What about being required to carry a your-own-government-controlled tracking device?
Because the US or Chine government can't harm me in Europe via the data they collect from me, But the EU authorities can if they want to, so naturally I fear them more if they were the ones hoovering my data.
What are the odds they're using this on-shore tech grab to implement their own domestic version of China's social credit score system, to easily get data on their own citizens who commit "wrong-think", without having to through the effort to twist the arm of US entities every time they want to do that?
Food for thought, but I do think we're living the last years of online anonymity, it's inevitable.
Now imagine being debanked by your own government because they don't like what you're saying and becoming unemployed, homeless and dead. I don't think they're remotely comparable.
For example, a few years ago, a power tripping gov bureaucrat turned off my unemployment payments over a technicality. Luckily, I had enough money to pay a lawyer to sue them and won, but it was tight. What if I hadn't had the money to hire a lawyer? Since I was in a foreign country, with no family or close friends to fall back on. I was exclusively relying on the welfare state I paid into for years, that then turn its back on me for shits and giggles.
So I don't think you understand just how bad it can be for you if your government decides to turn on you and fuck with you, if you're comparing this to losing access to your work email account.
See the famous case of UK postal workers that got fucked by their government trying to hide their mistakes.
Since when is google a bank?
>The only solution is untraceable, permissionless money, like Monero. Why do you think governments try so hard to ban it?
Because untraceable currency is mostly used by criminals for crime.
How is this comparable to your government debanking you meaning that no bank, landlord, layer or job will touch you?
It's as close as you get to a complete shunning from modern society. You're reset to the cash you hold on you and keep custody of. And yes. In the U.S., the list that manages who can and cannot transact is centralized under OFAC. So it is at the whims of Executive whether or not any financial activity can be done with you.
Luckily in most European countries renters are protected and they cannot just kick you out of your home for missing one rent payment (IANAL, but in NL it requires 3 months of no pay and a judge has to approve). Most likely they wouldn't approve if you missed a payment because you were locked out of your banking account.
It is not unreasonable for governments to pursue avenues for laundering money. I recognize that you likely don't believe governments should prosecute money laundering, but that view is not aligned with the majority of citizens in your country.
The government can prosecute money laundering and all the other crimes, but it's not an excuse to impose extrajudicial punishment. Until they stop, having some cash and crypto is your only means of defense.
I'm unsure about your reference to extrajudicial punishment, is it referring to de-banking associated with AML and KYC regimes in the US? If so, I agree that unjust things are unjust. I believe we should seek to fix those injustices directly through lobbying lawmakers, rather than rejecting an entire system that has significant security benefits.
I am sympathetic to people who have a fatalistic attitude when it comes to political reforms. Having other financial instruments as a backup is a good practice.
It's not entirely hopeless I guess. For what it's worth, the US government recently issued an EO that purportedly stops banks from debanking you for political reasons. Hopefully a future administration would take care of the other part.
In 2025, North Korea managed to steal from the world over 10% of its GDP worth in cryptocurrency.
Of course in this judge's case there might still be some banks who are willing to work with him even at the risk of getting sanctioned as there weren't language in the news that he was completely debanked which I assume they would highlight if it was the case.
They lost access to everything american, including Visa and Mastercard. It's in french and maybe not the best source but it's not paywalled :
https://www.tf1info.fr/international/nous-sommes-attaques-le...
> "Payments are mostly cancelled," he continued, "as almost all cards issued by banking institutions in Europe are either Visa or Mastercard, which are American companies."
They are not completely debanked since they can go to the bank and withdraw cash, but it's a crippling situation to be in.
You don't have to imagine it.
Alina Lipp, Thomas Röper, Xavier Moreau, Col Jacques Baud, Nathalie Yamb. The last two are Swiss nationals. The Baud case is interesting because he's a Belgian resident who now can not even buy food or pay his bills while living in his own home.
The EU commission just passed chat control to have government mandated software in every phone
https://www.eff.org/deeplinks/2025/12/after-years-controvers...
The most recent related information I could find was some movement to extend the temporary derogation of the ePrivacy Directive, which expires on 2026/04/03, to 2028/04/03 but even that did not seem to have passed yet. [2]
The very fact they're trying to extend the temporary derogation hints to me that they think it'll take some time yet to pass Chat Control (if at all).
