Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

111–120 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#111

eIDAS is a cartel created to protect the business interests of EU biggest certification authorities.

It is a digital certificate standard. Browser certificates is only a tiny part of it, that wasn't why it was made. Having a standard for digital certificates is a good thing, it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.

>it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.

eIDAS was introduced in 2016. Now 7 years later there still isn't a API specification for interoperability (there are drawings though https://blog.eid.as/new-apis-for-the-eidas-ecosystem/ )

In the meantime, any digital signature done in EU must be done with a certificate issued only by the "select" CA to be considered "valid".

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#112

For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/

eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU.

For example banking, signing official documents like grades from school etc, all of those usecases are a part of eIDAS. That is the core of the standard and there you really want to see all the certificate information to be sure it is the right origin, since unlike browsers there is no list of trusted CAs, you just see that some organization accepted it.

Edit: Browsers already had their own standard that they think is better than eIDAS, so they don't want this to apply to them. But Occam's razor says that EU just added "and browsers should also do this" instead of there being some conspiracy behind it, it was simple to just add everything instead of leaving just browsers out.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#113
post #49
post #45

Earlier quoted context omitted.

This forces browsers to accept all the CAs approved by the EU states, and you can be certain that some of them will be used for decrypting (and if needed modifying) the traffic

And then you can just tell the browser to not trust those CAs and you are safe. This is nothing like "chat control". This only lets the government spy on people who don't care if the government spies on them.

IIRC one cannot tell the browser to not trust root CAs, that's why all the fuss.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#115
post #91
post #86

Earlier quoted context omitted.

It is "easily", because current commercially available "firewall" appliances include that kind of capabilities. Just a few clicks, install a CA certificate, add a logging endpoint, done. Certain regulated industries like finance and medicine are required to use those. All chats are instantly intercepted and logged. And the way to spy on people via a certificate authority is exactly as described, you get a CA that sig…

Maybe browsers shouldn't hardcode those things? If they let you blacklist CAs you could do that yourself or via a plugin. There is nothing preventing browsers from implementing that, and have a one click button "don't trust compromised CAs". Could even had that during install as a toggle, would satisfy every legal requirement. If this means users gets more power over what CAs to trust then that is a good thing.

You can manually distrust hardcoded CAs in all common browsers. But even now, this is rarely used because it is tedious, there are roughly a hundred active CAs.

And depending on how that law will be interpreted by courts, manually distrusting might be considered illegal.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#116

eIDAS is a cartel created to protect the business interests of EU biggest certification authorities.

It is a digital certificate standard. Browser certificates is only a tiny part of it, that wasn't why it was made. Having a standard for digital certificates is a good thing, it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.

I’ve read enough mozilla.dev.security.policy threads along the lines of “but we’re a qualified eIDAS CA (erm, TSP)! — but your audits, key management, and issuance controls are all crap! — but eIDAS!” that I feel that it might, in fact, be partly an attempt by CAs to ensure that they can’t be kicked out of browsers at the browsers’ discretion, or even have to obey CA/BF decisions. It certainly appeared that the fuss around QWACs got much louder as the EV UI downgrade progressed.

Maybe it wasn’t the original intention, but right now, even ignoring the surveillance angle, I feel that it would be a major downgrade to the post-Symantec state of the Web PKI. In particular, the process for getting a CA disqualified or inconvenienced in any other way seems to be so onerous as to be basically intractable, especially if you, the relying party, are not in the EU. As far as I can tell (but here I can be wrong), as a relying party you don’t even have standing to do anything about it—it’s considered to be solely the business of your country’s government, and if the government body doesn’t care (see: Facebook and the Irish DPA), tough, guess you’re a single-issue voter now.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#117

The proposal is so obscene that I doubt Apple, Google or even Microsoft would ever comply with it.

They'd probably be fined into submission if they don't though.

If it gets to that point, one alternative would be creating some ad-hoc non profits that are on paper not controlled by them (but in practice they are) and then giving up the control of their respective browsers to said non-profits.

But it won't get to that point. I don't really think the US government would be ok with a regulation like this, either, and they have even more bargaining power than tech companies.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#119
Related:

https://mullvad.net/en/blog/2023/11/2/eu-digital-identity-fr...

https://alecmuffett.com/article/108139

(via https://news.ycombinator.com/item?id=38109581 and https://news.ycombinator.com/item?id=38109731 respectively, but we merged the comments hither)

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#120
post #81
post #75

Earlier quoted context omitted.

There's probably at most one person every ten millions who uses add-ons displaying each connection's certificate authority; and even them will likely not notice anything if it's only done to them occasionally (not to mention that absolutely no one checks the connections used to download third-party stuff, to my knowledge).

Yes, because CA level attacks are basically nonexistent and not a very big deal since they require you to control the targets internet connection. The moment people learn that the US government could control a CA and your internet provider to spy on you maybe that will change. But as is people think it is too much work for governments to bother with it.

> Yes, because CA level attacks are basically nonexistent and not a very big deal.

I'd call that bs, CA level attacks are very unlikely to be detected, so we know little about their prevalence.

(you edited your comment to add... that it requires you to control the targets internet connection?? And "the moment people learn that thenUS government could control (a CA) and your internet provider to spy on you maybe that will change With tls becoming ubiquitous they're now indispensable

Post reply on HN