Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

1–10 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#2
> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ...

So same as today but with less steps?

Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is game over.

e.g. https://pki.treas.gov/crl_certs.htm https://www.bit.admin.ch/bit/en/home/themes/swiss-government... plus all the gov CAs already in your browser (looking at firefox source they include, guangdong, taiwan, honkkong, netherlands and Greece. IOS 16 contains spain, belgium, something called "Government Root Certification Authority 00 B6 4B 88 07 E2 23 EE C8 5C 12 AD A6 0E 06 A1 F2" :shrug, greece, hk, Netherlands, Switzerland.

Re: Some observations on the final text of the European Digital Identity framework

#3
Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend.

Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

Re: Some observations on the final text of the European Digital Identity framework

#4
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

> Cookie banners happened because US devs didn't steelman EU regs.

What would steelmaning EU regs have looked like? Not really sure what you mean by this.

Re: Some observations on the final text of the European Digital Identity framework

#5

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

> And every single government force you to download their own cert

Is that true though? I’ve immigrated quite a bunch (western world only) and never had to download a certificate when interacting with the government.

Re: Some observations on the final text of the European Digital Identity framework

#6
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

> Cookie banners happened because US devs didn't steelman EU regs. What would steelmaning EU regs have looked like? Not really sure what you mean by this.

> What would steelmaning EU regs have looked like?

A simple "decline [all]" / "accept" choice, not a huge list with dozens of sliders for dozens of options each labelled "legitimate interest" all of which are set to "Accept" by default?

Re: Some observations on the final text of the European Digital Identity framework

#7
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

> Cookie banners happened because US devs didn't steelman EU regs. What would steelmaning EU regs have looked like? Not really sure what you mean by this.

A header to opt in instead of a banner...

I'm sorry now I'm confused. Is UI design this hard? Is this neurotypical?

Re: Some observations on the final text of the European Digital Identity framework

#8

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.

Re: Some observations on the final text of the European Digital Identity framework

#9
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

> Cookie banners happened because US devs didn't steelman EU regs. What would steelmaning EU regs have looked like? Not really sure what you mean by this.

Only use cookies to provide services that the user specifically asks you to provide. Never use the cookies to anything where the action wasn't initiated by the user. That way, nothing you do requires asking for consent and you don't need a stupid banner.

Re: Some observations on the final text of the European Digital Identity framework

#10
post #5

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

> And every single government force you to download their own cert Is that true though? I’ve immigrated quite a bunch (western world only) and never had to download a certificate when interacting with the government.

They used yo. Now most governments just have their own "proper" CAs which are included by default in web browsers. If you look at the default CA list of Firefox or Chrome you will see most of them are public agencies.
Post reply on HN