Hacker News new | ask | show | jobs
by Deukhoofd 18 days ago
This entire issue is a disaster of a Github issue. It looks like its on the entirely wrong repository. I did eventually find the text in another repository; the one for the Android reference implementation: https://github.com/eu-digital-identity-wallet/av-app-android...

It was removed from there to clarify the entire "Hey, this application is not done yet"

It being in the reference implementation instead of the spec is a massive difference. One means that it's just there to show an example, and we should push national governments to do it better in their implementations, while the other would mean that it'd be a requirement for all implementations, which it doesn't appear to be.

It also looks like the reference implementation removed that functionality entirely several months ago: https://github.com/eu-digital-identity-wallet/av-app-android...

2 comments

In my opinion the whole "it's just a reference and national govs can decide" is a nonsense excuse to diffuse blame in a circle. The only outcome is that national governments will closely follow the reference and reuse the decision, the citizens of each country then have to manually complain to their own government individually, at which point they might get ignored because, well the reference implementation has it or talks about it, so they're just following the recommended security requirements, and who are you anyway to be demanding our system get less secure are you some kind of cybercriminal?

Play Integrity is still recommended to be evaluated in the documentation, with no mentions of its consequences. https://github.com/eu-digital-identity-wallet/av-app-android...

Honestly, root detection is a cat and mouse game. So many ways to spoof it. Same with Play Integrity. If the goal is to prevent bad actors, it will never work really. It will be just a big headache for the citizens. Look at how gatekeeping certain websites is working. VPNs became mainstream. So are proxies too especially for bad actors. Malicious actors have just to pay up a service to do so. And I am sure it will be the same with Android (it already is with keyboxes you can purchase to spoof play integrity)