Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

21–30 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#21

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

I filed the obvious bug against Firefox ten years ago :(

https://bugzilla.mozilla.org/show_bug.cgi?id=953322

Re: Some observations on the final text of the European Digital Identity framework

#22
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

>Cookie banners happened because US devs didn't steelman EU regs.

EU sites have the same amount of cookie banners as US ones. (ie, all major sites have one)

Re: Some observations on the final text of the European Digital Identity framework

#23

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…

I’m curious what country this is, if you’re willing to share.

I’m surprised any business filing is using a desktop app rather than on the web these days.

Re: Some observations on the final text of the European Digital Identity framework

#24

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

The game is not over just because you trust a CA. If they sign a certificate for a domain, they have to also publish that they did (in the CT logs) before browsers will accept it. If they do so for an entity that didn't ask for it, that will be investigated by browser and OS vendors and it may easily end up with the CA becoming untrusted.

Well this is it, they will no longer become untrusted. They can however, ask to have the offending certificate revoked if they have proof it's bad and once they have permission from the authorities (they kind of have to grant the permission if there's evidence but will be on the authorities timeline).

Re: Some observations on the final text of the European Digital Identity framework

#25

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats

Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

Re: Some observations on the final text of the European Digital Identity framework

#26
post #8

Earlier quoted context omitted.

As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.

I’m curious though what CA your country uses for governmental services. Historically a lot of EU countries used some less than stellar CAs.

My local government is using GlobalSign and the Tax Agency (and probably all of the central government) uses Entrust.

Re: Some observations on the final text of the European Digital Identity framework

#27
post #8

Earlier quoted context omitted.

As far as I know my country doesn't force me to download any certificate, and Firefox doesn't have a cert issued by my government.

nonetheless your government can force your ISP to do so many things

Yeah, and send somebody to my house yo shot me in the head. But none of them is happening.

Re: Some observations on the final text of the European Digital Identity framework

#28

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

I think they are just certs to identify yourself to EU or national insititutions for procedures (filling taxes and so), like the certs some European countries issue.

Re: Some observations on the final text of the European Digital Identity framework

#29
post #25

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

Browsers are allowed to ask permission to remove them if they are compromised.

They still have to receive that permission before they can do it.

Re: Some observations on the final text of the European Digital Identity framework

#30
post #25

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

It's pretty much an open forum, you can go and read discussions where they've removed CAs. It's more oriented around the individuals than the companies.
Post reply on HN