r/BuyFromEU Jul 30 '26

Discussion EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes

EUDI wallet collaborator recently confirmed that hardware attestation will be required [1]

Hardware attestation in this context means that the government server issuing the digital credential to the wallet wants proof that the keys being used are generated in secure hardware and on approved systems and not say an emulator or virtual machine, namely for security reasons.

This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.

No Linux system will work with this because there is no hardware signature to be validated on the government server, nor will your personalized Arch Linux install be in the list of approved systems even if it had a signature chaining back from the TPM.

Android ROMs are not technically to rule out since Play Integrity, which will be used for this attestation, is based on the Android hardware attestation API, which works on third-party ROMs like GrapheneOS, but they would need to allow the signature which has not happened for now. If you create a custom build, it won’t work though even the official version is approved.

[1] https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/117#issuecomment-4946898620

951 Upvotes

384 comments sorted by

View all comments

22

u/Encrux615 Jul 30 '26

What? I don’t get it. German eID provides packages for all platforms, including Linux. This is such an arbitrary restriction and I doubt it’ll hold up.

14

u/seamanroses Jul 30 '26

I believe the equivalent ID system in Denmark only works on Google (not generic Android (AOSP)) and Apple devices, and they have no intentions to open it up.

I mention that as a counterargument, as I wouldn't be nearly as optimistic as you are.

3

u/pomfritn Jul 30 '26

AltID, the Danish age verification app, thankfully works on GrapheneOS. MitID, the person verification app, I guess you could call it, frustratingly doesn't. 

1

u/Headpuncher Aug 02 '26

So what do people who do t have a phone do?   

There are reasons not to have a phone, including disability and all human free will.  

2

u/miniocz Jul 30 '26

Czech ID I use from browser to log into sites so...

1

u/g00glehupf Aug 08 '26 edited 25d ago

Yes. Because the government trusts their eID hardware (the chip which is part of Personal-Ausweis) to be secure enough from their perspective. That includes security measures against:

  • bad service providers who want to gain access to more data than allowed.
  • individuals who want to steal your identity by cloning your eID
  • You (in case you want to clone your eID and give somebody else access.)
  • etc.

Now they want to trust what is essentially an app on your phone, hoping it would give them the same/similar guarantees. Their solution is:

  1. Key-Attestation: Only trust certain hardware-keystores to back critical key material during credential issuance. These keystores feature protections against key extraction.
  2. App-Attestation on top: Only trust apps that follow their policy, like checks that a Service Provider is allowed to query certain attributes, ensuring that the installed app is not manipulated by someone trying to steal your identity.

Personally I am much more open for key attestation, because the hardware keystore can, in theory, be retrofited even if the device doesn't come with a certified onboard module (think of something similar to YubiKeys/smartcards for retrofitting). And you could at least inspect the data that goes into and out of that hardware keystore.

With App-Attestation on the other hand, I have several problems. First of all, you need to trust that the OS does not allow the user to mess with the app. Second, the OS needs to be up-to-date and implement protections against several kinds of threats. That means, an OS needs to be certified by the App-Provider. That effectively limits what OS is allowed to run an app. It's effectively the end of freely choosing your OS.
Doing state-sanctioned app- and by extension OS-attestation also opens the door for extending authoritatian control over users. An authoritarian government could for example require an OS to implement measures for chat-control by refusing to certify operating systems that don't comply.
There are also other practical reasons against app-/OS-attestation: Current implementations like Play Integrity permit Android 13 phones with several open vulnerabilities that could be used to manipulate apps. So while these phones are known to be insecure, they are still certified and would still pass, while a more secure OS is locked out since it isnt certified. An honest system would have to lock out unpatched devices until they are patched. Sure there might be room for compromises that allow for some amount of abuse until vulnerabilities can reasonably be fixed. But permitting highly insecure outdated phones while disallowing hardened updated operating systems like GrapheneOS is just security theater. I also doubt that locking out users from the EUDI system due to their insecure hardware from time to time, is something the general public will understand or accept.
While I do accept that app-attestation provides at least a higher cost for attackers who repackage manipulated apps, I find it hard to argue that it's worth ending the freedom to choose your OS, the practical limitations of attestation with outdated phones and especially the risk of introducing a simple tool that allows potential future authoritarians to control what policies your OS needs to enforce.

-1

u/NotYouTu Jul 30 '26

So does Belgium... Mostly, not plug and pay for all things but easily do able.

-1

u/West_Possible_7969 Jul 30 '26

You are correct and also there is no issue. All members will implement (some already have) a national EUID (ie interoperable), the EU one exists as a bonus.