Dutch digital identity system crisis
blogs.fsfe.org
blogs.fsfe.org
I've already said this numerous times here on HN, but it is a dark future we are getting into. The only thing that came remotely close to this level of "you require this proprietary software for daily life" level of danger was ActiveX.
This makes it easy for businesses like banks to work with those ecosystems and provide a secure experience without inventing much themselves. What's the alternative? SMS 2FA is abysmal. Maybe they could provide you a configurable webhook, but now they don't control the experience, and that's part of their requirements. Not to mention I wouldn't trust a bank to implement webhooks correctly.
The problem is we're becoming sophisticated enough as a society that we are forced to rely on a few establishments to maintain that sophistication. Whether it's for chain of security, microprocessors, springs in our toasters, it's not possible to keep everything open and interchangeable while maintaining our current way of life.
I'd love that, but it's not realistic, as far as I can tell.
There are cross platform MFA solutions that could be supported. Your guess is as good as mine as to why banks don't support them.
Is there actually anything wrong with SMS 2FA, other than SIM swapping?
SIM swapping isn't a problem with SMS so much as the phone carriers, who really need to put stricter processes in place for verifying account transfers. IMO, they deserve most of the culpability.
I don't really see point of SMS in flow, but hey I can somewhat live with it.
Lose your wallet with cards, lose your phone (or just a phone with Apple/GooglePay). Get a replacement SIM, be locked out of receiving any SMS for 24h[0]. Now be somewhere where is no local branches of your bank.[1] Or even better - be abroad.
Or just be in a taxi at 9PM when no one works and the bank locks you out - just like when it happened to me. Gladly I found an ATM where I could withdraw from a secondary account.
[0] Actual practice of cellular operators in my country. Safety
[1] Even better with the virtual banks without any.
I agree insofar as, this is exactly why I strongly believe that 2FA should always be optional. But, if the user has chosen to use 2FA (or has not opted out), what’s wrong with SMS?
Not quite because if you lose your YubiKey - you just lost your YubiKey, you still have the ability to call the bank (and my bank knows my number, so they greet me by the name) and at least do something, in the situation I've got in the previous comment I could lift the lock out with the code word, only if I could recall it then.
But the phone is not only your 2FA item, it is also your "virtual identity" now for too many services, banks included. And with the tendency of banks to shoehorn you to their phone apps this starts to get ridiculous, if you lose your phone you are now:
lost your banking app (2FA with push)
lost the ability to 2FA with SMS as a backup
lost the ability to install the app on the new phone (oh hi $username, it is really you despite you just gave your $username@gmail.com and password? We sent you an SMS to confirm it is really you, FOR YOUR SAFETY)
lost the ability to login to your bank account on someone's else phone (same shit with SMS to your phone number)
Bonus points: if you lost your ID or doesn't have it on you - you can't restore the SIM with your number. Or even buy a new one in many cases.
> But, if the user has chosen to use 2FA (or has not opted out), what’s wrong with SMS?
Pfft. I was forcefully shoehorned to mandatory SMS 2FA by my bank. I've opted out of this some years ago and it did work... till I was 600km from my home, I needed to buy the train tickets, I tried to logon to the bank webapp to move the required amount to the primary account only to discover what they enabled 2FA without asking. And the phone where my SIM (known by the bank)[0] was installed was literally on it's last 10% of charge in the airplane mode. It could literally shutdown just from the act of disabling the airplane mode so I could receive the SMS.
So if the problem is not with SMS 2FA. The problem is what nowadays "SMS 2FA", at least for the banking apps[1], is way, way more than just SMS alone.
[0] I'm not sure if they monitor IMEI of the device, but I wouldn't be surprised, considering they receive the notification of the changed IMSI.
[1] Not sure how these practices are widespread world wide.
* One-time-pads (yes, I had a bank that would give me a card with 50 codes you were supposed to use once, then go back to the branch for more. Didn't last long, though, and was replaced with:)
* Reusable codes: bank gives you a card with 50 codes. Bank randomly asks you for code number X. X may eventually repeat over time. (Bank also tells you your specific card serial number so that you can identify them).
* Credit cards housing an actual e-Ink display that would give TOTP codes. https://www.e-ink-info.com/e-ink-used-create-dynamic-cvv-cre...
