Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

61–70 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#61
post #33
post #15

Earlier quoted context omitted.

I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc). There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a f…

I doubt there is any text that browsers have to enable those certs by default outside the EU. It could weaken protection for people in the EU, but then the way forward is to make requirements for root certs mandatory in the EU. Maybe I missed it, but did the document require special UI elements for EU certs?

[deleted]

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#62
post #12

I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…

One element that results in less security is that it becomes more difficult to replace.

For example, QWACs cannot legally be automated (e.g. via ACME), because of certain restrictions applied to needing to validate the natural or legal person making the certificate request. This actually was an issue for one CA (BuyPass) that tried to support ACME but ran afoul of the framework.

While originally QWACs were proposed as optional, regulation such as PSD2 attempts to make them mandatory for (financial services) servers to obtain. If one of those keys is compromised, then the server wishing you obtain a replacement certificate may have to wait weeks to obtain such a certificate, or make an in-person visit to the CA (e.g. the post office).

A considerable number of compromised or misissued certificates have failed to been revoked on the industry-agreed upon timelines (24 hours or 5 days, depending), because of challenges CAs have faced because their customers haven’t (or legally can’t) automate replacement, and because the additional information in the certificate requires manual validation, despite having no technical impact on the TLS connection.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#63
post #18
post #8

This did get posted a few weeks ago at the time it was written but didn't get much traction at that point, yet seems like a reasonably important issue. The EU has done worthy things for issues like privacy, but whatever pluses and minuses of regulating personal and business policy I'm a lot more dubious about government sticking its hand directly into how specific software (like browsers) functions. That seems like a…

I feel similarly about the EU forcing companies to use usb-C as a charging port. I love usb-C, and it is basically a requirement for any electronic I buy. But forcing everyone to use it until the end of time is ridiculous. Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C.

On a slightly different angle, my frustration is that it's not done on a general standards or outcome based requirement. For example rather than dictating a specific thing or even standard like micro-USB, simply require, e.g., that 90% of all power cables must comply with an industry self-organized standard within 3 years of the final release and, e.g., that the largest firms must subsidize the compliance by the smallest firms in order to prevent gaming the system to drive the small companies out of business.

There is a rather significant and major issue that this change highlights; essentially all our politicians and bureaucrats see themselves as smart and wise enough to be central planners and masters of the universe … when the truth could not be farther from it.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#64
It's ultimately my decision which certificates I will trust. I can choose to trust just one certificate, and ignore the Mozilla root store, or I can use Mozilla's root store, and modify it. These are my decisions, not Mozzilla's.

So this proposed regulation mandates that my browser must support QWAC, and include TSP roots? Does that mean that browsers MUST deprive me of the ability to control my root store? Would I be in violation if I modified my (open-source) browser so that it was no longer in compliance?

Supposing I published my patch on a website outside the EU (e.g. in the UK)?

To be clear, I don't want a root cert from any entity that is effectively controlled by a government, to be trusted by my browser. Some governments bother me more than others, (for example) a Turkish government-controlled CA was caught forging certificates. There's still a Turkish CA in there, I see; Debian have seen fit to remove it.

It's all fine, the sky won't fall. As long as I can still decide who I trust.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#65
post #7

> In a nutshell, the revised Article 45 would force browsers to suspend the ‘root store’ policies that are essential for maintaining trust and security online. [..] At the same time, the types of website certificates that browsers would be forced to accept, namely QWACs Can someone explain where this 'force' comes from? I wasn't aware the EU had such authority to decide how programs on a users private computer must b…

The EU has exactly as much authority as we believe it to have, and as much as the member states are willing to enforce.

Those of us not within their bounds could just decide not to comply with their nonsense, and there isn't a great deal that they could actually do about it.

Instead we're letting Europe pull a California, to the detriment of the entire internet.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#66
post #13
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

I don't think QWACs are at all the same as state controlled root certificates. Browsers aren't going to show EV certificates.

The proposed regulation requires that QWACs MUST be accepted and recognized as such, such as using the European List of Trusted Lists as part of the root store.

That is, if a QWAC is issued by a CA that is not part of the browser root store, it must not be rejected (as any other untrusted certificate would be).

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#67

Earlier quoted context omitted.

For citizens who want efficient, effective access to services that require identity. The need for identity isn’t going away, and a poor implementation doesn’t guard against overreach.

> The need for identity isn’t going away [..] My identity is just fine, but thanks for your concern :) I can walk into my local bank branch and ask to either pay in or withdraw money and they don't ask for any kind of ID(!), or my account number, becuase they actually know me :) They even tend to say "Hello $firstname" when I walk in, even if I only called in to use the ATM. Amazing how good ol'fashioned _offline_ id…

[deleted]

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#68
post #15
post #12

I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…

I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc). There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a f…

> Not all European CAs meet browsers' root programs requirements.

That sounds like a huge problem, why should EU trust that USA handles trust certificates well? Of course they would want to regulate this instead of leaving that extremely large security hole open, letting USA alone decide what counts as secure or not is not in EU's interests.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#69

Earlier quoted context omitted.

For citizens who want efficient, effective access to services that require identity. The need for identity isn’t going away, and a poor implementation doesn’t guard against overreach.

> The need for identity isn’t going away [..] My identity is just fine, but thanks for your concern :) I can walk into my local bank branch and ask to either pay in or withdraw money and they don't ask for any kind of ID(!), or my account number, becuase they actually know me :) They even tend to say "Hello $firstname" when I walk in, even if I only called in to use the ATM. Amazing how good ol'fashioned _offline_ id…

Why would someone try your local branch instead of any one of their 200 convenient nation-wide locations that all have access to your money and don’t know what you look like?

Personal trust as a foundation for identity became an untenable option as soon as the modern age arrived and our world expanded beyond our immediate geographic area.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#70
post #56
post #26

Earlier quoted context omitted.

When this becomes widespread then you can expect to have to authenticate this way everywhere. Want to make a Twitter account? Please authenticate with your government ID. Facebook? Of course. Video games? You bet. South Korea already has these retirements for (some of) their video games.

The draft revisions actually propose such authentication to be mandatory to implement for service providers if their users would like to use it. That is, it specifically targets websites (particularly Very Large Online Platforms) that they MUST accept such ID in lieu of an email or password, at the user’s request. This was part of the original motivation for the revisions, to target “Sign in with Facebook” or “Sign i…

So $VLOP is compelled to accept QWAC user-certificates, if one user requests it? And QWAC user-certificates are issued by TSPs whose CA cert must appear in the root-store unconditionally?

That means there is nothing preventing $TSP from forging my certificate, and giving it to criminals/government-agents, and nothing to keep the TSP in line, because the single audit constraint is "Keep the Minister satisfied".

I personally don't have a problem with the idea of replacing passwords with user-certs, provided I get to generate my own cert with my own private key. But the evidence is that general users can't learn how to use certificates.

I hate passwords, but I'd rather use passwords than a user-cert issued by an unreliable CA.

Post reply on HN