Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

111–120 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#111

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

You make a good point. In a state of pandemic, the population IS in some sense similar to livestock, bodies to be managed, since the virus has weaponized our bodies. Wouldn't you say?

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#112
post #98

Earlier quoted context omitted.

It would be compelled speech if the law required the browsers to say that a connection is secure when its creators don't want it to. https://en.wikipedia.org/wiki/Compelled_speech Whether or not it would violate the 1st amendment would be up to the courts to decide.

The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.

I feel there is a big difference between a mandated warning label (California cancer labels), Vs a mandated endorsement like forcing browses to say that unsecure connection is secure.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#113
post #96
post #89

Earlier quoted context omitted.

I think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse. On the other hand, can Mozilla accept an Iranian CA even if they can match the root program's requirements? Amusingly, Mozilla rejected the US government's request to add the federal P…

Trust in government is typically a lot higher in EU than most other parts of the world, so you can't really compare. I know Americans often wants private companies to protect them from governments, but in EU people typically wants their government to protect them from private companies. I trust my government way more than I trust Mozilla, Google, Microsoft and Apple combined, it isn't even close.

Mozilla has identified issues with CAs that are part of eIDAS. The severity of these issues can be debated, but the nice part of Mozilla's root program is that these are publicly debated. For example, the community identified repeated issues with the CA Certinomis and after failures to improve they were distrusted. Is it a good thing that the EU says that doesn't matter and Certinomis certs must be trusted as part of eIDAS?

https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB...

https://wiki.mozilla.org/CA/Certinomis_Issues

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#114
post #62
post #12

I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…

One element that results in less security is that it becomes more difficult to replace. For example, QWACs cannot legally be automated (e.g. via ACME), because of certain restrictions applied to needing to validate the natural or legal person making the certificate request. This actually was an issue for one CA (BuyPass) that tried to support ACME but ran afoul of the framework. While originally QWACs were proposed a…

Not being able to automatically renew certificates seems like a rather minor point in the bigger picture.

I get QWAC goes against the trend of phasing out EV certs. But isn’t the real issue that the browsers don’t trust TSP audits carried out for EU member states?

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#115
post #15
post #12

I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…

I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc). There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a f…

Are the TSP audit requirements less strict than what the browsers’ root programs require?

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#116

Earlier quoted context omitted.

The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.

I feel there is a big difference between a mandated warning label (California cancer labels), Vs a mandated endorsement like forcing browses to say that unsecure connection is secure.

Sure there is a big difference, but not from the perspective of free speech. Both cases forces you to display a label even if you don't want to show it to people. It is understood that the label isn't your speech, hence it doesn't limit your free speech rights.

You might object to this for other reasons, but free speech isn't a good reason.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#117
post #12

I wonder why QWACs are less secure than DV. There is an argument why EV should be treated the same a DV I'm not buying that argument but for the moment let's accept it as true. However, now Mozilla is arguing that EV is less secure than DV. That seems weird to me. Currently, browsers have root certificates for lots of countries. I can imagine that for a country it becomes a huge problem if suddenly a major browser de…

QWACS are untrustworthy because they can be issued by a CA that is not publicly audited. But the way I understand it, a QWAC is an identity certificate, issued to users, not to websites. AIUI, websites are to be compelled to accept such user-certs in lieu of a password. Well, I don't see what that has to do with the contents of the root store - that controls the website identities that my browser will accept, not the…

QWACs are for web sites, not users. CAs have to be audited as a TSP in order to issue them and be approved by the member state.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#118
post #98

Earlier quoted context omitted.

It would be compelled speech if the law required the browsers to say that a connection is secure when its creators don't want it to. https://en.wikipedia.org/wiki/Compelled_speech Whether or not it would violate the 1st amendment would be up to the courts to decide.

The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.

>"The cancer label warnings in California aren't violating any free speech"

That's because it's commercial speech [0] attached to a sale of a product, which gets a reduced level of protection. I'm don't think that you could, in the US, compel non-commercial software to express messages like "We trust this CA". Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the CA; to boycott a CA; to implement this in code and ship it.

[0] https://crsreports.congress.gov/product/pdf/IF/IF11072 ("The First Amendment: Categories of Speech")

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#119

Earlier quoted context omitted.

The cancer label warnings in California aren't violating any free speech, this is the same thing so it wouldn't violate it. All the browsers would say is "The European Union has verified the identity of this site owner" or something similar.

> "The cancer label warnings in California aren't violating any free speech" That's because it's commercial speech [0] attached to a sale of a product, which gets a reduced level of protection. I'm don't think that you could, in the US, compel non-commercial software to express messages like "We trust this CA" . Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the C…

> Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the CA; to boycott a CA; to implement this in code and ship it.

Nothing so far says that Mozilla can't tell its users that EU trusts this but Mozilla doesn't. However it is clear that it is intended to force Mozilla to at least gives the user the choice to trust EU on this.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#120
post #107

Earlier quoted context omitted.

I see, QWACs are to be issued by banks. And websites are required to trust them. So if the bank gets hacked, then presumably the EU will indemnify the relying website against any legal action for trusting an unreliable CA? Even if that website is in China/Russia/Belarus? You seem to have read the proposed regulation, Jensson; the information you've given is not in the position paper. Any chance of a summary?

The QWACs can be issued by anyone who meets the minimum requirements, which are substantially less than those required for TLS server CAs in browsers. So while it’s true that banks can issue these, in practice there are many small companies with fewer than a thousand or so certs out there which have the same requirement that they must be accepted. The eID certificates do come with probative (legal) effect, but this i…

Thanks. Your explanation is miles more informative about that than the original article.
Post reply on HN