* Actual FIDO devices.
What about N26, I don’t remember needing the app and I can log into a website. Not sure though…
It seems to be forgotten that email 2FA exists.
I can't quantify the risks relative to SMS 2FA because there are such broad ranging implementations but given the broad adoption of gmail, how many people can really snoop unencrypted email traffic at backbone chokepoints ?
There are many cases where I would be perfectly happy with the risk profile of either SIM swap attacks or email interception.
Even better, if you re-use passwords, they can use one password to access your email account and the service, and get the 2FA token via email.
Come on, we have open webbrowsers, which are 100x more difficult to implement than a chain of trust. Surely, somebody could come up with a reliable alternative.
Every time any HN discussion veers toward alternative smartphone OSes, for instance, people come out of the woodwork to talk about how they just couldn't possibly access their bank without an Android or iOS device... what are you all doing with your bank so often? I log in a couple times a month, from my PC, to check balances and pay my car loan. I've certainly never needed a damn app.
That’a all together with iOS FaceID enabler. Monzo is actually way simpler.
I've usually provided my phone number already, as part of the delivery address, so it's a click to choose MobilePay, another to confirm the number, then I fingerprint-unlock the MobilePay app and swipe to confirm the payment request that appears.
As someone who doesn't have it, it's very rapidly become the thing that makes me feel the most like a second-class citizen.
The British version (PayM) isn't used much, but at least you can add a phone number to your own account within normal internet banking, and send money to a number linked to an account without using either side using an app.
So, for most purchases it just doesn't trigger
1: https://en.wikipedia.org/wiki/Transaction_authentication_num...
I tried using the site of my bank but I could never make it work. There's no fighting it and it sucks.
I do recall seeing a popup at one point ("hey we see you've done some weird shit to your phone, call us if you don't knowewhat rooting means" or something like that) but that's really just about it.
I should try running it in Anbox, come to think of it. Would be a fun experience.
If you're a developer in the EU and you think you can do better, the PSD2 system is set up to allow for fintech solutions like these. You'll need to get the necessary documentation in order, or even a license, to get access to actual banking APIs (thank goodness) but from that point on you should be able to write your own app. You'll have to be very careful, though, you don't want to anger the financial regulators.
https://https://play.google.com/store/apps/details?id=com.in...
Also, I tried running the app in Anbox but there's no x86 build of the APK and Google's ARM Android emulator is just broken these days, the VM doesn't even boot.
I fear this isn't a temporary oversight but a sign of the long-term trends towards governments only supporting the major platforms. Those platforms will then complete the quid pro quo by "voluntarily" banning apps that the government doesn't approve of, like bittorrent, Tor, E2EE messengers, VPNs, etc.
https://arstechnica.com/gaming/2021/09/riot-games-anti-cheat...
Then there is the question about interacting with the hardware for reading the card as well.
Microsoft wants you to use their new APIs but they realised they couldn't force developers to do that. With their efforts for a mobile phone operating system dead in the water they've been more accepting of normal applications for a while now.
"Dutch civil servants used social media to spy on citizens, says study"
https://www.euronews.com/my-europe/2021/05/19/dutch-civil-se...
"Dutch secret service 'also has access to information from PRISM'":
https://news.ycombinator.com/item?id=5860215
"The Netherlands, a surveillance state?" (2017):
https://www.ictrecht.nl/en/blog/the-netherlands-a-surveillan...
"Sweeping surveillance powers planned by Dutch government" - "The Netherlands is already the most heavily phone-tapped country in the world" (2016)
https://www.irishtimes.com/news/world/europe/sweeping-survei...
"With a population of 17 million, the Netherlands is already the most heavily phone-tapped country in the world – with about 26,000 taps granted to the police and other agencies, excluding the security services, every year, according to figures from the Department of Justice."
The author of the article just made himself part of this list...
Not surprising, given that the Netherlands is the major port of entry for drugs into Europe - alone the port of Rotterdam had cocaine seizures worth 5 billion euros in 2021 [1], and Europol estimates 1500 distinct criminal organizations in the cocaine trade.
[1] https://www.nrz.de/region/niederrhein/rotterdamer-hafen-koka...
[2] https://www.nzz.ch/international/die-niederlande-sind-fuer-d...
Most recent government services operate via the web or APIs anyhow.