[1] https://oeil.europarl.europa.eu/oeil/en/procedure-file?refer...
[2] https://oeil.europarl.europa.eu/oeil/en/procedure-file?refer...
In some areas, sure - like GDPR.
In other areas, absolutely not - like chat control.
As another commenter pointed out, it seems as if government mandated privacy intrusion is OK, while violations by corporations are quickly shutdown. It’s like the opposite of how it works here in the US.
Once you give people an outside boogieman(Putin, Trump, Covids, etc) or a self inflicted false flag crisis(surge in violent crime rates for example) to shake them up to their core and put the fear in them, you can then easily sell your intrusion of privacy in their lives and extension of the police state, as the necessary solution that protects them.
When you start lose control of your people because their standard of living has been going downhill for 2 decades and they realize the future prospects aren't any better so they hate you even more, you can regain control of them by rallying them up on your side in a us-versus-them type of game against external or internal aggressors that you paint as "the enemy". The media is your friend here. /s
This isn't an EU or US exclusive issue, it's everywhere with a government issue. The difference as to why the EU people seem to be more OK with government intrusion compared to the US, is that EU always has external aggressors the government can point to as justification for invasiveness and control, while the US has been and still is the unchallenged global superpower so it has no real external threats ATM, meaning division must be manufactured internally (left vs right, red vs blue, woke vs maga, skin color vs skin color, gender vs gender, etc) so that the ruling class can assert control in peace.
Either way, we all seem to be heading towards the same destination.
Also, your police aren’t afraid to go the extra mile to quash dissent. Look at what’s happening in the UK for example with Palestine Action. The only difference is that they are less armed and better trained.
Since you’re a pedant, look at what Germany is doing in this same area.
The Danish proposal for indiscriminate chat control did not receive enough support and was retracted last autumn. Similar proposals have been put forward regularly over the past 30 years and have so far come to nothing just as regularly.
The Danish proposal for indiscriminate chat control did not receive enough support and was retracted last autumn. Similar proposals have been put forward regularly over the past 30 years and have so far come to nothing just as regularly.
For the conservative (and sometimes not so conservative) non-experts things like this sound like an easy win. So every new generation of politicians has to be educated about it again.
That has never been passed in any form.
> the opposite of how it works here in the US.
It appears that you have conveniently forgotten about FISA, EARN IT, CLOUD act, PATRIOT act, LAED, etc, etc.
It always boggles my mind that most Europeans are absolutely convinced that nothing like that could ever happen again. Meanwhile, many people in the US are convinced that the government will be coming for them any minute now.
It’s not that it cannot happen again. It’s that the EU is explicitly built against that and if it happens it will come from the national governments (see Hungary), not the EU.
what's the difference? The EU relies on national gov't to enforce rules. Until the EU becomes a sovereign entity with standalone enforcement mechanisms, it's no more able to ensure things can't happen than the UN.
It's not the same. EU will cut your funding if you don't follow their rules. UN is not finding any EU countries, but the opposite, we all pay to fund the UN.
So to prevent individual EU nations ever becoming authoritarian, like Hungary, we have to cede sovereignty and authority to the EU & EC unelected bureaucrats like Ursula VDL who take over as the main executive leaders, ensuring we'll no longer have the danger of national-level authoritarianism.
Hell of a solution.
Surely the better solution to issues like Hungary is ensuring we get more democracy to Hungarian people, not giving authority over Hungary to someone else the Hungarian people can't elect.
Not really, and the example of Hungary shows that it would not be that effective for that purpose.
The EU is a union of nations, not really of people. It was built so that nations play nice with each other. Each member state still does more or less what it wants within its borders, as long as it does not jeopardise the union.
In that way it’s not perfectly democratic, because there are layers of indirection between the citizens and the institutions.
Commissioners are nominated by member states and approved by parliament. So they are generally aligned with the politics dominant at the national level and palatable to MEPs. Von der Leyen is there because she had support from the German government and was from the dominant block in parliament. It’s not direct democracy, but it is not a faceless blob either.
It's a bit ironic that most of those people voted for Trump, who is now doing exactly that. But I guess they think it's ok as long as the government is coming for others, not for them (at least not yet)...
There's a divide between generations and geographies to start with. Younger vs. older generations see things differently. Westerners vs. Easterners (especially those who remember the communist times) see things differently.
