Today we publish our policy analysis together with @edri on the upcoming #eID Reform of the EU. What’s does the new European electronic identity system called #eIDAS mean for privacy? A thread 🧵1/13
Every EU citizen and resident will get a unique, live-long identifier. Such a persistent ID was deemed unconstitutional in several EU countries. That didn’t stop the EU Commission to propose every tracking companies dream. 2/13
Governments have to offer their citizens a European Digital Identity Wallet App which will be free of charge and optional. But eGovernment services will use it and Big Tech companies like Google and Amazon will have to support it to log into their servies. 3/13
The Wallet App will be a ubiquotos platform to identitfy, authenticate and check attributes (about) us. The identity comes from the state. The attributes can be from public entities (age, drivers license) or from private institutions (medication, memberships, etc). 4/13
The architecture will allow the provider of the Wallet App to observe every transaction. So every time we verify our age to buy something or we rent a car with our drivers license, the government or the company acting on its behalf will know. 5/13
The system is open for the private sector and the industry wants to use this system to identify (and track) their customers and users. Concepts like selective disclosures are perverted in so far as there are no anonymous transactions to for example verify our age. 6/13
We don't know the security of the system, because this and many other central questions are left open and will be decided via deleagted acts once the law is already adopted by parliament. A stunning 23 times the Commission is giving itself the power to decide unilaterally. 7/13
Once a company is accepted in any EU country, they can use the system EU-wide. If a company is abusing the system, there is no redress mechanism or way to expell them. The bill contains no safeguards against abusive use cases like targeted advertising, insurances or profiling. 8/
The #eIDAS reform is breaking the security of the web by giving governments access to the security system of web browsers. This would allow for government surveillance on an enourmous scale. Many have warned about the devastating consequences of this. eff.org/deeplinks/2021… 9/13
Once this system is in place, the cost of identifying someone online or offline will be zero. That means anonymity online and offline will become increasingly under thread. Previously failed attempts to force a real name policy on social media platforms could then succeed easily.
Lastly, the proposal assumes everybody has a Smartphone that can operate the Wallet App securely. This is not true and will lead to widening of the digital divide, or worse identity theft. We already see Government servies becoming more expensive if citizens don't have an eID.11
Tomorrow morning we will give testimony in the expert hearing of the Industry committee of the European Parliament. This is the lead committe deciding on #eIDAs. We want to raise awareness to these serious problems. Read the blogpost: en.epicenter.works/content/orwell… 12/13
A more detailed analysis of the whole proposal can be found in this joint document with @edri: epicenter.works/document/3865 You can find the Parliament disucssion tomorrow here and there will be a live stream: epicenter.works/event/3866 13/13 END

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with epicenter.works

epicenter.works Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @epicenter_works

Dec 16, 2021
#EMSLeak: Heute veröffentlichen wir mit @derStandardat gravierende Sicherheitsmängel im Gesundheitsministerium. Mit der in diesem Video dokumentierten Sicherheitslücke können Melderegister und epidemiologisches Meldesystem abgefragt werden. epicenter.works/content/datens… 1/7
2️⃣ Über einen freizügigen Umgang mit Zertifikaten ist es Unbefugten möglich, allen Menschen in 🇦🇹 Labormeldungen für beliebige anzeigepflichtige Krankheiten, wie AIDS, Syphilis oder Covid-19 im EMS einzutragen und im begrenzten Umfang auch abzufragen. 2/7
3️⃣ Auch das Zentrale Melderegister (ZMR) kann abgefragt werden und auch die Privatadresse von gesperrten Personen aus Medien, Justiz und Politik. Zu Coronapositiven sieht man auch Telefonnummer und E-Mail Adresse. 3/7
Read 7 tweets
Mar 17, 2020
Zum Vorgehen von A1: Wir sehen das Grundproblem schon im Produkt von A1. Eine Aggregation von Daten führt nicht automatisch zu ihrer Anonymisierung. [THREAD]

derstandard.at/story/20001158…
Um gegen die Zusammenführung mit Daten aus anderen möglichen Datenbanken zu schützen, wären zusätzliche mathematische Verfahren notwendig, von denen unklar ist, ob sie eingesetzt werden.
Eine Nutzung eines Systems zur Bewegungsstromanalyse durch den Staat ist demokratiepolitisch deutlich heikler als die Nutzung dieser Daten durch Private.
Read 5 tweets
Sep 4, 2019
Wir sind heute im @PCConcordia zum Thema Netzpolitik. @brodnig wird mit Vertretern verschiedener Parteien diskutieren und wir präsentieren unser netzpolitisches Wahlbarometer. Wir sind gespannt auf die Meinungen der Parteien. #wirhabengefragt
@PCConcordia @brodnig .@derHoyos: "Die FPÖ war mal eine Partei, die sich mal für Datenschutz eingesetzt hat. Jetzt nicht mehr." #wirhabengefragt #netzpolitik
@PCConcordia @brodnig @derHoyos Ad Bundestrojaner: "Das Kollektiv darf nicht eingeschränkt werden" - @derHoyos #netzpolitik
Read 30 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

:(