Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

121–130 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#121
post #26

Earlier quoted context omitted.

A proper online identity framework is long due though. Maybe this is not the proper one but sending copies of my passport, electricity bills and lately selfie recordings as well to "prove my identity" doesn't seem right either.

When this becomes widespread then you can expect to have to authenticate this way everywhere. Want to make a Twitter account? Please authenticate with your government ID. Facebook? Of course. Video games? You bet. South Korea already has these retirements for (some of) their video games.

Yeah, and I never get asked by US companies to prove my identity with my credit card for adult content (which includes music videos from Laibach?!?!)... yawn ... typical US hysteria about IDs, but commercial exploitation is all fine and dandy.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#122
post #115
post #15

Earlier quoted context omitted.

I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc). There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a f…

Are the TSP audit requirements less strict than what the browsers’ root programs require?

Mozilla says so.

https://drive.google.com/file/d/1DgJe-Ku4u66JF2D6zha28tSKxPB...

I can't speak with authority, but my reading of PKI issues suggests Google is just as strict, while Microsoft and Apple are less strict. However, that just might be because MS and Apple are less public with their root programs.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#123

Earlier quoted context omitted.

> "The cancer label warnings in California aren't violating any free speech" That's because it's commercial speech [0] attached to a sale of a product, which gets a reduced level of protection. I'm don't think that you could, in the US, compel non-commercial software to express messages like "We trust this CA" . Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the C…

> Mozilla has a 1st amendment right to not trust to CA's, and to tell their users why they don't trust the CA; to boycott a CA; to implement this in code and ship it. Nothing so far says that Mozilla can't tell its users that EU trusts this but Mozilla doesn't. However it is clear that it is intended to force Mozilla to at least gives the user the choice to trust EU on this.

The part where they're forced to provide the EU's alternative version is still compelled speech.

The decision of trusting or not trusting a CA has an expressive character; it's not pure machine math. Some of the decisions are political speech, even: "we don't like the policies of country X, therefore we'll boycott their root certificate". (Roughly characterized)

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#124
post #99

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

> Why do you need to prove your identity unless you there is some intent to prosecute you? Most of the value in the economy is based on people taking on transaction risk on behalf of others, so replacing it with digital identity will destroy degrees of economic freedom and opportunity for your kids and grandkids. Identity does not create opportunity, it limits it. I don't understand this argument at all. In what way…

Unless the entity that vouches for the identity or oversees transactions wanted to limit the ability of some disfavored participants, for some reason.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#125
post #7

> In a nutshell, the revised Article 45 would force browsers to suspend the ‘root store’ policies that are essential for maintaining trust and security online. [..] At the same time, the types of website certificates that browsers would be forced to accept, namely QWACs Can someone explain where this 'force' comes from? I wasn't aware the EU had such authority to decide how programs on a users private computer must b…

> Would e.g. making a fork of Firefox that does not comply with this digital identity framework be illegal?

No, this only applies to medium to large companies shipping browsers and they only have to follow it after operating for 5 years. If you fork a browser and edit it then that is working as intended, and if you fork it and distribute binaries that is also ok since you aren't a medium big company. Possibly the company label refers to CA or site, but the 5 year window gives you plenty of time to refork every 5 years in the worst case, and this only apply if you operate as a browser provider so you can use it yourself forever.

"Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services"

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#126

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

You make a good point. In a state of pandemic, the population IS in some sense similar to livestock, bodies to be managed, since the virus has weaponized our bodies. Wouldn't you say?

The common method to deal with avian influenza is killing all the livestock when one case is detected. Your comparison is scary and uncanny, but well aligned with how violent the pandemic has been handled by various governments.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#127
post #99

Earlier quoted context omitted.

> Why do you need to prove your identity unless you there is some intent to prosecute you? Most of the value in the economy is based on people taking on transaction risk on behalf of others, so replacing it with digital identity will destroy degrees of economic freedom and opportunity for your kids and grandkids. Identity does not create opportunity, it limits it. I don't understand this argument at all. In what way…

Unless the entity that vouches for the identity or oversees transactions wanted to limit the ability of some disfavored participants, for some reason.

If your bank wants to stop you from making a transaction they can do so today as well, not sure how this would change anything. The big difference is that now you could verify the other parties identity before the transaction instead of just your bank doing it.

I can see an objection to erasure of cash, but not these identities.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#128

It's ultimately my decision which certificates I will trust. I can choose to trust just one certificate, and ignore the Mozilla root store, or I can use Mozilla's root store, and modify it. These are my decisions, not Mozzilla's. So this proposed regulation mandates that my browser must support QWAC, and include TSP roots? Does that mean that browsers MUST deprive me of the ability to control my root store? Would I b…

This is all the initial recommendations says about browsers and certificates, there is nothing about preventing browsers from allowing the users to configure this, just to have them support it (and most of this is already supported by browsers, this is mostly just a recommendation to force all browsers to implement site security): > To that end, web-browsers should ensure support and interoperability with Qualified c…

Thanks.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#129
post #96
post #89

Earlier quoted context omitted.

I think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse. On the other hand, can Mozilla accept an Iranian CA even if they can match the root program's requirements? Amusingly, Mozilla rejected the US government's request to add the federal P…

Trust in government is typically a lot higher in EU than most other parts of the world, so you can't really compare. I know Americans often wants private companies to protect them from governments, but in EU people typically wants their government to protect them from private companies. I trust my government way more than I trust Mozilla, Google, Microsoft and Apple combined, it isn't even close.

Mozilla argues in their paper that once governments in one part of the world start forcing browsers include root certificates, governments in other parts of the world will start doing the same shortly after. You might trust your government more, but you certainly wouldn't trust arbitrary governments more.

Furthermore, I have seen nothing wrong in mozilla's stewardship of the root certificate program in the decades it's been running, whereas mozilla points to deficiencies in the EU's certificate programs. This is to be expected since running a root store is not one of the EU's specialties. I would trust that government most that defers to private companies in areas where they lack expertise.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#130
post #68
post #15

Earlier quoted context omitted.

I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc). There is also the concern that special indicators displayed with a certificate can mislead users. A scummy company with an EV cert isn't any more trustworthy than if they had a DV cert, but browsers want to be careful not to imply a f…

> Not all European CAs meet browsers' root programs requirements. That sounds like a huge problem, why should EU trust that USA handles trust certificates well? Of course they would want to regulate this instead of leaving that extremely large security hole open, letting USA alone decide what counts as secure or not is not in EU's interests.

No one said they should. The EU should at least meet the same if not better standards. Instead they are trying to make an objectively less secure system.
Post reply on HN