Hacker News new | past | comments | ask | show | jobs | submit
All governments are "doing something". It just isn't at all effective and mostly because they're unwilling to invest even marginal amounts.

Like in this case. The technology here utterly depends on Google Play Services on Android or App Attest on Apple (or "secure enclave"), and that is in fact essentially the only functionality.

This could have been solved instead switching to a standard (switching to OATH, RFC 4226 and RFC 6238), thus killing the dependency on Google/Apple while still allowing those devices to work smoothly, but also allowing a Linux implementation, allowing anyone . Plenty of European companies provide implementations for this, some with and some without the dependency on Google/Apple attestation.

I'm not talking about some abstract sense of "did the government do anything at all today", I am saying "good on the government for doing something in this specific case instead of doing nothing and letting it be sold", which was a possible outcome, and in fact the default outcome of the vast, vast majority of acquisitions is that the government does nothing to intervene.

Could they do something better, sure. I am still glad to see they did something at all.

I can sign in to DigID without using my phone, except sometimes with an SMS verification code. (Of course they want to, and should, phase that out. Hopefully that won't be replaced by app store dependence.)
loading story #48281166
loading story #48281317
Uhm, no, DigiD works without Play Services:

https://www.logius.nl/actueel/qr-code-scanner-digid-app-werk...

(Also works fine on my GrapheneOS phone with only basic integrity, also worked on microG when I tested.)

{"deleted":true,"id":48279446,"parent":48279231,"time":1779801467,"type":"comment"}