Hacktakes · Edition 6
Hacktakes · Edition 6 · July 14, 2026

Felony Contempt of Citizenship: How the EU is Outsourcing State Identity to Apple and Google

By requiring proprietary device checks for its digital identity wallet, the EU transforms corporate surveillance into a prerequisite for citizenship.

By Silas Grant

Sparked by European "age verification" "app" forcing everyone to use Android or iOS · discussion

I don't care if you were born here, your phone isn't on the guest list.
I don't care if you were born here, your phone isn't on the guest list.

On the one hand, Brussels' aggressive regulatory crusade against American tech monopolies is the stuff of legend. The Digital Markets Act, the Digital Services Act, the General Data Protection Regulation—the European Union ostensibly loves to flex its sovereign muscle against Silicon Valley. So it is supremely, bitterly ironic that the EU is currently attempting to outsource the fundamental state function of citizen identification to Google and Apple, and they are doing it quietly in the comments of an obscure GitHub pull request:

https://github.com/eu-digital-identity-wallet/av-doc-technical-specification/discussions/19

This architecture is the systemic equivalent of the state installing a corporate bouncer directly inside the lobby of City Hall, a private enforcer who refuses to let you renew your passport unless you agree to wear an actively transmitting commercial tracking collar. I spent the morning reading through the technical specifications for the EU Digital Identity Wallet, and the core documentation requires users to submit to "device attestation" (a sterile tech-policy euphemism for a proprietary commercial lock-in). We must translate this jargon immediately. In the tech-washing vocabulary of mobile monopolies, attestation masquerades as an objective security check, while structurally operating as a blunt-force weapon that criminalizes the act of escaping commercial surveillance to access state services.

Let's look at the plumbing of this disaster. When you open a mobile app that uses Google's Play Integrity API, the application pings the mothership to ask a highly specific question. It asks whether this device is running unmodified, commercially approved software. If the answer is yes, the app works. If the answer is no, the app permanently refuses to load. Apple maintains a functionally identical mechanism. The official public relations excuse for this lock-in is device integrity, relying on the assumption that only a trillion-dollar corporation can be trusted to secure a mobile environment. To understand the actual stakes, we have to trace this single API call backward to the structural imperatives of the monopoly. These corporations do not view your phone as your property; they view it as a licensed terminal connected to their extraction machinery. The strict operational purpose of these attestation checks is to protect the mobile duopoly's business model from the user, ensuring that any attempt to escape the telemetry dragnet results in a punitive loss of basic device functionality, effectively converting every independent piece of hardware back into a subservient terminal of the company store.

Consider the position of a citizen who refuses to live inside a mobile surveillance panopticon. If you wipe your Android phone and install a privacy-focused custom ROM like GrapheneOS to sever the constant stream of behavioral telemetry flowing back to Mountain View, Google's API automatically flags your device as untrustworthy. You have committed the unpardonable sin of controlling your own computer, and for that, you must be excommunicated from the digital ecosystem. The moment the European Union hardcodes this exact same proprietary API into its state identity wallet, the state functionally revokes your digital citizenship simply because you modified your own hardware. The furious Hacker News reaction to this specification perfectly captures the exasperation of the tinkerer: you are being told by a government bureaucracy that securing your own device against corporate spying makes you an unacceptable security threat to the state.

The state is weaponizing anti-circumvention laws to enforce a corporate walled garden, delegating the sovereign power of the European Union to unaccountable, rent-seeking executives who operate entirely outside the democratic process. If a privacy advocate or a rogue software engineer decides they want to spoof the attestation check to make their digital state ID function on a free and open operating system, they run headlong into Article 6 of the EU Copyright Directive (the European equivalent of the draconian US DMCA Section 1201).

Because these attestation APIs rely on proprietary cryptographic access controls to enforce their arbitrary, margin-padding market dominance, bypassing that API check to access your own municipal services transforms a basic act of digital self-determination into a legally actionable copyright violation, effectively allowing monopolists to weaponize the criminal justice system against citizens who merely refuse to be tracked.

It is absolute bullshit.

The mobile duopoly maintains the transparent fiction that OS-level lock-in is the only valid method to establish digital trust, insisting that any open alternative would unleash a catastrophic wave of identity theft and fraud. We know this is empirically false because we already have the math to prove otherwise. The Dutch Yivi app relies entirely on attribute-based cryptographic verification to prove identity. Yivi verifies that you are who you say you are through the cryptographic signature of the credential itself, meaning the system works perfectly and securely without ever caring whether your operating system was blessed by Tim Cook or Sundar Pichai. We have the cryptographic tools to establish trust without establishing a surveillance monopoly.

Because a mathematically verifiable credential operates independently of the hardware manufacturer, attribute-based cryptography entirely negates the necessity of corporate telemetry. The state can simply verify the math. The obstacle to adopting this standard is purely political, driven by a bureaucratic failure of imagination that conflates corporate market dominance with actual civic security. When the state delegates the mechanics of citizenship to a private entity's Terms of Service, it actively accelerates a class war against its own public, artificially inflating the switching costs of leaving a mobile ecosystem by tying the basic rights of civic participation to a commercial user account.

The only workable solution to this crisis is for regulators to legally mandate structural interoperability within the EU Digital Identity Wallet framework (a legally enforceable defense of digital sovereignty), ruthlessly stripping out all requirements for proprietary device attestation and explicitly replacing them with open, mathematically verifiable cryptographic standards. State infrastructure must never rely on proprietary OS-level lock-in. We should not have to appease a corporate bouncer just to prove to our own governments who we are.

← Back to Edition 6