Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

31–40 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#31
post #25

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

> Or a transfer of power from US-centric companies to actual sovereign bodies.

Why are your characterizing the CA/Browser forum as US centric companies? Its a collection of certificate issuers from all over and notably includes European Accredited Conformity Assessment Bodies’ Council and the European Telecommunications Standards Institute.

Re: Some observations on the final text of the European Digital Identity framework

#32
post #25

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

The thing is that you can currently choose which org to give that power, and at least so far, those orgs have acted in line with wanting you to choose them (i.e. on your behalf).

Re: Some observations on the final text of the European Digital Identity framework

#33
post #25

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

I would far rather have things decided by US-centric companies than even somewhat influenced by France and Germany. At least the former have comprehensible motivations.

Re: Some observations on the final text of the European Digital Identity framework

#34
post #28

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

I think they are just certs to identify yourself to EU or national insititutions for procedures (filling taxes and so), like the certs some European countries issue.

The proposed certificate authorities can generate certificates for any entity, not just EU sites and not just new ones. They would have to be treated as valid, per the regulation.

Trust is the critical component in the PKI infrastructure. When it’s subverted and you can’t just remove the offending authorities, then it’s not really working properly anymore.

Re: Some observations on the final text of the European Digital Identity framework

#35
I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone.

People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it.

All I see are advantages.

And Sweden isn't alone in using some sort of eID.

So how come the EU can't just build on existing experience? Why are they making it more difficult?

Re: Some observations on the final text of the European Digital Identity framework

#36

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

Re: Some observations on the final text of the European Digital Identity framework

#37
post #25

Earlier quoted context omitted.

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

> Or a transfer of power from US-centric companies to actual sovereign bodies. Why are your characterizing the CA/Browser forum as US centric companies? Its a collection of certificate issuers from all over and notably includes European Accredited Conformity Assessment Bodies’ Council and the European Telecommunications Standards Institute.

[flagged]

Re: Some observations on the final text of the European Digital Identity framework

#38
post #5

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

> And every single government force you to download their own cert Is that true though? I’ve immigrated quite a bunch (western world only) and never had to download a certificate when interacting with the government.

here's one example, the brazil irs https://www.receita.gov.br/

good lucky finding the cert if you didn't download your firefox in brazilian portuguese or didn't register you apple device in brazil. I mean, it is not difficult to find the cert, but it is a pain for travelers.

Re: Some observations on the final text of the European Digital Identity framework

#39

Earlier quoted context omitted.

In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…

I’m curious what country this is, if you’re willing to share. I’m surprised any business filing is using a desktop app rather than on the web these days.

Costa Rica. And before you can download some of the installers, they ask for your unique digital signature card number.

Re: Some observations on the final text of the European Digital Identity framework

#40
post #5

Earlier quoted context omitted.

> And every single government force you to download their own cert Is that true though? I’ve immigrated quite a bunch (western world only) and never had to download a certificate when interacting with the government.

here's one example, the brazil irs https://www.receita.gov.br/ good lucky finding the cert if you didn't download your firefox in brazilian portuguese or didn't register you apple device in brazil. I mean, it is not difficult to find the cert, but it is a pain for travelers.

The problem seems to be "wrong domain", not "CA not recognized". You sure you have the right URL?
Post reply on HN