Plus suing for alternatives to Google/Microsoft duopoly should be front and center for fringe firms in the space.
Honestly, FirefoxOS received a lot of flak for not "focusing on their browser", but if it had succeeded it would have been a huge win for digital freedom and privacy.
EU member: lol, citizens get yourself an iPhone or Android or no digital services for you.
Yes, I am glossing over nuance here - but how short sighted is this approach.
Yes, the dutch government is itself perpetuating the situation, but they're only doing what private industry has for years.
And I just can't understand this logic?
1) Someone makes a platform, it's big and successful
2) State wants to overlord it, so they make apps only for said platform
3) State says platform is so dominant apps are only on said platform and there's no choice - must be regulated
Wtf?
1) Someone makes a platform, it's big and successful.
2) Private companies (banks, taxi services, streaming providers, education platforms) decide to only make apps for said platform, because the potential market of customers using anything else is too small to justify any business investment.
3) State says platform is so dominant apps are only on said platform and there's no choice - must be regulated.
4) State follows the same practices as private companies when making its own apps, for the same reasons as the private companies.
We're talking about an MFA solution, no? There's really no way to do that with pure HTML/CSS, you need some sort of TOTP generator.
IMO, this is why 2FA should always be optional, but the rest of the world seems to disagree with me...
Anyways, my government is sending me SMS for auth anyways and won't stop anytime soon. No need to introduce yet another requirement on the citizens.
In fact, intervention wouldn't have to be to change SMS. They could instead mandate a standard like U2F or FIDO2. If they really don't like those for some reason, EU states could get together and make a new standard and mandate that.
I'd be okay if they regulated telco carriers a little bit more than they already do; much more okay than with anything resembling what they're trying to do now.
Thoughts similar to this one are often deployed here - like this:
commenter A: This makes <problem related to surveillance> worse
commenter B: It's only incrementally worse, so it's OK. Besides <other parts of problem> mean there's no practical difference currently (at least if you've already basically admitted defeat about <problem> as I have), so what possible rational basis could there possibly be for not going ahead?
But many steps that make a problem incrementally worse can lead you to a bad place. Many steps that make things incrementally better would lead us to a better place. And with a tangled problem like this is by now, I think you do sometimes have to accept that not every step may always make a practical difference for many people, if you want to move towards a solution rather than forever away from it.
In this case I'm surprised to see you use the word "only" - government starting to mandate something is a significant step over even a duopoly doing so, because the cost of trying to ignore a government mandate can be much higher even than ignoring the smartphone duopoly - right? I can and do avoid the smartphone duopoly currently, but good luck to me if the government mandates it, eh?
Also given government power, in some ways it's a lot easier to make progress on knotty problems like this one than it is for a company, because government has a lot of power - so in that sense they have less excuse than private industry for moving us backwards here. Of course the public, though I think they see the problem to some extent, don't really believe in solutions yet. It's up to us to give them confidence that better solutions exist.
EU member: Hey IT team get us some sort of identity verification! (doesn't care about the details)
The nuance and knock on effects, costs, and etc of policy are often hard to account for, but big sweeping legislation sure is nice to think about.
Plenty of members of our community choose not to use a device that is tied to vendor-specific services.
What does phasing out of SMS have to do with this? SMS is using a device (SIM or eSIM) that is tied to (wildly insecure) vendor-specific services.
Further, a decent alternative, TOTP, is not iOS or Android specific. Nor are Yubikeys.
It's unbelievable to me how many people's accounts are tied to, and have been reassigned to bad actors by, their telco, and yet banks still think this is a lovely idea.
Pretty convinced the survival of SMS as 2FA is, as made clear by FB among others, excused "because we take your security seriously" but actually implemented for tying you to your data master record.
I don't know a second factor standard that provides the same level of validation. FIDO2 is probably more secure but it doesn't support the current security mechanisms already in place right now. I'd like the standard to be extended in some way, like Yubikey-like devices with screens to verify what you're doing with the necessary key attestation for government services, but we can only wait and see.
I'm not sure if these apps require Google Play services or not, but if they don't, I have no problem with them from a privacy perspective. You can run them in Anbox if you want and they're some of the lowest permission apps I have on my phone.
