I do not think you can guarantee that Mobile BankID will support a technical work-around like this for the rest of my life. What if next month it requires a Google Service?
I read yesterday that Mozilla's location services will be shut down, which /e/ uses. What if BankID says they need an accurate location service for security reasons, and refuse to connect to a new alternative? What BankID switches to a encrypted service API which cannot be emulated?
I don't like modding hardware nor want to figure out how to do this.
I want my kids, when they get a phone when they are older, to have their right of access and privacy rights maintained by Swedish law without having to learn the tech first.
The status quo won't change unless people start complaining.
> I do not think you can guarantee that Mobile BankID will support a technical work-around like this for the rest of my life.
No, it won't but then again - what will? App life time is measured in months, not in years let alone ´for the rest of your life'. I used to run BankID on my Linux laptop but that is no longer supported either. Things change all the time so it is what works here and now that is important. I will soon no longer be able to use BankID because I'm not a Swedish citizen and the new version insists on scanning a Swedish ID (driver's licence excluded since that does not contain an RFID transponder yet), let alone the fact that none of my devices has RFID capability.
Location services can be spoofed if BankID insists on being nosy.
There is no 'emulation' involved in running BankID, it just runs as intended on my devices (several of them, running different versions of LineageOS, all of them Google-free).
I think we're talking past each other here. You want the future to be free from proprietary lock-ins. So do I. You are looking for a way to escape the 'duopoly' of Ggl and the fruit factory. So do I. These things do not happen without people acting in some way which is where we seem to be on different tracks. You want people to (I paraphrase) start complaining where I want them to start acting. Actions speak far louder than words after all. It also helps in giving access to services here and now instead of maybe, later. This is how Linux and the BSDs arrived on the scene as well, not because people complained but because they started acting.
As to your children getting phones I'd say it is up to you to lead by example in the hope that some of what you show them sticks. Speaking from experience I can only say "good luck" seeing how as social pressure is a stronger force than parental advice. All of their friends and peers will have tons of privacy-leeching apps on their duopoly-devices which they also will want to have because that is how those peers communicate. Thus far I have been able to keep the worst offenders at bay by offering self-hosted alternatives which they now use, e.g. a self-hosted XMPP server with Conversations on their phones instead of Whatsapp/Telegram, self-hosted Nextcloud instead of Google, self-hosted Peertube servers (several for different types of content) instead of Youtube for publishing their own content, self-hosted mail instead of Gmail, etc.
BankID is a special case because it ties a state-issued ID to commercial services (banks). I want the Swedish state - to be specific either Skatteverket (the tax department, responsible for the population register) or the police (responsible for issuing passports and ID cards) - to start issuing an alternative electronic ID which is not tied to any specific commercial service, i.e. which can be used with any device. It can be in the form of a transponder in the ID card, driver's licence or passport, in the form of something like a Yubikey or in that of a certificate which can be used in any browser but it should be useable as long as the user agent follows the required open standards. Something like the Dutch DigiD system [1] or the Belgian CSAM [2] can be used as a starting point.
I don't mean app time, I mean officially support the option of using a privacy-oriented phone, along with any required services, through an app acquisition and update system which is not significantly more difficult than the current distribution. I want that company to be as equally subject to privacy laws as my mobile phone provider, my internet service provider, or my electricity provider.
> I will soon no longer be able to use BankID because I'm not a Swedish citizen and the new version insists on scanning a Swedish ID
I am a Swedish citizen and I do not own a device which is able to scan a Swedish ID.
What are they going to do? Force me to buy a smartphone with terms of service I do not agree with? Shut off my bank services?
Have you gone to the bank and said that you are going to get rid of your smartphone, and want to switch to BankID on a file? I'm curious if that's even a valid option. It seems everyone who has a smartphone is so addicted to it that they can't give it up.
> Actions speak far louder than words after all. It also helps in giving access to services here and now instead of maybe, later.
People have been using your suggestion for years. Has it improved the situation?
No. You said BankID no longer works on Linux (even with Wine?).
Because the rejoinder has been "if you don't like it, you don't need a smart phone." For you, a smart phone was important enough that you accepted the risk of future problems.
For me, a smart phone is not that important, and I don't want to accept the risk of future problems. It isn't like what I'm asking is impossible - there are existing phone providers with terms I can agree to, but only if I know that it's a viable long-term solution. Which it isn't now, as you've said.
It requires forcing Swedbank, etc. to support alternative, which I can't do but the state might. Especially since the state want to have a contactless id card, which mongol mentioned at https://news.ycombinator.com/item?id=39727561 . The document is clear that depending on commercial interests like BankID is one of their concerns.
Or Sweden can pass laws saying that mobile store operators selling in Sweden must follow strict privacy laws against targeted marketing and advertising, and that privacy cannot be opted out.
Or Sweden can pass laws which say businesses must have comparable options for those who do not have a smart phone. (For all I know, that already exists.)
I read yesterday that Mozilla's location services will be shut down, which /e/ uses. What if BankID says they need an accurate location service for security reasons, and refuse to connect to a new alternative? What BankID switches to a encrypted service API which cannot be emulated?
I don't like modding hardware nor want to figure out how to do this.
I want my kids, when they get a phone when they are older, to have their right of access and privacy rights maintained by Swedish law without having to learn the tech first.
The status quo won't change unless people start complaining.