Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

11–20 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#11
post #8

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.

nonetheless your government can force your ISP to do so many things

Re: Some observations on the final text of the European Digital Identity framework

#12
So basically:

Governments are being given authority to create dodgey certificates,

Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and

Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up).

Or am I missing something?

Re: Some observations on the final text of the European Digital Identity framework

#13
post #7

Earlier quoted context omitted.

> Cookie banners happened because US devs didn't steelman EU regs. What would steelmaning EU regs have looked like? Not really sure what you mean by this.

A header to opt in instead of a banner... I'm sorry now I'm confused. Is UI design this hard? Is this neurotypical?

Yes, stupid shit like punishing your users with abusive UI for regulations you dislike is neurotypical.

Re: Some observations on the final text of the European Digital Identity framework

#14
post #8

Earlier quoted context omitted.

As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.

nonetheless your government can force your ISP to do so many things

Without a valid certificate, any ISP MITM attacks would be obvious

Re: Some observations on the final text of the European Digital Identity framework

#15

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes to the Forum and then browsers decide how to deal with that CA. Notably, in the worst case scenario, the browser developers can and have decided to completely distrust an entire CA, completely destroying their business. This has happened multiple times.

eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats.

All those existing government CAs are currently audited by CA/B. If Greece gets caught misissuing certificates they can have their CA roots revoked by the browser vendors. The concern is that under eIDAS, the EU could just not revoke the certificate, and the browser vendors' hands would be tied. They'd be forced to accept known bad CAs and every cert they sign, including the spyware ones.

Re: Some observations on the final text of the European Digital Identity framework

#16
post #8

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.

I’m curious though what CA your country uses for governmental services. Historically a lot of EU countries used some less than stellar CAs.

Re: Some observations on the final text of the European Digital Identity framework

#17
post #10
post #5

Earlier quoted context omitted.

> And every single government force you to download their own cert Is that true though? I’ve immigrated quite a bunch (western world only) and never had to download a certificate when interacting with the government.

They used yo. Now most governments just have their own "proper" CAs which are included by default in web browsers. If you look at the default CA list of Firefox or Chrome you will see most of them are public agencies.

I think Certificate transparency checks mean you should be able to tell if the certificate was fraudulently issued for a domain that is not with the CA. (This circumvents that.)

In your scenario, if the domains CA is the government CA anyway, then it's fair game. Most domains' CA will be cloudflare or whatever not the government CA.

Re: Some observations on the final text of the European Digital Identity framework

#18

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

The game is not over just because you trust a CA. If they sign a certificate for a domain, they have to also publish that they did (in the CT logs) before browsers will accept it. If they do so for an entity that didn't ask for it, that will be investigated by browser and OS vendors and it may easily end up with the CA becoming untrusted.

Re: Some observations on the final text of the European Digital Identity framework

#19

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't provide the password then it blocks and you can't make the obligatory declaration. If you don't send said declaration, you are liable for big fines...

Re: Some observations on the final text of the European Digital Identity framework

#20

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…

Well that's dystopian.
Post reply on HN