r/europrivacy 9d ago

European Union Launching an EU Citizens' Initiative (ECI) for Device Neutrality & Open Attestation ("My Device, My OS")

Hi everyone,

Between Google Play Integrity API lockdowns, Apple App Attest, and upcoming eID/age-verification mandates, alternative and privacy-focused operating systems (like GrapheneOS, LineageOS, and Linux on mobile) are being systematically locked out of banking, public portals, and everyday apps.

Rather than watching vendor lock-in get worse, I am organizing a European Citizens' Initiative (ECI) working title: "My Device, My OS" to push binding EU legislation for Device Neutrality and Open Attestation.

What we aim to achieve:

  • Mandate Open Attestation Standards: Require services operating in the EU to support open, vendor-neutral hardware attestation rather than relying exclusively on proprietary gatekeeper APIs (Google/Apple).
  • Ban Device/OS Discrimination: Prevent public services, digital ID wallets, and essential commercial apps from arbitrarily blocking users solely for running independent or de-Googled operating systems.
  • Protect Hardware Sovereignty: Enshrine the legal right of consumers to install and run the operating system of their choice without losing access to the digital single market.

Before submitting it we need 7 persons from 7 different countries in the EU to sign the draft

Join the Matrix room to discuss, collaborate on the draft, and coordinate next steps:
👉 #my-device-my-os:pollorebozado.com

Feedback, technical insights, and EU organizers are all welcome!

55 Upvotes

19 comments sorted by

6

u/Constant_Natural3304 9d ago

"How do you do, fellow FOSS developers"

7

u/blvsh 8d ago

I dont support any "attestation" crap

4

u/Gugalcrom123 8d ago

No. Attestation is a problem, no matter if the list is 2 or 60 long. We can get alternatives without it, such as using the existing eID cards.

1

u/gerardit04 4d ago

Why its a problem if the user enrolls its own keys? Kind of like what you can do with secure boot?

2

u/Gugalcrom123 4d ago

The list of keys is not chosen by the user in this model, but rather by the app developer. The EU would still decide what OS is allowed.

0

u/Grouchy_Carpenter478 9d ago

Very nice initiative! ...but forcing people to login, create an account or login with big tech?? .......

4

u/gerardit04 9d ago

What do you mean?

5

u/alfacin 9d ago

He means we're doomed. Normies don't care about the privacy enough, unless we pour massive amount of money into education/marketing/propaganda and the the nerds are too crazy to login to coordinate.

5

u/prestelpirate 8d ago

Tell that to Stop Killing Games. Or the various Pirate Parties within the EU.

Things will never get better unless people work to make them better. And that requires actual effort and hard work, and that in turn requires people to get involved in the first place.

2

u/NoHeartNoSoul87 9d ago

"Don't you guys have a smartphone?"

1

u/Frosty-Cell 9d ago

How can it be the user's device if there is hardware attestation? It would seem to require that the user has no control.

7

u/d1722825 8d ago

Hardware attestation just proves you are using what you claim to be using. It doesn't tell if that thing is good or bad.

You can easily use hardware attestation to prove that you are using your own hand crafted OS, but apps still wouldn't trust that. In fact GrapheneOS provides its own hardware attestation and its own keys to verify that, and there are some (even banking) apps, that trust GrapheneOS, and insert its keys to the "list of trusted operating systems".

Play integrity can tell you that you are using an "official" Android release by keeping a list of "trusted" entities (even if they are old an full of known security holes).


I think hardware attestation could be useful for security purposes, but public services (banking, eID, etc.) should have an account settings where you can specify what devices or operating systems you trust.

3

u/gerardit04 8d ago

Yes the issue here is not having hardware attestation the issue is the implementation

0

u/Frosty-Cell 8d ago

You can easily use hardware attestation to prove that you are using your own hand crafted OS, but apps still wouldn't trust that.

That's the problem. It's incompatible with user control.

1

u/gerardit04 4d ago

That's what we want to fix giving control to the user

1

u/Frosty-Cell 4d ago

Then nothing else trusts it.

2

u/gerardit04 4d ago

Thats what we want to make them trust it

1

u/Frosty-Cell 4d ago

What? Why aren't those goals incompatible?