Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

1–10 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#2
>One of the most important ways in which browsers protect users is through website authentication. For instance, if a person wants to visit Europa.eu, the web browser must reliably ensure that the site is actually under control of the owner of the domain ‘Europa.eu’, and not an attacker on the network impersonating the European Commission’s domain.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#5
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#6
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

This EU effort to control is ongoing for many years now, how is it in any way unexpected?

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#7
> In a nutshell, the revised Article 45 would force browsers to suspend the ‘root store’ policies that are essential for maintaining trust and security online. [..] At the same time, the types of website certificates that browsers would be forced to accept, namely QWACs

Can someone explain where this 'force' comes from? I wasn't aware the EU had such authority to decide how programs on a users private computer must behave. Would e.g. making a fork of Firefox that does not comply with this digital identity framework be illegal? Or is this just hyperbole from Mozilla, and the browser would be merely non-compliant?

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#8
This did get posted a few weeks ago at the time it was written but didn't get much traction at that point, yet seems like a reasonably important issue. The EU has done worthy things for issues like privacy, but whatever pluses and minuses of regulating personal and business policy I'm a lot more dubious about government sticking its hand directly into how specific software (like browsers) functions. That seems like a serious step beyond merely trying to ensure there is competition and choice in different products, full disclosure about them, level playing fields etc. Dictating implementation details even for open source feels like something with much, much more scope for serious negative side effects getting baked in particularly in fields where best practices move fast.

A negative security example that comes readily to mind are how bad government policies/standards helped cement for a long time the awful practice of complex password requirements including rapid change requirements, "security questions" and so on. These are actively negative for security, people in the field realized pretty fast (and of course many argued from the start) that the only reqs for passwords should be some minimum length, not using previously exposed ones, and having a sufficiently high maximum length that everyone is free to use more comfortable ones like diceware if they wished. While that has been getting revised at last bureaucracy still moves much too slowly there.

Of course this hasn't made it through the gauntlet and hopefully won't, but I'm glad to see it getting some attention.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#9
post #6
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

This EU effort to control is ongoing for many years now, how is it in any way unexpected?

Perhaps I'm out of the loop, but the EU attempting to make it illegal to distribute web browsers that don't include certain features is unexpected (and deeply worrying) to me.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#10
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

Governments though can do that through their own passive demand. Ie., they can issue proper smartcards/tokens for citizens to identify themselves with, and then say that those can (and eventually must) be used for electronic interactions with the government itself (taxes being a big one but they'd easily be useful for a range of stuff). Follow/improve open standards. With something good, open and convenient private usage will naturally follow. Government can also by definition get involved with the issue of legal liability and fix BS like "identity theft" by shifting liability for businesses who do not meet good authentication standards. Doing it that way also creates room for fixing serious issues in practice before a natural rollout, as it starts by the government dogfooding its own standard. And if a lot of sites demand it, browsers will respond absent overwhelming reason not to, which itself is a good form of pressure to get said overwhelming reasons fixed.

I'm very doubtful though that trying to just directly legislate how software universally works though bypassing process is a good idea. Massive room for abuse as well.

Post reply on HN