So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function
Absolutely pathetic
PhD Candidate in the CoreSec group at #TUGraz, focusing on side-channel security. Apart from that, I also post #Linux and #privacy related stuff.
Opinions posted here are my own and do not necessarily reflect those of my employer.
| Website | https://stefangast.eu |
So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function
Absolutely pathetic
Ohne Google/Apple = Keine EUDI-Wallet
Die Wallet soll EU-Bürger*innen unabhängiger machen - doch sie vertraut blind den gleichen Tech-Giganten, die wir mit DMA & Datenschutzklagen bekämpfen.
Die Wallet prüft via Play Integrity (Android) & App Attest (iOS), ob euer Gerät sicher ist. Gerootet/Jailbroken? Kein Zugang. Veraltete Sicherheitsupdates? Blockiert.
Wie souverän ist eine digitale ID, wenn zwei US-Konzerne über ihre Nutzung bestimmen? Und was passiert, wenn Google/Apple die Attestierung einfach abschalten? Oder meinen Account sperren? Ich soll doch in der EUDI-Wallet zukünftig alles vom Personalausweis bis zum Mietvertrag speichern, wenn ich das recht verstanden habe.
via HackerNews
since that browsergate site about LinkedIn seems to be gaining traction I figure I should mention:
edit: and as someone else noted in the replies, looking through the list of extensions of scans for... they're pretty much all "AI"/scraper/automation plugins. so, should LinkedIn be doing this, or even able to do this in Chrome? no! but also, it does seem like the stuff they're scanning for is all extensions that shouldn't exist to begin with tbh
edit 2: please see this follow-up post which proves this is just a shitty campaign by people who made an addon called "Teamfluence" that got blocked by LinkedIn
Apparently #LinkedIn runs a silent browser scan on every #Chrome user who visits the site.
6.222 extensions.
~405 million users affected.
No consent, no disclosure, no mention in their privacy policy.
Read the full technical breakdown, legal analysis and searchable database of every scanned extension: https://browsergate.eu/
Microsoft is running one of the largest corporate espionage operations in modern history. Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedIn’s servers and to third-party companies including an American-Israeli cybersecurity firm. The user is never asked. Never told. LinkedIn’s privacy policy does not mention it. Because LinkedIn knows each user’s real name, employer, and job title, it is not searching anonymous visitors. It is searching identified people at identified companies. Millions of companies. Every day. All over the world.
More closed-door discussions with the Trump administration won’t strengthen cooperation, they will undermine trust, transparency, and in the worst case even the EU’s ability to enforce its own rules.
Together with other civil society organisations, we call on the @EUCommission to halt this “dialogue” and focus on stronger, faster, and more transparent enforcement of Europe’s digital laws.
Read our statement ⤵️
https://edri.org/our-work/europes-digital-laws-are-not-bargaining-chips/

In reaction to the recent plan to “open a formal dialogue” with the US government on EU tech rules, EDRi and other civil society organisations urge the Commission to halt this plan that risks giving Big Tech a back door to weaken the EU digital rulebook and its enforcement.

Donald Trump poltert bei jeder Gelegenheit gegen die EU und ihre Digitalregeln. Künftig soll ein neues Gremium der US-Regierung offenbar Mitsprache einräumen, berichtet das Handelsblatt. Im Gegenzug soll es Zollerleichterungen geben.
RE: https://infosec.exchange/@mttaggart/116320350237766467
It's so funny that no one even wants to own the word "ad" anymore. They're "tips." For your own good. Gotcha.