"Holder Binding" of the e-ID - Implementation for Android and possible alternative solutions #53
Replies: 3 comments 3 replies
|
As has been argued by Daniel Micay, the whole point of this exercise is ultimately "to protect against people tampering with the app, not security". So point 4 above
should actually be the first point since points 1–3 are simply done to be able to trust the signature check result of the OS, IIUC. Or as Daniel Micay puts it: "The whole reason they're doing this is trying to enforce using an OS which enforces the expected security model which most alternate operating systems are known to not be doing." |
What will happen to a user already registered when its device won't receive any more updates from the manufacturer ? |
|
Having discussed with several folks from BITS at the participation meeting last Friday, and given my issue that I want to use the eID, but the swiyu android app doesn't recognize Sailfish OS as a secure environment, and given that the Android platform soon may become even more restricted, I'd like to re-launch this discussion to help out the BITS and make it possible to use the eID outside of the US-controlled platforms (Digital Sovereignty). Having had the opportunity to chat with other participants of the civil society as well as the BITS & team swiyu itself, here are some ideas that got pondered and the concerns raised by various stakeholders below. Before I commit my resources to any option, I'd like to at discuss with the swiyu project members on a course of action that aligns with their plans and would not fail due to either self-imposed or external constraints. Discussed solutions:
Concern & Limitations raised:
Prior (Wallet) Art:
So before I waste any (more) of the BITS' limited resources or mine own, could we please align on if there is any further options on the table and how best I could spend my time to work towards getting a solution as soon as possible if not on the same launch day as the eID that does work on other platforms than those of the increasingly unreliable transatlantic partners? What solutions would have any chance of getting either automatic certification (because they are developed as swiyu projects) or at least have reasonable chances of getting certified if developed outside these repos? I'm very concerned that sooner rather than later, my lack of access to an eID will exclude me from being able to participate in public life, like Twint that has already in some circles started to become the only accepted payment solution (no cash or credit cards) and I can't use either. The latter is from private company, so I can't really do much about that except complain to those that us it as the only payment option, but the eID is a government issued solution, so as a citizen I feel obligated to participate in finding and implementing a solution, even if folks like me still only represent a niche of the population. |
Uh oh!
There was an error while loading. Please reload this page.
We would like to continue the discussion that arose from the ‘Add to F-Droid’ issue here, summarise the most important points and address any questions.
The legal provisions apply as requirements for the technological design of the e-ID, namely that the link to the holder must be technically verifiable. For other types of credentials, different forms of attestation can be implemented.
For Android operating systems, we defined the following requirements in our blog post from August 2025:
For these checks, we will use the operating system's API rather than Google's Play Integrity service.
The measures listed are intended not only to protect users, but also to prevent devices from being manipulated in such a way that they can be misused as ID proxies.
We are aware that only a limited selection of operating systems and devices currently meet these criteria. We are monitoring which alternative solutions are being developed in the EU and elsewhere in order to allow other devices and operating systems (see discussion on Linux smartphones). Suggestions from the community are very welcome in this discussion.
All reactions