Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

71–80 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#71
post #57

Earlier quoted context omitted.

A Memorandum of Understanding is a far cry from the legislation they are trying to push through. A MoU is not legally binding. From your link: > The recent 582-40 parliamentary vote in favor of a common charging standard came about because the European Commission's previous approach of merely "encouraging" tech companies to develop a standardized solution "fell short of the co-legislators' objectives," according to a…

Almost as if they've seen a shortcoming with signing just a memorandum of understanding and took it a step further this time around. > To address the challenges for consumers as well as the environment, the Commission has supported a common charging solution for mobile phones and similar electronic devices since 2009. The Commission first facilitated a voluntary agreement by the industry in 2009 that resulted in the…

> Almost as if they've seen a shortcoming

A shortcoming for _their_ goals. Their goals are at odds with what is best for us. It is a good thing the micro-b MoU did not have any teeth.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#72
post #18
post #8

This did get posted a few weeks ago at the time it was written but didn't get much traction at that point, yet seems like a reasonably important issue. The EU has done worthy things for issues like privacy, but whatever pluses and minuses of regulating personal and business policy I'm a lot more dubious about government sticking its hand directly into how specific software (like browsers) functions. That seems like a…

I feel similarly about the EU forcing companies to use usb-C as a charging port. I love usb-C, and it is basically a requirement for any electronic I buy. But forcing everyone to use it until the end of time is ridiculous. Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C.

> Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C.

But they didn't. These people aren't that dumb, they told companies to settle on a standard, and now that we have a good standard that basically everyone follows they want to make a law to ensure everybody follows it. Bringing up a scenario where they did the right thing and argue "just imagine if they didn't do the right thing here, that would be a problem!" isn't a strong argument.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#73

Earlier quoted context omitted.

> A proper online identity framework is long due though. Due by whom, and for what?

For citizens who want efficient, effective access to services that require identity. The need for identity isn’t going away, and a poor implementation doesn’t guard against overreach.

> services that require identity

Suppose I have my personal QWAC installed in my browser. Does this mean that I won't be able to visit $BIGSITE without authenticating and logging-in?

That wouldn't make things more efficient - it would create friction, because I'd have to switch browsers if I wanted to visit a site that I didn't want to authenticate to; or do some settings fandango to disable QWAC before clicking a link.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#74
post #71

Earlier quoted context omitted.

Almost as if they've seen a shortcoming with signing just a memorandum of understanding and took it a step further this time around. > To address the challenges for consumers as well as the environment, the Commission has supported a common charging solution for mobile phones and similar electronic devices since 2009. The Commission first facilitated a voluntary agreement by the industry in 2009 that resulted in the…

> Almost as if they've seen a shortcoming A shortcoming for _their_ goals. Their goals are at odds with what is best for us. It is a good thing the micro-b MoU did not have any teeth.

I can't speak on behalf of anyone but myself, but when that goal is less e-waste, their goal sure does align with mine, even if it may take me 20 extra minutes to charge my devices when something better than type C comes around.

If I can charge my laptop with it, it's surely good enough for charging devices with a much smaller battery at least for the next decade or so.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#75
post #29

Earlier quoted context omitted.

> I wasn't aware the EU had such authority to decide how programs on a users private computer must behave. Why not? They publish directives that result in criminal law in member states all the time. A directive is published, member states are obligated to turn that into domestic legislation, and yes, ultimately a state can criminalise lots of things if it wants to.

> such authority Key word "such". Prescribing which certificates I am obligated to trust is many many steps beyond e.g. banning DRM circumvention (which is itself a step too far IMO).

Likely it only applies to software you ship to users in EU, not software you use yourself even if you are in EU.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#76

Earlier quoted context omitted.

> A proper online identity framework is long due though. Due by whom, and for what?

For citizens who want efficient, effective access to services that require identity. The need for identity isn’t going away, and a poor implementation doesn’t guard against overreach.

The EU is already doing that through eIDAS. It's basically a federated login system for government services that works (or at least, should already be working) across governments.

The implementation is not that different from the "log in with Google/Facebook/Twitter/MySpace/Apple" buttons on many websites, though the login procedure is a bit more involved because of the sensitivity of the data.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#77
post #3

Authoritarianism raises its head in all sorts of interesting ways. Interesting to see the EU choose the path of Kazakhstan.[0] [0] - https://www.internetsociety.org/news/statements/2019/interne...

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

We use BankID for this in Norway (and elsewhere in Scandinavia I think).

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#78
post #12

I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…

QWACS are untrustworthy because they can be issued by a CA that is not publicly audited.

But the way I understand it, a QWAC is an identity certificate, issued to users, not to websites. AIUI, websites are to be compelled to accept such user-certs in lieu of a password. Well, I don't see what that has to do with the contents of the root store - that controls the website identities that my browser will accept, not the user-identity that the website accepts.

I read the position paper, but not the regulation. I'd like to see a better explanation of the regulation.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#79
post #10

Earlier quoted context omitted.

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

Governments though can do that through their own passive demand. Ie., they can issue proper smartcards/tokens for citizens to identify themselves with, and then say that those can (and eventually must) be used for electronic interactions with the government itself (taxes being a big one but they'd easily be useful for a range of stuff). Follow/improve open standards. With something good, open and convenient private u…

I think you touch on the issue.

Having a standard for Identity Management seems reasonable. Mandating that such a state-regulated identity be used for all on-line data passing on the internet seems like a nightmare waiting to happen.

That may not be the step in between "collect underpants" and "profit" but it feels like it's coming. In the U.S., I'm sure something like this will be sold in the clothing of think-of-the-children.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#80

I think the Browsers should swing the axe the other direction. Indicate the website is broken when EV certificates are present. Also, indicate all websites are broken if/or when the Root-CA-trust ever be forcefully extended to include EV CA authorities, in particular state backed authorities. I'm not sure about the EU, but forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of…

"forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of speech." I understand the issues mentioned in passing scammy actors as legitimate but, in which way your rights to speech would be vulnerated?

[deleted]
Post reply on HN