The real victims of this move aren't the privacy enthusiasts who run Qubes on their coreboot-enabled Thinkpads, they'll find a way. I'm worried about the elderly and other less technically minded who have no idea how any of these apps work. The government doesn't provide them any courses on how to use their services and neither do the banks. The layout and flow of the official apps keep changing and it's impossible for some to keep up. People say "well you should just Google it then" but that's even worse, because that's the easiest way to get scammed out of your money. Someone will definitely have paid top dollar for an ad that matches keywords like "how to log into bank" leading to a step-by-step guide on how to transfer all your money to a money mule.
There's also U2F of course, but in the absence of more pressure I guess that everybody who was using that will use FIDO2 or nothing (seems like a regression from my point of view - I don't have any need for passwordless login).
> The real victims of this move aren't the privacy enthusiasts who run Qubes on their coreboot-enabled Thinkpads, they'll find a way. I'm worried about the elderly and other less technically minded who have no idea how any of these apps work.
The real victims aren't any individual but society - the real problem is destabilisation through centralisation of power.
I can't login into the bank without the phone. Also you can't verify online payments in most locations without the app.
Previously the digital certificates were used.
Infuriating, and it's only going to get worse. And then the EU complains about Google/Apple's monopoly power - I wonder why...
Lacks the reference to a transaction. An attacker could send unlimited transactions for 15 seconds after you approved yours.
So an approved payment initiation services (PIS) can do transactions on your behalf. But you still want to have control over which transfers they actually send, so you want to make sure the confirmation code only works for a certain transaction.
https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-cl...
Banking IT seems to have their heads in the clouds of regulations, and risk aversion to even proven modern secure solutions.
At the same time they only allow a 5-digit pin as password for everyone, and as the phone is the second factor it doesn't have 2FA itself. The 5-digit pin is enough to access everything, you don't even need a username because the app is tied to the account.
It's obvious they just threw something together to comply with regulations.
Far worse, there is no regulation to force any of this it's just competition. Mostly by smaller "banks" with even worse track records concerning security.
If anything it'd probably give better grounds to prosecute the services that require Apple/Google.
I remember once when my bank didn't trust me enough to even have a debit/ATM card and forced me to go into the branch and queue up and show ID just to get my own money out of my account.
They should remove the dependency on Google Play Services, and probably publish the API details for any enterprising Linux nerds that want to make an app. If they did those two things I don't see any grounds for complaint.
https://france-identite.gouv.fr/
The old system worked fine and will still be necessary for the people who can't enroll in the new one, like resident foreigners who won't get a French biometric ID card.
One has to dig a bit, but as the proposed workflows use a smartphone app, it looks to be dependent on the Android/iOS platforms.
It looks a bit like what we also have in Belgium, but with more (or different) options and with an app that is not privately owned at least.
The fact they can figure out my kids’ ages based on their online behavior, and through their tracking and monitoring is fucking chilling. They don’t even use Gmail often at all.
You don’t see the problem with this?
See also, the millions of cookie banners that infest every web page because of the EU.
Government regulation is an attempt to make people aware this tracking exists: every time you see a wall, that means the site requires a level of tracking for which there exists no legal basis other than consent, thus it has to ask you if you're okay with that (like any ethical site should do anyhow).
Automated decision making is also part of GDPR but unfortunately is very very weakly implemented. Basically, companies just have to tell you it exists (if and only if it has a significant impact on your life), and then your only recourse is to request a human in the loop, and they will just press the same button as the AI did and you have no idea if they even looked at your case because the decision making doesn't have to be transparent. And that's only for important life things, none of this even applies to being banned from google account unless you sue them and get the judge to agree this has a major impact on your life.
How is any of the GDPR actually working out? Has it made a difference? Has it made the web better or worse?
As far as depending on Google - don’t?
It's not about using cookies
Have they made browsing the internet better? Have they decreased tracking?
They don’t have these checks in place for the fun of it. They’re usually legally mandated, otherwise some parent will sue them because “Google exposed my child to X Y or Z”
[1] https://support.google.com/families/answer/7106787?hl=en
And yet they are so fallible in their other forms of detection like fraud that lock people out of their accounts. The entire thing is creepy and maddening at the same time.
I think their system just blindly classifies every account as minor unless they purchase something.
