Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

91–100 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#91
post #10

Earlier quoted context omitted.

Governments though can do that through their own passive demand. Ie., they can issue proper smartcards/tokens for citizens to identify themselves with, and then say that those can (and eventually must) be used for electronic interactions with the government itself (taxes being a big one but they'd easily be useful for a range of stuff). Follow/improve open standards. With something good, open and convenient private u…

I think you touch on the issue. Having a standard for Identity Management seems reasonable. Mandating that such a state-regulated identity be used for all on-line data passing on the internet seems like a nightmare waiting to happen. That may not be the step in between "collect underpants" and "profit" but it feels like it's coming. In the U.S., I'm sure something like this will be sold in the clothing of think-of-th…

> Mandating that such a state-regulated identity be used for all on-line data passing on the internet seems like a nightmare waiting to happen.

They didn't mandate that though, the proposal was that it should be possible to use it, not that everyone should be forced to use it. You would still be able to log in using other means.

Basically, facebook would be required to provide you with the option to use e-id to log in. But you could still log in with other means. It just gives you more freedom.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#92
post #88
post #72

Earlier quoted context omitted.

> Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C. But they didn't. These people aren't that dumb, they told companies to settle on a standard, and now that we have a good standard that basically everyone follows they want to make a law to ensure everybody follows it. Bringing up a scenario where they did the right thing and argue "just imagine i…

If basically everyone follows, then why require it and shut off or slow down future innovation? Regulations like this are nearly always obsolete by the time they are implemented.

> If basically everyone follows, then why require it and shut off or slow down future innovation? Regulations like this are nearly always obsolete by the time they are implemented.

Apple doesn't follow it. Also the reason companies settled was that EU threated them with regulations, if they didn't follow through when some companies (Apple) misbehaves it would mean that such threats would lose teeth and wont solve future problems. So if anything the problem here isn't EU, the reason that law is coming is Apple. Best possible scenario is that companies dynamically create new standards and fall inline, but Apple refuses to play along so regulations are necessary.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#93

Earlier quoted context omitted.

I can't speak on behalf of anyone but myself, but when that goal is less e-waste, their goal sure does align with mine, even if it may take me 20 extra minutes to charge my devices when something better than type C comes around. If I can charge my laptop with it, it's surely good enough for charging devices with a much smaller battery at least for the next decade or so.

Are chargers really a significant source of e-waste? E-waste is a direct consequence of technology progress. We're not still all using 486s. Technology advances, people want that new stuff. I would wager charging ports are insignificant.

Hey on my Android, I'm happy to reuse my old chargers.

It would be another thing if I was on Apple ecosystem.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#94
post #82
post #39

Earlier quoted context omitted.

Mozilla doesn’t decide that. Mozilla is an option _you_ can chose to use. It’s one of N options.

But all large browsers happens to be American. It makes sense that EU wants to regulate this rather than hand over all decisions related to trust to USA. For example, imagine if all big browsers everyone uses where made in China, and mostly just trusted Chinese CA. Do you think that would be a problem? Do you think the rest of the world would just let that happen instead of starting to regulate it? That is the situat…

I never asked EU to do this for me, and don't want it. No government should have this power. Who did? I don't remember a single party having this in their program.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#95
post #87

Earlier quoted context omitted.

So $VLOP is compelled to accept QWAC user-certificates, if one user requests it? And QWAC user-certificates are issued by TSPs whose CA cert must appear in the root-store unconditionally? That means there is nothing preventing $TSP from forging my certificate, and giving it to criminals/government-agents, and nothing to keep the TSP in line, because the single audit constraint is "Keep the Minister satisfied". I pers…

The "unreliable CA" you are talking about here happens to be banks and similar. Do you trust that your bank doesn't just steal your money? Yes, you basically can't function in modern society if you don't. These e-id's just piggybacks on that trust to also work on online sign-ins. Most people worry more about their bank account being compromised than their github, so if these CA's (ie banks) starts to abuse their posi…

I see, QWACs are to be issued by banks. And websites are required to trust them.

