Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

41–50 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#41
post #25

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

Sovereign-my-ass when they can issue any cert and mitm anything without any recourse.

Re: Some observations on the final text of the European Digital Identity framework

#42

Earlier quoted context omitted.

In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…

Well that's dystopian.

The same central bank is asking banks (and other entities) for unanonymized information about costaricans, including bank deposits, to publish an "information package" indexed by geographical location. This under the pretext of being required by the IMF. I found it curious that nobody in the legislative commission (akin to a "congressional hearing") tasked with looking into the matter has mentioned the importance of differential privacy.

Re: Some observations on the final text of the European Digital Identity framework

#43

Earlier quoted context omitted.

In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…

I’m curious what country this is, if you’re willing to share. I’m surprised any business filing is using a desktop app rather than on the web these days.

> I’m surprised any business filing is using a desktop app rather than on the web these days.

It's a complete nightmare. If you want to use some other digital services you are restricted to specific browser versions, some only allow you to use Windows, and in some cases the unsigned installer is only available via HTTP.

Re: Some observations on the final text of the European Digital Identity framework

#44

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID.

Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services despite warning my bank about the potential problems months ahead of the forced transition. The only way to regain access is to travel back to Denmark and visit my bank or my local council.

Re: Some observations on the final text of the European Digital Identity framework

#45
post #44

Earlier quoted context omitted.

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…

an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.

Re: Some observations on the final text of the European Digital Identity framework

#46

Earlier quoted context omitted.

here's one example, the brazil irs https://www.receita.gov.br/ good lucky finding the cert if you didn't download your firefox in brazilian portuguese or didn't register you apple device in brazil. I mean, it is not difficult to find the cert, but it is a pain for travelers.

The problem seems to be "wrong domain", not "CA not recognized". You sure you have the right URL?

i'm mobile. probably got the wrong url. only have bookmarks for the ca certs https://www.gov.br/iti/pt-br/assuntos/repositorio/repositori...

Re: Some observations on the final text of the European Digital Identity framework

#47

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

BankID is mostly snakeoil. It's not really much more than TOTP 2fa, where you have to have shown physical ID to some of the involved organizations at some point. All the stuff they do with keys is pointless in the end, and is just theatrics to make it sound safe.

The providers holds all the keys, you cannot verify that a signature is legit yourself, you wont get access to the keys they use to sign things, and a cryptographic signature is not really the same as a normal signature on a document.

Re: Some observations on the final text of the European Digital Identity framework

#48
post #44

Earlier quoted context omitted.

Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…

an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.

I agree, lack of standardization discourages freedom of movement.

However, it is also necessary to make sure data privacy is factored in.

Re: Some observations on the final text of the European Digital Identity framework

#49
post #25

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.

Re: Some observations on the final text of the European Digital Identity framework

#50
post #22
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

>Cookie banners happened because US devs didn't steelman EU regs. EU sites have the same amount of cookie banners as US ones. (ie, all major sites have one)

I frequently travel to the EU and the amount of cookie banners is decidedly higher.
Post reply on HN