Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

21–30 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#21
post #18
post #8

This did get posted a few weeks ago at the time it was written but didn't get much traction at that point, yet seems like a reasonably important issue. The EU has done worthy things for issues like privacy, but whatever pluses and minuses of regulating personal and business policy I'm a lot more dubious about government sticking its hand directly into how specific software (like browsers) functions. That seems like a…

I feel similarly about the EU forcing companies to use usb-C as a charging port. I love usb-C, and it is basically a requirement for any electronic I buy. But forcing everyone to use it until the end of time is ridiculous. Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C.

For the record, the feedback period on the EU charging port directive proposal is still open until tomorrow: https://ec.europa.eu/info/law/better-regulation/have-your-sa...

I quickly glanced at a couple of the feedback documents they've got so far, and they seem to echo your concerns. We'll see if the parliament makes any changes.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#22
post #9
post #6

Earlier quoted context omitted.

This EU effort to control is ongoing for many years now, how is it in any way unexpected?

Perhaps I'm out of the loop, but the EU attempting to make it illegal to distribute web browsers that don't include certain features is unexpected (and deeply worrying) to me.

The EU has been attacking encryption for years. To attack the browser's root certificates does not seem out of character.

Deeply worrying, yes, but not unexpected.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#24
post #7

> In a nutshell, the revised Article 45 would force browsers to suspend the ‘root store’ policies that are essential for maintaining trust and security online. [..] At the same time, the types of website certificates that browsers would be forced to accept, namely QWACs Can someone explain where this 'force' comes from? I wasn't aware the EU had such authority to decide how programs on a users private computer must b…

> I wasn't aware the EU had such authority to decide how programs on a users private computer must behave.

Why not? They publish directives that result in criminal law in member states all the time.

A directive is published, member states are obligated to turn that into domestic legislation, and yes, ultimately a state can criminalise lots of things if it wants to.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#25
post #9
post #6

Earlier quoted context omitted.

This EU effort to control is ongoing for many years now, how is it in any way unexpected?

Perhaps I'm out of the loop, but the EU attempting to make it illegal to distribute web browsers that don't include certain features is unexpected (and deeply worrying) to me.

They are protecting their interest

Why should a foreign country have control over my interests?

Why should Mozilla DECIDE what I should and shouldn't trust?

I am very glad that the public opinion decided to not trust Firefox at all (3% market share today)

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#26
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

When this becomes widespread then you can expect to have to authenticate this way everywhere. Want to make a Twitter account? Please authenticate with your government ID. Facebook? Of course. Video games? You bet.

South Korea already has these retirements for (some of) their video games.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#27
post #12

I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…

They're not saying EVs or QWACs are themselves less secure than DV. Rather they are saying that they aren't more secure (because of difficulties interpreting them) and so leading users to place more trust in them can hurt the consumers.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#28
I think the Browsers should swing the axe the other direction. Indicate the website is broken when EV certificates are present. Also, indicate all websites are broken if/or when the Root-CA-trust ever be forcefully extended to include EV CA authorities, in particular state backed authorities.

I'm not sure about the EU, but forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of speech. Regrettably I would not be surprised if EU took a more authoritarian stance.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#29
post #7

> In a nutshell, the revised Article 45 would force browsers to suspend the ‘root store’ policies that are essential for maintaining trust and security online. [..] At the same time, the types of website certificates that browsers would be forced to accept, namely QWACs Can someone explain where this 'force' comes from? I wasn't aware the EU had such authority to decide how programs on a users private computer must b…

> I wasn't aware the EU had such authority to decide how programs on a users private computer must behave. Why not? They publish directives that result in criminal law in member states all the time. A directive is published, member states are obligated to turn that into domestic legislation, and yes, ultimately a state can criminalise lots of things if it wants to.

> such authority

Key word "such". Prescribing which certificates I am obligated to trust is many many steps beyond e.g. banning DRM circumvention (which is itself a step too far IMO).

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#30

I think the Browsers should swing the axe the other direction. Indicate the website is broken when EV certificates are present. Also, indicate all websites are broken if/or when the Root-CA-trust ever be forcefully extended to include EV CA authorities, in particular state backed authorities. I'm not sure about the EU, but forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of…

"forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of speech."

I understand the issues mentioned in passing scammy actors as legitimate but, in which way your rights to speech would be vulnerated?

Post reply on HN