So if the bank gets hacked, then presumably the EU will indemnify the relying website against any legal action for trusting an unreliable CA? Even if that website is in China/Russia/Belarus?

You seem to have read the proposed regulation, Jensson; the information you've given is not in the position paper. Any chance of a summary?

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#96
post #89
post #68

Earlier quoted context omitted.

> Not all European CAs meet browsers' root programs requirements. That sounds like a huge problem, why should EU trust that USA handles trust certificates well? Of course they would want to regulate this instead of leaving that extremely large security hole open, letting USA alone decide what counts as secure or not is not in EU's interests.

I think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse. On the other hand, can Mozilla accept an Iranian CA even if they can match the root program's requirements? Amusingly, Mozilla rejected the US government's request to add the federal P…

Trust in government is typically a lot higher in EU than most other parts of the world, so you can't really compare. I know Americans often wants private companies to protect them from governments, but in EU people typically wants their government to protect them from private companies. I trust my government way more than I trust Mozilla, Google, Microsoft and Apple combined, it isn't even close.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#97
The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that?

A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just this month you have to check-in with the government before you can enter a restaurant. (only temporary, surely) It's designed to manage people like livestock, and we all know that some pigs are more equal than others. Even vax passports and so-called "mandates," have exploited loopholes in our high trust societies and assumed formlessness as to avoid being challenged legally. Digital identity regimes will use the same indirect methods. This is their strategy.

Why do you need to prove your identity unless you there is some intent to prosecute you? Most of the value in the economy is based on people taking on transaction risk on behalf of others, so replacing it with digital identity will destroy degrees of economic freedom and opportunity for your kids and grandkids. Identity does not create opportunity, it limits it.

Civilization doesn't survive malicious institutions that turn inward against the people they serve, and I hope other technologists think seriously about identity and consider the consequences of it falling into the hands of an enemy or evil institution, because having worked in identity, I guarantee it will.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#98

I think the Browsers should swing the axe the other direction. Indicate the website is broken when EV certificates are present. Also, indicate all websites are broken if/or when the Root-CA-trust ever be forcefully extended to include EV CA authorities, in particular state backed authorities. I'm not sure about the EU, but forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of…

"forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of speech." I understand the issues mentioned in passing scammy actors as legitimate but, in which way your rights to speech would be vulnerated?

It would be compelled speech if the law required the browsers to say that a connection is secure when its creators don't want it to.

https://en.wikipedia.org/wiki/Compelled_speech

Whether or not it would violate the 1st amendment would be up to the courts to decide.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#99

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

> Why do you need to prove your identity unless you there is some intent to prosecute you? Most of the value in the economy is based on people taking on transaction risk on behalf of others, so replacing it with digital identity will destroy degrees of economic freedom and opportunity for your kids and grandkids. Identity does not create opportunity, it limits it.

I don't understand this argument at all. In what way does the economy require that people take on risks of identity theft when they trade with each other? I don't see a single instance of trade being limited even if all transactions were between established identities.

There are other issues of tight tracking of course, but I don't see this one.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#100
post #94
post #82

Earlier quoted context omitted.

But all large browsers happens to be American. It makes sense that EU wants to regulate this rather than hand over all decisions related to trust to USA. For example, imagine if all big browsers everyone uses where made in China, and mostly just trusted Chinese CA. Do you think that would be a problem? Do you think the rest of the world would just let that happen instead of starting to regulate it? That is the situat…

I never asked EU to do this for me, and don't want it. No government should have this power. Who did? I don't remember a single party having this in their program.

If you don't like it then you can ask your country representatives to block it for your country, EU doesn't have the power to enforce anything locally. And if all of EU doesn't like it then you can vote out the people who did it and they will give new recommendations next cycle.

EU is safe in that way since the people making the legally binding laws to enforce them aren't the same people making the EU laws, so everything has to go through at least two levels of elected representatives to actually take effect. This means that if EU wants to spy on you then your country can block it, and if your country wants to spy via this system on you then they have to get approval from EU at least. Either way EU is an improvement over just having your local representatives.

Post reply on HN