It's very hard to say what many and most people are doing on either side of the Atlantic. Until a few short years ago you wouldn't have imagined enough Americans would vote for the leader they did, knowing exactly what they're getting, and yet they did. So people aren't always forthcoming about their views and beliefs.
In Europe for anyone who can't remember the "hard times" it's easy to fall into the trap of believing things will stay good forever. The US hasn't had equivalent "hard times" relative to the rest of the world for as long as any person in the US has been alive and a few generations more. So they too can easily believe things can't turn sour, which is why this recent and swift downturn caused so much shock and consternation. But the US also always had a lot of preppers and people "ready to fight the Government" (that's why so many have guns, they say). It's a big place so you expect to have "many" people like this.
Their reaction and opposition to ChatControl (or near complete lack of both) would indicate otherwise? They could hardly care less about privacy.
National governments which have openly declared that believe they have the right to unlimited access to any private communication hardly lost any popularity or faced real consequences.
What are the odds that once shut down "chat control" will come up under a new name?
Right now, it's more like US corpos are try to twist the arm of EU governments [1][2], pushing heavy propaganda to manipulate our elections [3], allying with the US government to do so. And the US government has been threatening EU govts with invasion [4], leveraging US corpos to harm lawful individuals doing their jobs in the EU [5], and sanctioning elected officials for performing their duties [6], or threatened to [7].
Sure, there's an hypothetical risk of the EU turning sour. On the other hand, when it comes to US corpos, the risk has materialized.
[1]: https://www.bbc.com/news/articles/cly930y90lro [2]: https://www.bbc.com/news/articles/c0589g0dqq7o [3]: https://www.politico.eu/article/twitter-faces-renewed-scruti... [4]: https://en.wikipedia.org/wiki/Greenland_crisis [5]: https://www.lemonde.fr/en/international/article/2025/11/19/n... [6]: https://www.brusselstimes.com/1931733/eu-parliament-blasts-u... [7]: https://www.politico.eu/article/us-accused-threats-eu-diplom...
It's totally not the "ministry of truth".
That's an amusingly naïve perspective. The US government absolutely can harm you, via a multitude of ways.
China's government has strategic goals to destabilise and weaken the EU, and data-farming will be part of their strategy.
What part of the cellphone manufacturer being based overseas makes you think the government can't track you via it?
Even leaving asides 5-eyes style data-sharing agreements, your US/Chinese smartphone still connects through a domestic cellphone carrier, using a domestic number. That's enough to have at a minimum fine-grained location tracking, call logs, and data usage.
One only needs a few looks at what the EU Commission has been doing lately to see that if left unchecked their plan is a UK-like total surveillance state.
The usual first victims are sex workers, not political minorities.
Attestation in on itself isn't unwarranted which (to me) is an important security measure. Attestation as commonly implemented on Android via Play Integrity (the way banking apps are known to do) is restrictive, sure: https://grapheneos.org/articles/attestation-compatibility-gu... / https://archive.is/snGEu
If it's an important safety measure _for me_, shouldn't I get to decide whether I need it based on context?
I think it's fair for banks to apply different risk scores based on the signals they have available (including attestation state), but I also don't want the financial system, government & big tech platforms to have a hard veto on what devices I compute with.
Sure, banks could probably build a mechanism that lets some users opt out of this, just as they could add a Klingon localization to their apps. There just isn't enough demand.
I don't think a good security engineer would rely on atty as "front line" anti brute force control since bypasses are not that rare. But yeah you might incorporate it into the flow. Just like captchas, rate limiting, fingerprints etc and all the other controls you need for web, anyway.
I know I'm quibbling. My concern is that future where banks can "trust the client" is a future of total big tech capture of computing platforms, and I know banks and government don't really care, but I do.
Correct. And the end of ownership, privacy, and truth too. If something can betray you on someone else's orders, it's not yours in the first place. You'll own nothing and if you aren't happy, good luck living in the woods.
Hm, Play Integrity isn't that slow on Android, from my experience.
> don't think a good security engineer would rely on atty as "front line" anti brute force control since bypasses are not that rare
I'm not privy to device-wide bypasses of Play Integrity that ship with Trusted Execution Environment (which is pretty much all ARM based Androids), Secure Element, and/or Hardware Root of Trust, but I'd appreciate if you have some significant exploit writeups (on Pixels, preferably) for me to look at?
