Hacker News new | ask | show | jobs
by Erikun 17 days ago
Im confused, the github discussion says that the README says

App and device verification based on Google Play Integrity API and Apple App Attestation

But I can't find that anywhere. Am I missing something?

4 comments

It used to say that, it was removed as a PR measure, while in practice the national implementations (as you do not use this app, but a national one) require it, because the specification only mandates Android/iOS versions to be provided (it allows others, but no government will do so), and it does not mandate them not to have "attestation".
This entire issue is a disaster of a Github issue. It looks like its on the entirely wrong repository. I did eventually find the text in another repository; the one for the Android reference implementation: https://github.com/eu-digital-identity-wallet/av-app-android...

It was removed from there to clarify the entire "Hey, this application is not done yet"

It being in the reference implementation instead of the spec is a massive difference. One means that it's just there to show an example, and we should push national governments to do it better in their implementations, while the other would mean that it'd be a requirement for all implementations, which it doesn't appear to be.

It also looks like the reference implementation removed that functionality entirely several months ago: https://github.com/eu-digital-identity-wallet/av-app-android...

In my opinion the whole "it's just a reference and national govs can decide" is a nonsense excuse to diffuse blame in a circle. The only outcome is that national governments will closely follow the reference and reuse the decision, the citizens of each country then have to manually complain to their own government individually, at which point they might get ignored because, well the reference implementation has it or talks about it, so they're just following the recommended security requirements, and who are you anyway to be demanding our system get less secure are you some kind of cybercriminal?

Play Integrity is still recommended to be evaluated in the documentation, with no mentions of its consequences. https://github.com/eu-digital-identity-wallet/av-app-android...

Honestly, root detection is a cat and mouse game. So many ways to spoof it. Same with Play Integrity. If the goal is to prevent bad actors, it will never work really. It will be just a big headache for the citizens. Look at how gatekeeping certain websites is working. VPNs became mainstream. So are proxies too especially for bad actors. Malicious actors have just to pay up a service to do so. And I am sure it will be the same with Android (it already is with keyboxes you can purchase to spoof play integrity)
From what I can gather from the linked discussion it was started as a pull request or a issue and was transferred to a discussion later. Perhaps some data was lost there? If you expand the comments fully there is also mention of a nuked merge request, I assume it was related to this text.

Edit it was not visible from the discussion link but it is visible from the issue link below. Also it seems to be transferred over from a totally different repo?

https://github.com/eu-digital-identity-wallet/av-doc-technic...

> Am I missing something?

Yes, that this post is propaganda.