Student IDs on iPhone and Apple Watch Expand to Canada and More US Universities
apple.com
apple.com
So this is awesome on the part of Apple, but what about Android? Are student ID's on Android already a thing? Are they being developed?
Or are there unique aspects of Apple controlling the hardware that inherently make cards like these more secure on Apple, that Android can't match (but maybe Pixel can)?
> You can add your campus ID card to your Android phone to securely access your residence hall. You can also use your campus ID with Google Pay to pay for things on campus such as dining, laundry, vending, books, and more.
I really wish we would have stayed with the Google Wallet moniker. Seeing that you can add student IDs, Walgreens Card[0], Vaccine status/card[1], various metro cards (like Japan's Suica[2]), it is more like a wallet than a pay app at this point.
[0] https://www.walgreens.com/topic/promotion/google-pay.jsp
[1] https://support.google.com/googlepay/answer/10890261?visit_i...
[2] https://blog.google/products/google-pay/add-suica-and-waon-g...
But then I wasn't sure if they just branded "any NFC pass you can put in your phone" as "Google Pay" which would be stupid but believable. Thanks for confirming.
Personally while I like the idea of digital ID, never losing your cards, almost-impossible to get stolen, I don't like the idea that if someone (i.e. a LEO) needs to see my information, I might need to hand them my device, and in a some jurisdictions could be considered granting consent to a search. I also don't like the idea of what happens if your phone is damaged or the battery dies and it contains your only identification.
The second issue, I completely agree, I would rather the system be an addition to existing IDs rather than a replacement to them.
I don’t want cash, a wallet, plastic cards, metal keys, or tons of slips of paper from receipts and all other kinds of bullshit.
Putting it on the phone as a native app is hardly complex. Use QR codes, an officer won’t need to look at your phone
But what if I have neither iOS, nor Android? Why must the government/universities support the duopoly?
Librem5 runs (can run) Anbox, to explicitly support Android software applications.
Also, Anbox is not perfect - even some basic UI elements are broken (in the version I use for development). But it is good to have it.
Also, with 3GB of RAM we are not very far from a point of struggle with the resources.
Virtualization: I would like to see some benchmark results of the "NXP i.MX 8M" to roughly compare to the x86 Anbox experience, but I am not finding much data.
See also: https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...
"No longer needing a wallet" isn't a marginal gain -- it's a huge step forwards for convenience, security, and even safety.
[EDIT] and of course a sleeve on a smartphone is even harder to lose than a separate card holder. Plus, it comes with find-my without needing to buy some kind of extra bluetooth tag or something.
But individual cards are really easy to lose. Probably a mini front pocket wallet would be a reasonable option but fewer items is still better in general.
And physical cards exist as a fallback.
It's not about "supporting a duopoly" in the sense of entrenching it -- it's simply about cost-effectively supporting the devices students already have and use.
Android is an operating system for a bunch of OEMs who don't have secure elements in their devices, and even ones who do still exist in a fragmented ecosystem where their verification doesn't include ones outside their models. Modern chips have a similar feature, but the key management between manufacturers is an unsolved business problem. There are technical ways to solve it, but higher level interoperability beyond enforced standards has never a high priority for OEMs. The economics haven't been there.
You could make an inferior one for Android devices, but it likely wouldn't be sufficiently secure to handle payments, credit, taxation, fines, social compliance scores, and other use cases for identity. Identity security needs to be strong enough to be used as a stick, and the only carrots it offers are those whose scarcity is artificially managed.
Realistically, if you are attending a university, the cost of an Apple device can just be priced into your loan, and strategically, making university student products consolidate Apple's dominance of the middle class market and up, and as a status symbol of societal membership, sort of how Facebook started in the college system.
I'm skeptical of digital identity companies (as distinct from authentication services) because to me their entire business model reduces to Hollerith machines as a service, so YMMV on this view.
I'm also laughing that you say Android isn't secure enough to handle payments. Millions of people use it to do so every day.
I'm sure there are lots of Android pay solutions, but the risk profile is very different, the solutions for it are limited, and keys in software has a catastrophic failure mode. What's very likely is Android payment solutions are taking a fraud management approach with some kind of government backstop, as from a technical security perspective, software has hard limits.
It's not a monopoly if it's only for university educated people who get access to exclusive services. You can start your own managerialist economy.
What if the cop drops your phone walking back to their car to take down your information?
What if the cop creeps through your messages while he has your phone?
Personally, I'd rather just have a piece of paper ready.
I assume there already is, and the paper requirements are just something for people to trip over and trigger other suspicions.
The cop actually does not even need to know about insurance at all. The state charges everyone a yearly tax anyway (“vehicle registration”), they could easily just not let people renew this registration if they don’t have insurance.
Apple Wallet should be one of the first. Nobody is buying Apple devices for Apple Pay alone. They already realize the benefit having Apple Music be cross platform.
In the digital world the databases are accessible from anywhere in the world. Significantly larger attack surface, and we know for a fact no software, especially Apples, is going to be secure enough.
Governments have shown they cannot be responsible with even social security ID's. I hope they do not draw Inspirstion.
1. Most physical identification documents are trivial to fake.
2. Possession of a paper/plastic document means for a nonzero period of time you control the only valid one of its kind. A digital ID can be immediately revoked thus reducing the possession time of a hacker.