> My concern is that future where banks can "trust the client" is a future of total big tech capture of computing platforms
A valid concern. In the case of smart & personal devices like Androids though, the security is warranted due to the nature of the workloads it tends to support (think Pacemaker / Insulin monitoring apps; government-issued IDs; financial instruments like credit cards; etc) and the ubiquity & proliferation of the OS (more than half of all humanity) itself.
A monitoring app doesn't even interact with systems you don't own. Just put a liability disclaimer for running modified versions.
> warranted
Decided by whom? And why is Google trusted, not me? At minimum, I shouldn't face undue hardship with the government due to refusing to deal with a third party, unless we first remove most of Google's rights to set the terms.
This is unserious when Insulin overdose can be fatal.
> And why is Google trusted, not me?
(Hardware-assisted) Attestation on Android doesn't require apps to "trust Google".
Hi, you don't have the break the control on the strongest device. You only have to break it on the weakest device that's not blacklisted.
The situation is getting better as you note, but in the past the problem was that a lot of customers have potatos and you get a lot of support calls when you lock them out.
> think Pacemaker / Insulin monitoring apps; government-issued IDs; financial instruments like credit cards; etc
I agree with you on the need for trustworthy computing. I mainly disagree on who should ultimately control the trust roots.
Funny that you say that, but the so far best artificial pancreas that is completely free and open source will soon be much harder to install to any Android phone without every user getting a valid key from Google.
In Germany, doctors even recommend these tools if they work. Because they make patients who know what they are doing healthier and more safe.
Naturally me and hundreds of other diabetics have already contacted our EU representative due to the changes Google is planning to make in their platform.
https://androidaps.readthedocs.io/en/latest/
This tool has literally saved my life.
It's a security measure against the owner of the device, in other words, an attack. Would you be okay with me using a remote control to forcibly slow down your car so I can merge? Using attestation this way is fundamentally incompatible with ownership. If the bank wants some assurance about a device, they need to sell or issue one to me, like credit cards or point of sale machines, which are explicitly not your property.
The fact that the assurance is provided by a third party you have little recourse against just adds insult to injury.
In this example, a banking app is not making the entire Android device non functional when it refuses to work when remote attestation like Play Integrity fails.
Like I said, I'd be fine if they offer a viable alternative, like a card or a physical authentication dongle (which doesn't require spyware to use).
Would you consider MFA to be a measure against you, the owner of the device, because it makes it harder for you to login?
>If the bank wants some assurance about a device, they need to sell or issue one to me
They are offering you free software and are operating under a security model tied to these specific devices. You're still free to walk into their branches, or use their physical cards, if you prefer not use their limited selection of devices.
>Would you be okay with me using a remote control to forcibly slow down your car
Car manufacturers do this as well though. Some of this is for the benefit of their customers (preventing theft from easily cloned keys). Some of this is not for customer benefit, like locking down infotainment systems.
Banks however are only interested in preventing fraud.
Not really, unless the MFA involves the same type of attestation involved in the process. TOTP is fine, and you can put it in your password manager to avoid phones, and can be done without consenting to any spying. And I don't really own the account anyway.
> use their physical cards
The premise of this discussion is these will get replaced by the hostile phone app, since the Europeans are too lazy to make a proper replacement.
> locking down infotainment systems
I don't agree with that either, but you can presumably buy a car without one, and you'd still be allowed to drive. What if the government says, you can't drive anymore UNLESS you use the locked down infotainment system and consent to all the ads/spying that comes with it?
In theory - of course, it shouldn't make it any harder for _me_ to login, it's just that in practice the friction is inevitable since it can't distinguish between me and someone else without it.
> You're still free to walk into their branches, or use their physical cards, if you prefer not use their limited selection of devices.
The point is that this freedom is going away. I'd absolutely want to use their physical cards (there are smartcards with e-ink displays which would be a great thing for confirming payments), but no, they're slowly taking this away, starting by limiting transfers done without their mobile app.
And _their_ mobile app needs to invade __my__ property by locking down the system. I understand this might be neccessary to ensure the UI can be trusted, but this shouldn't happen on my device as it restricts my ability to do completely unrelated things.