and now want it back - for free. This is criticized as having a low chance of success, as well as being a pretty unreasonable demand.

TIL Google is China
You misunderstand, my point is that Non-Google Android is Chinese. Which it obviously is.
Mobile is the UI/UX equivalent of… I don’t even know… a moon landing? A wonder of the world?

I’m not saying it can’t be duplicated. I’m saying if you want to build a mobile platform you need to approach it with appropriate respect for the incredible difficulty of making something that usable.

Indeed. Power management alone is a massive research area with never-ending complexity across a bunch of domains. And nailing the ecosystem correctly is very hard (both devices and software). Security is another bottomless pit of research and improvement. When trillion-dollar companies like Amazon and Microsoft ceded mobile to Google and Apple, it was a good demonstration of how hard a successful mobile platform is to get off the ground.
Nah that's complete bull. It's been a solved problem since Android 2.0.

The only thing they're improving on mobile these days are addictiveness and data collection.

There are experimental mobile platforms, and they work fine. They won't appeal to the mass-market but there's really no reason to disallow them.
UI/UX is not the problem at all, app compatibility/availability is.
Ok we get new HN articles every week now about migrating to EU solutions and digital sovereignty. At this point EU should just do as China, please: have EU their own cloud providers, softwares, hardwares, phones and also its own closed-EU only mini-internet barrier by a big EU digital policy border. Just like China, NKorea and Russia. They would be finally at peace with themselves.