3. Digital ID’s can be protected by on-device biometric authentication. Yes “physical access is total access” but it takes more sophistication to exploit a properly protected digital ID
4. People today are more apt to lose a physical document over their phone, which is also easier to locate when lost.
5. Your state likely sells their drivers license database. Yes that’s right. Ever wonder how some business require valid ID to open an account? They check the info on your card against their copy of the db. Hackers don’t have to hack the government to get the info on your ID (and exploit it) there are myriad targets that can be exploited.
I personally trust Apple more to actually want to protects users' information rather than try find legal loopholes in protection mechanisms to aid their business model.
Targeted attacks are no longer a "rarity", it's the natural result of having singular software platforms. Iphones are very popular, and very wealthy and powerful people use them, therefore they become a very lucrative target. Snowden was talking about the Pegasus project before we even knew the name of it. The ability to just exploit someones phone via a text message, no user interaction. There are plenty more where that came from, don't worry.
After fall 2022, the EU plans to do a pilot of the EU digital ID. It would "let users store electronic forms of identification and other official documents, such as driver’s licenses, prescriptions and school diplomas." [1]
https://apnews.com/article/europe-health-coronavirus-pandemi...
(i am a beta tester in a state digital ID system rollout)
There's a single "Mobile Citizen" app and there you download various kinds of IDs into it, by logging in to the relevant website for that ID.
Though you can't use it in place of your ID card, it's enough to get you through I.e. police identification. You can also download your driver license, student id, European covid passport, etc. onto it, and those do count as the real thing.
I totally get the convenience angle, being an Apple ecosystem dweller myself. However, with more and more of identities, payments moving to a single device the recovery workflow should be hassle free.
With physical documents, my IDs are spread out so if I lose my drivers' license I can pull out my passport to get a new one. How will it look like in Apple world? I haven't read the recovery workflow documented anywhere.
Imagine being on a business trip say ~5 years down the line and losing your phone. Your hotel key is gone, passport is gone, no money, no one to call, no app, no internet. Now what?
On the note of charge, Apple has recently included a feature that lets certain cards work even when the phone doesn't have enough charge to be normally used. It seems they shutdown the phone before the battery is entirely depleted, reserving a small amount of charge to be used for these cards.
https://support.apple.com/guide/security/express-cards-with-...
Perhaps Apple Wallet will act as a secondary but a fast path access and I'll continue to carry physical IDs but don't have to pull them out for most of the cases. That is how I used Apple Pay. I carried bank card with me but used Apple Pay 99% of the times.
That said, I don't really like a single electronic device being such a single point of failure. (And, to be honest I find taking out a card easier than Apple Pay most of the time.)
Yes, that would be more expensive if you don't already have multiple devices. I'd wager than many people here on HN (who are in the Apple ecosystem) have at least 2 devices on which they could add payment/IDs/access (Apple Watch, iPhone, iPad, MacBook).
Or is this yet another case of Apple's APIs being too limited, so they made themselves yet another loophole rather than fix it?
It's also PR.
The problem was it didn't reliably open doors, which is really the only thing you want from an access control system.
Apparently at the time NFC was for Apple Pay only, so the vendor had to use bluetooth; and apparently there was no way for them to keep their app running and the bluetooth radio running all the time. The Android version was no better.
Within a year they had switched back to plastic ID cards.
There is no API to send raw APDUs to a card or simulate a card (receiving APDUs from the reader). This makes it a non-starter for implementing any kind of smart card (such as receiving a challenge from a reader, signing it with a private key stored in the app - potentially delegated to the secure element - and returning it).
The APIs they provide only allow reading static values off "NFC Forum" tags which is useless for any kind of security or access control.
Still can't create payment apps though. No idea if this would be sufficient for an access control system.
My university uses Google for many of their online services. Due to Google policies/recommendations, it de facto will not work on an Android Phone without Play Service, as IMAP is considered less safe and by policy is forced off, and since Google de facto makes it impossible for any app to use OATH outisde of Google Play[1]. As a result, I have no access to my University email on my Android phone, since I refuse to put Google Play Services on it (As an aside, it ironically works perfectly on my Pinephone).
My university also forces a 2FA App called DUO Mobile. In the default configuration, you are forced to use an Android with Googple Play Services or iOS app, and we were forced to turn it on. Thankfully someone was able to figure out it's protocol to allow it to be used on other apps [2]. For a while, DUO did not even support Firefox, so one was even then forced to use Chrome to sign in online with a U2F Device.
While the digital ID is introduced now as an option, it wouldn't surprise me that this will be forced on students in 5-10 years, and now by default, they need to buy an Android/iOS phone to attend a University, then are forced to the Privacy Policy of companies that they have no choice for.
Consequences of forcing Google or Apple on students aside, another unintended consequence I worry about is students who come from poor income backgrounds. One of my dear friends from college came from an extremely low income family who could barely afford to help her through college. She did not have a laptop because of the price, and used the computer labs on campus to do all of her computer work. She didn't have a cell phone either, also due to price. I get that a cell phone/cell phone plan is increasingly becoming a necessity, but I seriously worry about people for whom that is yet one more barrier to entry to college.
[1] https://github.com/M66B/FairEmail/blob/master/FAQ.md#user-co... [2] https://github.com/rcslab/duo-cli