Last year a big hosting company in the Netherlands introduced a requirement for existing customers to accept the Google TOS/PP before being allowed to log in. Support of course did not see the issue, like literally could not find it. I had to send them screenshots with markings before they saw that the google captcha they had introduced includes some small gray links.
This might not even be such a big deal if the privacy policy explained the data sharing that will actually happen. Rather, there is one fairly short document that applies to literally everything from hosted email to captchas to hardware in your home. Thus it has to say that they will use all gathered data for basically any purpose. Something tells me this cannot possibly be legal (iirc GDPR requires specific and understandable language), but that's the state of affairs.
(Another interesting example was me asking in a chat with ~100 people whether anyone had read the TOS update yet from our broker—the place where you keep your pension money and stuff. The only reaction I got was "anyone reads that? xD".)
Kinda bothers me that everyone is just going along with any terms for convenience. It's ripe for abuse and doesn't have to be this way.
Legislation asking (indirectly) that companies shove even more of these "Click here to read our cookie policy" type messages into everyone faces has only made the problem worse.
Disagree here. It's not gotten worse, it's gotten more visible. It's only ethical to ask people before tracking them, so any site should have done this already. This legislation forces businesses to act more honestly towards users in this regard.
Businesses impacted then take this and frame it in a manner of "we're very sorry that your government forces us to annoy you with this, but if you'd just sign here we'll be right out of your way..." and the vast majority of techies swallow it because it is, indeed, annoying to have to sign away privacy again and again.
It doesn't have to be this way. See the omission of a cookie wall on various sites that don't do anything that requires special consent.
How does this even work? QR codes don't magically change when they're printed.
[1] https://community.bahn.de/faqs/muss-ich-mein-online-gekaufte... (german source, just saying that it can be used in the app or in PDF form on your smartphone, tablet or notebook)
Tell me about it.
Or, wait, tell them!
> Het E-ticket dat wordt geladen op een mobiele telefoon, tablet of laptop is alleen geldig als vervoerbewijs als het duidelijk leesbaar weergegeven kan worden op de mobiele telefoon, tablet of laptop.
https://www.ns.nl/binaries/_ht_1553092893605/content/assets/...
It seems that requirements to "consent" to TOS for things like major transport systems (government or not) or government health services (NHS services in the UK for example) just aren't consent in anything but some technical legal sense.
> Kinda bothers me that everyone is just going along with any terms for convenience. It's ripe for abuse and doesn't have to be this way.
I think it's not so much convenience as a change in the laws of the game? With TOS presented human-to-human, people in the past would have been more likely to react in a human way to the person offering them the TOS, businesses and governments would be constrained. Even if they got TOS in the post, there was a human in the loop to complain to and argue with. With TOS online, it's a fait accompli, which changes the costs to both parties.
I don't really get putting cryptographic IDs into citizen identification. There's not much it provides other than, "well someone had this ID and knew some pin when this ID was used".
The unfortunate side effect of this is, less technical people might see a digital signature as a full and complete proof. While it definitely is not.
It's far better than the status quo where easily forged documents (passports, driving licences, utility bills) that have a validity period of 5-10 years are considered infallible proof of everything.
Let's say that you want to implement age verification - all you need is for the card to sign a challenge saying that the user is old enough (which the backend can verify based on public keys published by the government) without having the card reveal anything else.
One outcome of the legal cases and appeals is that any government organisation using the card / database for identity verification (lots tried to make it the only form), must make an alternative approach available that is as convenient. The reality is that the alternatives usually require you to present in person and staffing levels have been lowered during COVID / because many people have switched to the digital system.
So there is a trend across Europe to implement this. I personally feel, that in many cases the investment in digital solutions is worthwhile (it's painful watching government employees type in information that the organisation already has access to - wastes time for everyone). BUT... It has to be done in an open, transparent and legal manner.
Highlighting the issue at an EU level, may result in frameworks that deliver the best solution for all EU citizens.
