Live data from Hacker News

Mozilla publishes position paper on the EU Digital Identity Framework

blog.mozilla.org

131–140 of 161 posts

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#131
post #89
post #68

Earlier quoted context omitted.

> Not all European CAs meet browsers' root programs requirements. That sounds like a huge problem, why should EU trust that USA handles trust certificates well? Of course they would want to regulate this instead of leaving that extremely large security hole open, letting USA alone decide what counts as secure or not is not in EU's interests.

I think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse. On the other hand, can Mozilla accept an Iranian CA even if they can match the root program's requirements? Amusingly, Mozilla rejected the US government's request to add the federal P…

> Who should users trust more: Mozilla or their local government?

Is that really a question to be taken seriously? One is a private organization, completely unaccounted for and in a foreign jurisdiction, who sets their own rules and follows up on themselves.

The other is accountable and audited by independent auditors in a system which upholds separation of power and keeps independent media?

(Just to clarify: Neither Mozilla or anyone else should accept QWAC or any other standard in the face of legitimate concerns, of course. That's not what trust means.)

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#132
post #99

The use cases for digital identity are almost all pernicious. Sure, you can use it for nice things like public services, except we do that today quite expansively without one, and why do we need biometric level proofs for that? A government digital identity means that every informal transaction in the economy that uses it relies on the state as an inline broker. We can see this today with vax passports, where just th…

> Why do you need to prove your identity unless you there is some intent to prosecute you? Most of the value in the economy is based on people taking on transaction risk on behalf of others, so replacing it with digital identity will destroy degrees of economic freedom and opportunity for your kids and grandkids. Identity does not create opportunity, it limits it. I don't understand this argument at all. In what way…

With the rise of the internet I now consider my identity to be valuable. So I don't give it away for free.

I personally don't want my identity checked unless I'm asking someone to trust me. And I'd rather use a trust-minimizing system before going there. You don't need your id checked when going to the restaurant or the theater. You need to check someone's id when they take your money and promise you something in return (and even then, there may be a better way).

> I don't see a single instance of trade being limited even if all transactions were between established identities.

Do you buy something if you need to send a copy of your id? Do you use a website if it requires Facebook connect?

The issues of tight tracking you mention would be amplified by widespread use of id checks so I think it's essential not to do them often.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#133
post #94

Earlier quoted context omitted.

I never asked EU to do this for me, and don't want it. No government should have this power. Who did? I don't remember a single party having this in their program.

If you don't like it then you can ask your country representatives to block it for your country, EU doesn't have the power to enforce anything locally. And if all of EU doesn't like it then you can vote out the people who did it and they will give new recommendations next cycle. EU is safe in that way since the people making the legally binding laws to enforce them aren't the same people making the EU laws, so everyt…

Wrong since at least 2009. The EU has the right to force regulations and directives - if the country doesn't implement EU law correctly, the EU can sue the state, stop the flow of donations and place sanctions...

The EU itself says so:

- https://ec.europa.eu/info/law/law-making-process/applying-eu...

- https://ec.europa.eu/info/law/law-making-process/applying-eu...

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#134
post #93

Earlier quoted context omitted.

Are chargers really a significant source of e-waste? E-waste is a direct consequence of technology progress. We're not still all using 486s. Technology advances, people want that new stuff. I would wager charging ports are insignificant.

Hey on my Android, I'm happy to reuse my old chargers. It would be another thing if I was on Apple ecosystem.

All the Apple chargers are compatible, and have been for quite a long time. They’ve had a standard USB-A port since at least 2004, and they now have a standard USB-C port.

The only reason to get a new charger is if you need more power, but that’s exactly the same situation as with Android. Where did you get the idea that you had to get new chargers?

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#135
post #92
post #88

Earlier quoted context omitted.

If basically everyone follows, then why require it and shut off or slow down future innovation? Regulations like this are nearly always obsolete by the time they are implemented.

