European governments are rolling out digital identity wallets, which are to be used by citizens to access services, and to verify their age online. As reported by Follow the Money and Android Authority, there is a serious problem with this: these wallets rely on safety services of Google and Apple. These are known as Google Play Integrity API, and Apple’s Managed Device Attestation. Such safety services (known as “remote attestation”) are used to ensure that wallet apps run on hardware that is not tampered with. In this article we explain why the EU-wallet case is part of a bigger problem: by embedding these safety services in public infrastructure, Europe risks making society dependent on private companies while serving their corporate interests.
↫ Danny Lämmerhirt
Setting aside the age verification nonsense, the fact that some European government are tying their identification services to iOS and Google Android is absolutely bonkers, especially in this day and age. There’s endless talk about reducing European dependence on the American tech giants who seem all too eager to do roll over when the Trump regime so much as glances in their general direction, and yet, they seem to want to effectively force us citizens to use American tech products.
Essential online tools, like banking, government services, communication services, digital driver’s licenses, and more, should not require the use of iOS or Google Android.

Let’s put this into context. When actual lives depended on it Apple (and Google) used their power to protect their monopoly and gather additional data to sell.
The UK National Health Service developed a Test & Trace (Covid tracking) app and Apple refused access to the Bluetooth stack in the name of “privacy”. Months later (April 2020) Apple (and Google) developed their own systems that used those same methods. But this time charged for their usage. UK was forced to redevelop the app and use their services for covid tracking taking months. This decision cost lives.
Putting you’re trust in corporations who have already shown you how they will act in a crisis is, to me, naive
Edit: I first posted this with source links but the comment then got blocked for it. But not much duckduckgo-ing will bring it all up
An app designed to track people was refused, and you’re saying that refusal costs lives? Really?
Here in Sweden Palantir has a new contract with the Police. Swedish citizens biometry is being used to train Palantirs AI. Good times.
Government made a “mistake” by not realizing how big the Internet would be.
Of course they should not be blamed for not reigning in quickly. Who could have foreseen a global scale network connecting the entire human existence with low latency series of tubes, would actually be useful outside of toys like finger, ping or mosaic.
After all even great visionaries told it would be a novelty, and have less relevance than the fax machine.
Today, they cannot repeat the same mistake. As there is an opportunity to save the kids and think about the safety of the populace, the great governments of the world agree on one thing: too much freedom is harmful for people.
We should expect new and more intrusive innovations in this global digital age that will protect us from the evils of federated, free, peer to peer communication and data exchange. The wild west cannot be tolerated.
[/s]
“open, hardware-based attestation mechanisms” is an oxymoron. It makes sense for the government to do the attestation themselves, but it changes little for end users.
A lot of people left comments on the EU Age Verification App’s GitHub page but the developers ignored them
Huh? As far as the government is concerned, I do not have an Android or iOS phone, I have a Nokia 5110 phone with a monochrome LCD screen
What happens if I refuse to install the government’s (cr)app? The UK government can demand from EU citizens wanting to travel there to install the ETA app because immigration is a privilege, not a right. But as a citizen, how will the Greek government (for example) force me to install their (cr)app?
Easy. Look at Turkey. Their government asks everybody who stays more than a few months to register their IMSI number; otherwise, your phone is banned from all local networks. The same in Kazakhstan. The same will be in Russia next year. At some point in the future, your phone would be banned from the network if you don’t have government software, for example. What, you can’t install it? Your problem.
a_very_dumb_nickname,
And “IMEI” cloning is expressly illegal. So you can’t assume “I’ll just duplicate burner phone ID on a top end Xaomi”. They will probably use their existing nationwide IDS to easily detect what happened.
Do you really want to risk going to jail over “freedoms?”
That is the burden many of us will have to face soon if we do not stop these embarrassing laws in their tracks.