> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.
Some observations on the final text of the European Digital Identity framework
11–20 of 153 posts
Re: Some observations on the final text of the European Digital Identity framework
#12Governments are being given authority to create dodgey certificates,
Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and
Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up).
Or am I missing something?
Re: Some observations on the final text of the European Digital Identity framework
#13Earlier quoted context omitted.
> Cookie banners happened because US devs didn't steelman EU regs. What would steelmaning EU regs have looked like? Not really sure what you mean by this.
A header to opt in instead of a banner... I'm sorry now I'm confused. Is UI design this hard? Is this neurotypical?
Re: Some observations on the final text of the European Digital Identity framework
#14Earlier quoted context omitted.
As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.
nonetheless your government can force your ISP to do so many things
Re: Some observations on the final text of the European Digital Identity framework
#15> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats.
All those existing government CAs are currently audited by CA/B. If Greece gets caught misissuing certificates they can have their CA roots revoked by the browser vendors. The concern is that under eIDAS, the EU could just not revoke the certificate, and the browser vendors' hands would be tied. They'd be forced to accept known bad CAs and every cert they sign, including the spyware ones.
Re: Some observations on the final text of the European Digital Identity framework
#16> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.
Re: Some observations on the final text of the European Digital Identity framework
#17Earlier quoted context omitted.
> And every single government force you to download their own cert Is that true though? I’ve immigrated quite a bunch (western world only) and never had to download a certificate when interacting with the government.
They used yo. Now most governments just have their own "proper" CAs which are included by default in web browsers. If you look at the default CA list of Firefox or Chrome you will see most of them are public agencies.
In your scenario, if the domains CA is the government CA anyway, then it's fair game. Most domains' CA will be cloudflare or whatever not the government CA.
Re: Some observations on the final text of the European Digital Identity framework
#18> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
Re: Some observations on the final text of the European Digital Identity framework
#19> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
Re: Some observations on the final text of the European Digital Identity framework
#20> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…