> If basically everyone follows, then why require it and shut off or slow down future innovation? Regulations like this are nearly always obsolete by the time they are implemented. Apple doesn't follow it. Also the reason companies settled was that EU threated them with regulations, if they didn't follow through when some companies (Apple) misbehaves it would mean that such threats would lose teeth and wont solve fut…

> Apple doesn't follow it.

They did follow it. The initial agreement was about chargers, not cables, and you can charge any iPhone off any usb charger. Now, we can discuss the spirit versus the letter, but they signed the agreement and followed it.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#136
post #36

Earlier quoted context omitted.

I don't understand the 'never gotten usb-C' part. Modern phones have more than enough space for two connectors. So usb-C next to a micro-B charging port is no problem. After a while, almost all phone also have usb-C, most people like usb-C, so the industry can petition to replace micro-B with usb-C. Are there any examples where the EU mandates legacy stuff that is no longer useful, but still has to be kept anyway?

Is that really better though? Phones would have to be manufactured with an unused port - and if you want to use all the functionality you’d need to buy another cable (yet more e-waste) Not that I have ‘the answer’ just that it’s a hard problem.

Given that most of my phones have been replaced due to issues with the USB port it would be pretty sweet if my phones had two charging ports.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#137
post #114
post #62

Earlier quoted context omitted.

One element that results in less security is that it becomes more difficult to replace. For example, QWACs cannot legally be automated (e.g. via ACME), because of certain restrictions applied to needing to validate the natural or legal person making the certificate request. This actually was an issue for one CA (BuyPass) that tried to support ACME but ran afoul of the framework. While originally QWACs were proposed a…

Not being able to automatically renew certificates seems like a rather minor point in the bigger picture. I get QWAC goes against the trend of phasing out EV certs. But isn’t the real issue that the browsers don’t trust TSP audits carried out for EU member states?

It’s actually a huge issue - look at how eliminating a key difficulty in obtaining certificates massively increased HTTPS adoption (via LetsEncrypt and others)

Similarly, automation affects how easy or hard it is to replace a CA, for example, if moving to distrust a CA. If you rely on QWAC attributes, you can only use QWAC CAs, and changing CAs becomes significantly more complex.

The audit issue is definitely an issue: the audits used are fundamentally different than what browsers try to achieve, and so having to adopt the lower standard definitely impacts user security. However, my point was that in addition to those concerns, the technical design itself results in less robust and less agile systems, and that makes things less secure.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#138

I think the Browsers should swing the axe the other direction. Indicate the website is broken when EV certificates are present. Also, indicate all websites are broken if/or when the Root-CA-trust ever be forcefully extended to include EV CA authorities, in particular state backed authorities. I'm not sure about the EU, but forcing browsers green-light weak security is a violation of the USA's 1st amendment freedom of…

I don't see how the USA's first amendment is at all applicable to the EU.

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#139
post #81
post #71

Earlier quoted context omitted.

> Almost as if they've seen a shortcoming A shortcoming for _their_ goals. Their goals are at odds with what is best for us. It is a good thing the micro-b MoU did not have any teeth.

Do you have so short a memory about all the proprietary connectors we needed to suffer before?

Sorry. I don't have time to reply to this comment because I need to find my Motorola charger. The thin long barrel jack, not the older thick short barrel jack one...

Re: Mozilla publishes position paper on the EU Digital Identity Framework

#140
post #72
post #18

Earlier quoted context omitted.

I feel similarly about the EU forcing companies to use usb-C as a charging port. I love usb-C, and it is basically a requirement for any electronic I buy. But forcing everyone to use it until the end of time is ridiculous. Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C.

> Imagine if they had done this a few years ago, and the micro-B connector was mandated. We would never have gotten usb-C. But they didn't. These people aren't that dumb, they told companies to settle on a standard, and now that we have a good standard that basically everyone follows they want to make a law to ensure everybody follows it. Bringing up a scenario where they did the right thing and argue "just imagine i…

It is the standard now, but should it be the standard forever? What happens when we want better features as new tech is invented?
Post reply on HN