Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

101–110 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#101

Earlier quoted context omitted.

I can't speak on behalf of anyone but myself, but when that goal is less e-waste, their goal sure does align with mine, even if it may take me 20 extra minutes to charge my devices when something better than type C comes around. If I can charge my laptop with it, it's surely good enough for charging devices with a much smaller battery at least for the next decade or so.

Are chargers really a significant source of e-waste? E-waste is a direct consequence of technology progress. We're not still all using 486s. Technology advances, people want that new stuff. I would wager charging ports are insignificant.

Two drawers full of useless USB cables next to me imply so, and that's next to having 6 chargers and cables pretty much everywhere you can sit in my apartment.

But I wouldn't call it significant, I would call it completely unnecessary. I'd really rather buy one when I need it than get one with every single gadget I buy, which is precisely what the EU is trying to achieve.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#102
post #56
post #26

Earlier quoted context omitted.

When this becomes widespread then you can expect to have to authenticate this way everywhere. Want to make a Twitter account? Please authenticate with your government ID. Facebook? Of course. Video games? You bet. South Korea already has these retirements for (some of) their video games.

The draft revisions actually propose such authentication to be mandatory to implement for service providers if their users would like to use it. That is, it specifically targets websites (particularly Very Large Online Platforms) that they MUST accept such ID in lieu of an email or password, at the user’s request. This was part of the original motivation for the revisions, to target “Sign in with Facebook” or “Sign i…

I'm saying it'll go even further than that though. If you want to use the service you will have to authenticate through this method. This is pretty much as perfect as it gets for any company trying to vacuum up data, because they will be able to uniquely identify every user. It's effectively the end of privacy by obfuscation, because you will have to identify yourself.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#103
post #98

Earlier quoted context omitted.

"forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of speech." I understand the issues mentioned in passing scammy actors as legitimate but, in which way your rights to speech would be vulnerated?

It would be compelled speech if the law required the browsers to say that a connection is secure when its creators don't want it to. https://en.wikipedia.org/wiki/Compelled_speech Whether or not it would violate the 1st amendment would be up to the courts to decide.

The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#104
post #87

Earlier quoted context omitted.

The "unreliable CA" you are talking about here happens to be banks and similar. Do you trust that your bank doesn't just steal your money? Yes, you basically can't function in modern society if you don't. These e-id's just piggybacks on that trust to also work on online sign-ins. Most people worry more about their bank account being compromised than their github, so if these CA's (ie banks) starts to abuse their posi…

I see, QWACs are to be issued by banks. And websites are required to trust them. So if the bank gets hacked, then presumably the EU will indemnify the relying website against any legal action for trusting an unreliable CA? Even if that website is in China/Russia/Belarus? You seem to have read the proposed regulation, Jensson; the information you've given is not in the position paper. Any chance of a summary?

I've worked on identity infrastructure in an EU country, I know a lot of details how it works, the EU proposal is just an extension and merger of the local ones. I can just explain how the local ones works, I don't know the exact details of the EU proposal as I no longer work in that industry.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#105

Earlier quoted context omitted.

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

> A proper online identity framework is long due though [..] You're entitled to your opinion but for me, it's a firm "No, thanks". I feel considerably more comfortable* carrying a paper document which proves my vaccination/negative test than I do using any kind of government-approved app on my phone. * that's putting it mildly

looks like you haven't lived in 5 European countries and have to interact with all of them for things like taxes, pensions, vehicles registrations, and with mobile phones numbers that change, 2FAs that go crazy, passwords that expire etc. etc.

Yes, a common electronic ID is an absolute godsend. Can't wait for it to be implemented on every fricking public administration website.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#106
post #56

Earlier quoted context omitted.

The draft revisions actually propose such authentication to be mandatory to implement for service providers if their users would like to use it. That is, it specifically targets websites (particularly Very Large Online Platforms) that they MUST accept such ID in lieu of an email or password, at the user’s request. This was part of the original motivation for the revisions, to target “Sign in with Facebook” or “Sign i…

I'm saying it'll go even further than that though. If you want to use the service you will have to authenticate through this method. This is pretty much as perfect as it gets for any company trying to vacuum up data, because they will be able to uniquely identify every user. It's effectively the end of privacy by obfuscation, because you will have to identify yourself.

They can already do that though, nothing is stopping them from adding this to their sites right now. EU already has e-id for people and companies can use that if they want.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#107
post #87

Earlier quoted context omitted.

The "unreliable CA" you are talking about here happens to be banks and similar. Do you trust that your bank doesn't just steal your money? Yes, you basically can't function in modern society if you don't. These e-id's just piggybacks on that trust to also work on online sign-ins. Most people worry more about their bank account being compromised than their github, so if these CA's (ie banks) starts to abuse their posi…

I see, QWACs are to be issued by banks. And websites are required to trust them. So if the bank gets hacked, then presumably the EU will indemnify the relying website against any legal action for trusting an unreliable CA? Even if that website is in China/Russia/Belarus? You seem to have read the proposed regulation, Jensson; the information you've given is not in the position paper. Any chance of a summary?

The QWACs can be issued by anyone who meets the minimum requirements, which are substantially less than those required for TLS server CAs in browsers. So while it’s true that banks can issue these, in practice there are many small companies with fewer than a thousand or so certs out there which have the same requirement that they must be accepted.

The eID certificates do come with probative (legal) effect, but this is where it gets complicated.

If the CA is hacked or screws up, yes, the CA is liable. But only if you did everything you were supposed to, such as checking every element of the certificate. These certificates have a variety of fields, such as “liability only up to XX euros”, and you (the site or user) are liable if you use it for more than that.

PSD2 has shown that the standards are a nightmare to fully implement. https://wso2.com/blogs/thesource/all-you-need-to-know-about-... gives a useful overview of how it’s worked for PSD2, and the new Digital Identity Framework/eIDAS Revisions proposes to make that the approach the standard everywhere.

In practice, this means that the server accepting your certificate needs to implement all of this correctly (spoiler: they don’t), or they bear the liability if the CA gets hacked - and they can’t distrust that CA. It also means the CA potentially learns every site you visit, because the sites have to check with the CA (if using OCSP).

Of course, if the government themselves directed the CA to misissue - e.g. at the direction of law enforcement - no such liability would be presumed, because it was a presumably lawful issuance.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#108
post #56

Earlier quoted context omitted.

The draft revisions actually propose such authentication to be mandatory to implement for service providers if their users would like to use it. That is, it specifically targets websites (particularly Very Large Online Platforms) that they MUST accept such ID in lieu of an email or password, at the user’s request. This was part of the original motivation for the revisions, to target “Sign in with Facebook” or “Sign i…

I'm saying it'll go even further than that though. If you want to use the service you will have to authenticate through this method. This is pretty much as perfect as it gets for any company trying to vacuum up data, because they will be able to uniquely identify every user. It's effectively the end of privacy by obfuscation, because you will have to identify yourself.

Yes, the current regulation is targeted at government sites authenticating citizens, but the goal with these revisions is to require VLOPs to support this, along with allowing them the ability to require this for all websites. The original roadmap called out by the European Agency for Cybersecurity (ENISA) suggests a long-term goal of making this mandatory, effectively reviving the idea of the “Internet drivers license” (for users) and “Authorized domestic website” (for servers).

Source: https://www.enisa.europa.eu/publications/qualified-website-a...

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#109

It's ultimately my decision which certificates I will trust. I can choose to trust just one certificate, and ignore the Mozilla root store, or I can use Mozilla's root store, and modify it. These are my decisions, not Mozzilla's. So this proposed regulation mandates that my browser must support QWAC, and include TSP roots? Does that mean that browsers MUST deprive me of the ability to control my root store? Would I b…

This is all the initial recommendations says about browsers and certificates, there is nothing about preventing browsers from allowing the users to configure this, just to have them support it (and most of this is already supported by browsers, this is mostly just a recommendation to force all browsers to implement site security):

> To that end, web-browsers should ensure support and interoperability with Qualified certificates for website authentication pursuant to Regulation (EU) No 910/2014. They should recognise and display Qualified certificates for website authentication to provide a high level of assurance, allowing website owners to assert their identity as owners of a website and users to identify the website owners with a high degree of certainty.

Edit: It also limits this to larger web browser providers in another part and only after 5 years. So people are free to run their own forks of browsers, so I doubt that it will be forbidden for browsers to just have a setting for specific sets of certs.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#110

Earlier quoted context omitted.

Are chargers really a significant source of e-waste? E-waste is a direct consequence of technology progress. We're not still all using 486s. Technology advances, people want that new stuff. I would wager charging ports are insignificant.

Two drawers full of useless USB cables next to me imply so, and that's next to having 6 chargers and cables pretty much everywhere you can sit in my apartment. But I wouldn't call it significant, I would call it completely unnecessary. I'd really rather buy one when I need it than get one with every single gadget I buy, which is precisely what the EU is trying to achieve.

Oh I'd totally rather just buy one as well, but let's be honest this is a first world problem around convenience, it's not going to put any significant dent in the global e-waste problem.
Post reply on HN