Libraries: Adobe Experience Cloud, Google AdMob, Google CrashLytics and Google Firebase Analytics
Domains catched so far: ajax.googleapis.com android.googleapis.com auditrecording-pa.googleapis.com clientservice.googleapis.com connectivitycheck.gstatic.com crashlyticsreports-pa.googleapis.com deviceintegritytokens-pa.googleapis.com doc-0k-ac-docs.googleusercontent.com firebaseinstallations.googleapis.com lh3.googleusercontent.com www.googleapis.com assets.adobedtm.com oms.dowjoneson.com 2.bp.blogpost.com firebase-settings.crashlytics.com s.webtrends.com statse.webtrendslive.com
To sum it up: googleapis, gstatic, googleusercontent, adobedtm!, dowjoneson?, blogpost!, crashlytics, webtrends, webtrendslive
Plus, the system is based on providers, so you have to go through many burocratic steps to get recognized and then you pay-per-user/year that can go up to 7 Euro/user
How is a phone app in a walled garden a better option for official authentication than the identity card you already use to identify yourself in all other official acts?
Iff this would have been opened up a third party provider could make something available on any platform (with requirements of course). Won't solve the problem but at lease someone would be able to instead of no-one.
We’ve lost the battle for privacy, were never likely going to win it from the get go imo, so let’s at least use it to our advantage
There's no reason to believe spam would stop if an online ID tied to a social security number is implemented.
Otters banging rocks, my friend, otters banging rocks.
Have been an architect on citizen identity schemes, and the conversation in govt that happens is mainly about whether to design and impose a new card based system (or similar) that has every forseeable feature they might need for the next 15-20 years it will take to get them out of circulation, and then write a gateway for it that applications have to integrate with - or federate to peoples' existing IDP's like banks, social platforms, and mobile devices using open protocols for authentication (SAML, OIDC), and then kick the can down the road on identify proofing for those credentials.
There are obviously tons of other factors and moving parts, but resolving this conversation within institutional governance frameworks is pernicious. A great example is that the legislative mandates of different government agencies may prevent them from sharing information about a citizen between them - because from a privacy perspective, there is no reason one agency should be able to use others to collect intelligence about you, because their only job is to provide you a service, and that is strictly prescribed.
The way we did it for federal services was a SAML federation between online banking and the federal government login, using a proxied MBUN (meaningless, but unique number), which has been in operation for over a decade and has been an acceptable privacy solution for all involved.
We don't have universal domestic identity cards in Canada because, like Germany, and other countries post WWII, we have a memory of how internal passport systems get used. The internal vaccine passport scheme for covid is wildly out of line with privacy legislation and outside the remit of government to institute in many ways, and was pushed through using emergency powers, and you can see how it has lost some momentum, but be assured, it will be back, this isn't their first rodeo trying to get national identity cards imposed, and these people never seem to give up.
We have a public health care system with cards for every eligible citizen, but the legislation for the cards explicitly defined the ID cards as not legal to use as any other form of identification (which again, may have changed during the pandemic), because using healthcare to impose a national identity system has historically (80s, 90s and into 00s) been seen as totalitarian, literally, the gesunteitpass/ahnenpass of a former age. Canada was where people escaped to from those regimes in the 20th century, and memory of them is still part of the national culture.
Also, where do you think identity comes from? Your name is from your family, birth certificate is issued through a hospital, your baptismal certificate by a church, your childhood vaccination cert by a municipal public health unit, drivers license by a DMV, your tax id and passport through a federal govt service, etc.
Your "identity," is not a document or a real thing, but rather, attributes associated with relationships, and even if we use biometrics and tag a guid to that and put it on some stupid immutable blockchain, it is still an artifact of relationships that are not the same for everyone. Anyway, there are maybe 1000 people in the world with similiar knowledge on this topic as mine, so please, AMA.
Germany does have national identity cards though.
The whole "no ID card" is a very peculiar Anglo-Saxon thing: US, UK, Ireland, apparently also Canada. Of course, you have passports and driving licenses, so effectively almost everyone does have ID, just less conveniently.
The difference is whether the ID is for a specific service and purpose, or a single identity with a general ID regime to be used at the discretion of police and other institutions. It's a significant legal difference.
What you refer to as a peculiar anglo-saxon no-id-card thing is also what we typically call freedom. The nordic countries have had ID cards forever as well, but also public salaries and other socialist policies that worked for them very well, so aversion to them is not necessarily a "white"/west thing. Freedom is not a value unique to any one culture. What's happening today is technology changes are being used as a pretext for pushing in more radical state controls just using the tech, but without legislative discussion about whether it's desirable.
We're not talking about unavailability of government services, there's still a process available, the analog one.