The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…
Mozilla publishes position paper on the EU Digital Identity Framework
111–120 of 161 posts
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#112Earlier quoted context omitted.
It would be compelled speech if the law required the browsers to say that a connection is secure when its creators don't want it to. https://en.wikipedia.org/wiki/Compelled_speech Whether or not it would violate the 1st amendment would be up to the courts to decide.
The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#113Earlier quoted context omitted.
I think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse. On the other hand, can Mozilla accept an Iranian CA even if they can match the root program's requirements? Amusingly, Mozilla rejected the US government's request to add the federal P…
Trust in government is typically a lot higher in EU than most other parts of the world, so you can't really compare. I know Americans often wants private companies to protect them from governments, but in EU people typically wants their government to protect them from private companies. I trust my government way more than I trust Mozilla, Google, Microsoft and Apple combined, it isn't even close.
https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB...
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#114I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…
One element that results in less security is that it becomes more difficult to replace. For example, QWACs cannot legally be automated (e.g. via ACME), because of certain restrictions applied to needing to validate the natural or legal person making the certificate request. This actually was an issue for one CA (BuyPass) that tried to support ACME but ran afoul of the framework. While originally QWACs were proposed a…
I get QWAC goes against the trend of phasing out EV certs. But isn’t the real issue that the browsers don’t trust TSP audits carried out for EU member states?
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#115I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…
I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc). There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a f…
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#116Earlier quoted context omitted.
The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.
I feel there is a big difference between a mandated warning label (California cancer labels), Vs a mandated endorsement like forcing browses to say that unsecure connection is secure.
You might object to this for other reasons, but free speech isn't a good reason.
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#117I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…
QWACS are untrustworthy because they can be issued by a CA that is not publicly audited. But the way I understand it, a QWAC is an identity certificate, issued to users, not to websites. AIUI, websites are to be compelled to accept such user-certs in lieu of a password. Well, I don't see what that has to do with the contents of the root store - that controls the website identities that my browser will accept, not the…
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#118Earlier quoted context omitted.
It would be compelled speech if the law required the browsers to say that a connection is secure when its creators don't want it to. https://en.wikipedia.org/wiki/Compelled_speech Whether or not it would violate the 1st amendment would be up to the courts to decide.
The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.
That's because it's commercial speech [0] attached to a sale of a product, which gets a reduced level of protection. I'm don't think that you could, in the US, compel non-commercial software to express messages like "We trust this CA". Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the CA; to boycott a CA; to implement this in code and ship it.
[0] https://crsreports.congress.gov/product/pdf/IF/IF11072 ("The First Amendment: Categories of Speech")
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#119Earlier quoted context omitted.
The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.
> "The cancer label warnings in California aren't violating any free speech" That's because it's commercial speech [0] attached to a sale of a product, which gets a reduced level of protection. I'm don't think that you could, in the US, compel non-commercial software to express messages like "We trust this CA" . Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the C…
Nothing so far says that Mozilla can't tell its users that EU trusts this but Mozilla doesn't. However it is clear that it is intended to force Mozilla to at least gives the user the choice to trust EU on this.
Re: Mozilla publishes position paper on the EU Digital Identity Framework
#120Earlier quoted context omitted.
I see, QWACs are to be issued by banks. And websites are required to trust them. So if the bank gets hacked, then presumably the EU will indemnify the relying website against any legal action for trusting an unreliable CA? Even if that website is in China/Russia/Belarus? You seem to have read the proposed regulation, Jensson; the information you've given is not in the position paper. Any chance of a summary?
The QWACs can be issued by anyone who meets the minimum requirements, which are substantially less than those required for TLS server CAs in browsers. So while it’s true that banks can issue these, in practice there are many small companies with fewer than a thousand or so certs out there which have the same requirement that they must be accepted. The eID certificates do come with probative (legal) effect, but this i…