Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

Have you ever tried to contribute to an EU opensource project hosted at

https://code.europa.eu?

I did and failed.

Why?

#DigitalAutonomy #DigitalSovereignty #OpenSource #EU #Tech

  • Copy link
  • Flag this post
  • Block
R.C.
R.C.
@RichardoC@infosec.exchange  ·  activity timestamp 3 weeks ago

@BjornW Do you know if anyone involved with that project is at #fosdem2026 ? Happy to show them in person the issues I'm encountering!

#fosdem

  • Copy link
  • Flag this comment
  • Block
Eric Herman
Eric Herman
@eric_herman@mas.to  ·  activity timestamp 4 weeks ago

@BjornW yes, since the requirements have been increased, I too can no longer log in. I was hopeful that they'd accept DigID with SMS verification, but no. Thus, I hit the same roadblocks you describe. It's frustrating.

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 3 weeks ago

@eric_herman at least we suffer from the same problem & therefor this a common problem that should be addressed. I got a reaction with some pointers which I will try after surviving Fosdem.

  • Copy link
  • Flag this comment
  • Block
Open Source Programme Office
Open Source Programme Office
@EC_OSPO@ec.social-network.europa.eu  ·  activity timestamp 4 weeks ago

@BjornW

Good morning Bjorn! We're (really) sorry you're having trouble getting onto code.europa.eu

Now, let's see

From what we can tell, it seems you're not yet finished with the EUlogin part?

Does this website provide any help?
https://trusted-digital-identity.europa.eu/eu-login-help/external-self-registered-account-faq_en

Else, there is also an email address

https://trusted-digital-identity.europa.eu/still-need-help-eu-login_en

EU Login Portal

Still need help with EU Login?

You have browsed all available information but could not find a solution to your issue? Please use the correct contact point depending on your situation.
EU Login Portal

External self-registered account FAQ

Browse questions related to your self-registered account.
  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 3 weeks ago

@EC_OSPO
Currently I'm at Fosdem, but I will get back to you after this event in the upcoming week or the next one. Thanks for you reply, much appreciated & hopefully we can get this sorted out.

  • Copy link
  • Flag this comment
  • Block
Robert Riemann 🇪🇺
Robert Riemann 🇪🇺
@rriemann@chaos.social  ·  activity timestamp 4 weeks ago

@BjornW thanks for sharing. I want to improve this!

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

@rriemann let me know if I can do anything else to help you change it. Many thanks!

  • Copy link
  • Flag this comment
  • Block
🅵
🅵
@fedor@todon.nl  ·  activity timestamp 4 weeks ago

@BjornW

Can't see code there.
There are guidelines, html-files, documents and other management stuff.

https://code.europa.eu/info/about/activity

https://code.europa.eu/info/about/-/network/master?ref_type=heads

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

@fedor there are plenty of repo's there. For instance https://code.europa.eu/EDPS/website-evidence-collector

  • Copy link
  • Flag this comment
  • Block
🅵
🅵
@fedor@todon.nl  ·  activity timestamp 4 weeks ago

@BjornW

Ah okay!
I'm curious now. Did they reject your patches/code?

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

You need to sign in to contribute, so you need an account.

You need to create an account on 'EU login' which seems to be the EU single sign-on system for this.

I managed to create an account on 'EU login' & logged into my account.

However I am not allowed to login into code.europa.eu yet.

I need to add some kind of multi factor authentication first.

Ok, safety first, I can imagine why...supply chain attacks anyone....

What are my options?

#OpenSource #Tech #EU

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

The MFA options are:

https://trusted-digital-identity.europa.eu/creating-managing-and-using-your-eu-login-account/what-second-factor-can-i-configure-my-account_en

1) EU Login Mobile app
only available in Google / Apple stores 🙄

Not an option. I use a de-Googled Android phone without Google's Play Store. A principled stance I'm sure more opensource people have.

2) Token / Token CRAM

Only available for EC staff & DG CLIMA users. Not an option

3) eID

I can use DIgID (NL eID). I do not feel comfortable using this to contribute to opensource.

This leaves: security key, (TPM) or Passkey

Let's try

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

1) Trusted Platform Module
I use Ubuntu Linux setup by @tuxedocomputers. They have disabled Secure Boot in WEBFAI by deafult. I do not know why. Apparently this also means it did not install the required files for TPM. I also wonder if this would work at all given with the Web Authentication API as I use LibreWolf.

TPM is not a solution now.

2) Security Keys?
I don't own a security key. I'm not sure I want one. Hardware can/will fail so I need at least 2. Not an option now.

Passkeys?

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

Sounds doable. Oh snag! The interface does not allow me to pick a passkey like the Help sections show.

Apparently Passkeys are not supported anymore!?

I have quit a high-tolerance for bureaucracy, opaque rules & stupid systems, but I'm not going to waste anymore time on this for now. I just wanted to discuss a possible bug 😩

Please @EC_OSPO @EC_DIGIT or whoever, fix this horrible system & enable participation by the wider opensource community.

CC @bert_hubert @rriemann

#OpenSource #Tech

  • Copy link
  • Flag this comment
  • Block
Benedikt Wi
Benedikt Wi
@benedikt@ruhr.social  ·  activity timestamp 3 weeks ago

@BjornW @EC_OSPO @EC_DIGIT @bert_hubert @rriemann After login in with a password, I was able to setup a #nitrokey at https://ecas.ec.europa.eu/cas/userdata/webauthn/manageMyWebAuthnDevices.cgi (if you prefer some software solution: #bitwarden / #vaultwarden also works) #webauthn #passkey

EU Login

  • Copy link
  • Flag this comment
  • Block
R.C.
R.C.
@RichardoC@infosec.exchange  ·  activity timestamp 4 weeks ago

@BjornW @EC_OSPO @EC_DIGIT @bert_hubert @rriemann Same issues here, and the unchangable username (which for me looks similar to n00b...) isn't great

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

@EC_OSPO @EC_DIGIT @bert_hubert @rriemann

I'm sharing this story, because I want OpenSource in EU & at the EC to succeed.

Not to shame people, but to give them the info they need to nudge their peers/superiors into changing the current failing system.

Thanks in advance!

#Tech #OpenSource #TechPolicy #Fosdem

  • Copy link
  • Flag this comment
  • Block
Konstantin 🔭
Konstantin 🔭
@iamkonstantin@mastodon.social  ·  activity timestamp 4 weeks ago

@BjornW I think that depends in which EU country you're based. For me in Belgium, I could just use the ItsMe app, a popular thing we have linked to our eIDs so the process is quite straightforward. The GitLab will require admin approval for your account at the end though (to be able to contribute to repos etc)

  • Copy link
  • Flag this comment
  • Block
Sam Hauglustaine
Sam Hauglustaine
@smhg@fosstodon.org  ·  activity timestamp 4 weeks ago

@iamkonstantin @BjornW do you know Itsme is owned by Belgian banks and telecom companies?

  • Copy link
  • Flag this comment
  • Block
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  ·  activity timestamp 4 weeks ago

@iamkonstantin I'm not comfortable to use DigID (Dutch eID) just so I can login into an opensource code repo to discuss a bug. Nope.

  • Copy link
  • Flag this comment
  • Block
Jordan Maris 🇪🇺 🇺🇦 #NAFO
Jordan Maris 🇪🇺 🇺🇦 #NAFO
@jmaris@eupolicy.social  ·  activity timestamp 4 weeks ago

@BjornW CC @EC_DIGIT !!!

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.29 no JS en
Federation disabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct