Germany · de.indymedia · · 1h
New name, old construction sites: These are the hurdles to the launch of the digital wallet “d‑you”
Deutsch (original) · Auto-translated to English
The German version of the EUDI wallet, which is scheduled to launch in January 2027, will be called “d‑you”. Until then, the Digital Ministry still has to solve IT security problems. If there are “remaining risks”, the federal government could postpone the start.
For Karsten Wildberger (CDU) it was “a special day”. The Digital Minister presented on Wednesdayhttps://bmds.bund.de/aktuelles/aktuelle-melden/detail/melde-eudi-wa...official name of the German EUDI wallet: “d‑you” will therefore be her name. The “d” stands for digital and for Germany, the “you” refers to the individual user, explains the minister.
The digital wallet is scheduled to launch as a mobile phone app on January 2, 2027. In the future, citizens will be able to store digital identification documents, certificates and hotel reservations there. It will be user-friendly and safe, Wildberger promised at the press event. At the same time, he emphasized that he sees the app as a “living product” that grows with new functions. “An ecosystem is emerging around d‑you,” said the minister, “which enables new applications, more innovative business models and more efficient administrative services.”
Initially, however, d‑you is starting significantly smaller than planned: initially only the digital ID should be usable, later driving license and “shortly afterwards” photo ID will follow. Additional functions as well as municipal and private sector applications will be added gradually.
The slow implementation shows that the deadline for launching the digital wallet is too ambitious. The federal government also indicates that the date could be postponed for security reasons. Because there are a number of construction sites surrounding the project, especially in terms of IT security.
There is still a lack of skilled personnel
The digital wallet is being created on behalf of the Digital Ministry by Common Codes GmbH, a company founded by the Federal Agency for Leap Innovations (Sprind). Just a few days ago, it was desperately looking for external support in the area of information security. The tendered contract provides, among other things, to secure the architecture of the app.
IT security researcher Bianca Kastl thinks this is too late. “It’s a bit like bringing a few safety engineers on a moving train and then asking them whether the brakes are okay,”https://background.tagesspiegel.de/digitalisierung-und-ki/briefing/bund-...Kastlthe Tagesspiegel Background.
We sound the alarm.
For your basic rights.
Join now
Thoroughly untested
The app itself has not yet been tested. At least it should be shortlyhttps://www.linkedin.com/posts/eudi-wallet-deutschland_our-code-is-open-...Start bug bounty program. It rewards external experts who find and report IT security vulnerabilities in the wallet.
However, there is still no test object. A few days ago the ministry released the source code for the apphttps://github.com/german-national-wallet/de-eudi-wallet-ios">iOSandhttps://github.com/german-national-wallet/de-eudi-wallet-android">Androi...published on the Github platform. However, security gaps should not be there, but only in the published applicationhttps://github.com/german-national-wallet/de-eudi-wallet-android/blob/ma...become. However, the apps are not yet available on the Google and Apple app marketplaces.
Meanwhile, the Federal Office for Information Security (BSI) is still writing the security requirements. The “Federal Cyber Security Authority” is to develop a national certification scheme for the digital wallet. Thehttps://bmi.usercontent.opencode.de/eudi-wallet/eidas2/en/spotlight/difa...Guideline 03189is supposed to determine which requirements d‑you must fulfill.
The delay has two main reasons. On the one hand, the EU Commission has not yet set all the requirements for the EUDI wallet. On the other hand, the BSI apparently has concerns about the IT security of the planned app, according to Tagesspiegel Backgroundhttps://background.tagesspiegel.de/digitalisierung-und-ki/briefing/einbl...June reported.
According to the BSI, publication of the guideline is only possible once the development of the wallet has been completed. “The first publication of TR-03189 on the BSI website is planned for the end of this year,” said a BSI spokeswoman when asked by netzpolitik.org – just a few days before the planned launch of d‑you.
Experts warn against signed data
This further restricts Wildberger's schedule. And it is possible that the federal government will address the BSI's concernshttps://background.tagesspiegel.de/digitalisierung-und-ki/briefing/von-w...more pushed aside. Already in October 2024https://de.linkedin.com/posts/markus-richter-134315204_opensource-digita...itselfthe then still responsible Ministry of the Interior (BMI) for an architectural variant for the German wallet that relies on so-called signed data. This decision, to which apparentlyhttps://background.tagesspiegel.de/digitalisierung-und-ki/briefing/einbl...very own interests in the Sprind teamled to far-reaching consequences for the security of the app.
In principle, there are two ways to confirm the authenticity and integrity of transmitted identity data with the digital wallet: with the help of a secure channel (“Authenticated Channel”) or by signing data (“Signed Credentials”).
Everything that is relevant to network policy
Three times a week as a newsletter in your inbox.
Subscribe now
The secure channel comes with the online function of thehttps://www.personalidentportal.de/Webs/PA/DE/buergerinnen-und-buerger...ID cardfor use. Secure and trustworthy data transmission ensures the authenticity of the transmitted data that identifies a person. The chip built into the ID card creates the technical requirements for this.
With signed credentials, on the other hand, the transmitted data is provided with a cryptographic signature. This means you essentially have a seal of authenticity - even long after transmission. This seal makes the data extremely valuable for data trading and identity theft, warned independentlyhttps://www.bundestag.de/resource/blob/901718/f867818288768364aa3cb9cd5d...BSI, thehttps://background.tagesspiegel.de/digitalisierung-und-ki/briefing/eudi-...,https://www.bundestag.de/resource/blob/901722/7b3b2d8edb2a64805bc1d96d71... https://www.bundestag.de/resource/blob/901724/67441ef0b9ead7f9f09f15cc52...as well as https://epicenter.works/fileadmin/medienspiegel/user_upload/epicenter.wo...Organizations.
Start could be postponed
Karsten Wildberger defended the BMI's decision for signed data at yesterday's press event. This is the only way the project can be scaled up, said the minister, who is known to like to think big.
However, yesterday he was noticeably reserved. Wildberger emphasizeshttps://www.zdfheute.de/politik/lanz-wildberger-lobo-russland-technologie... https://www.welt.de/videos/video6a57877b664e99bc41e93e7d/digitalminister...every occasionthat the state wallet will launch on January 2nd. At the same time, he is aiming for a rather quiet start. Wildberger said he first wanted to gather experience and feedback, and only then would d‑you be advertised more broadly and launch a nationwide communications campaign.
Alsohttps://dserver.bundestag.de/btd/21/073/2107319.pdf">dieThe federal government is apparently worriedthat not everything will go smoothly. It will “decide on the launch of the state EUDI wallet taking into account any residual risks”. In other words, it could postpone the launch of the wallet due to IT security concerns.
The work of netzpolitik.org is financed almost 100% from donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.
Read the full story at the source →
Source: de.indymedia