Earlier quoted context omitted.
> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.
Browsers are allowed to ask permission to remove them if they are compromised. They still have to receive that permission before they can do it.
Some observations on the final text of the European Digital Identity framework
51–60 of 153 posts
Re: Some observations on the final text of the European Digital Identity framework
#52> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
I filed the obvious bug against Firefox ten years ago :( https://bugzilla.mozilla.org/show_bug.cgi?id=953322
Re: Some observations on the final text of the European Digital Identity framework
#53Earlier quoted context omitted.
Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…
an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.
Re: Some observations on the final text of the European Digital Identity framework
#54Earlier quoted context omitted.
I think they are just certs to identify yourself to EU or national insititutions for procedures (filling taxes and so), like the certs some European countries issue.
The proposed certificate authorities can generate certificates for any entity, not just EU sites and not just new ones. They would have to be treated as valid, per the regulation. Trust is the critical component in the PKI infrastructure. When it’s subverted and you can’t just remove the offending authorities, then it’s not really working properly anymore.
Re: Some observations on the final text of the European Digital Identity framework
#55> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…
Re: Some observations on the final text of the European Digital Identity framework
#56Earlier quoted context omitted.
> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.
A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.
Re: Some observations on the final text of the European Digital Identity framework
#57Re: Some observations on the final text of the European Digital Identity framework
#58So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?
Re: Some observations on the final text of the European Digital Identity framework
#59Earlier quoted context omitted.
I filed the obvious bug against Firefox ten years ago :( https://bugzilla.mozilla.org/show_bug.cgi?id=953322
Do browsers check the CAA records for a domain if they exist? Seems like that would solve the issue.
Even if they did, it doesn't really address the problem. In order to mount an effective impersonation attack, the attacker needs to either control the network or the DNS. In either case, they will generally be able to remove or change the CAA record; remember that DNSSEC deployment is comparatively rare and browsers do not verify DNSSEC in any case.
Re: Some observations on the final text of the European Digital Identity framework
#60Earlier quoted context omitted.
an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.
At least your Spanish DNIe contains an X.509 certificate you can access via PKCS#11 that Just Works, both for authentication and signature. You can even use it for SSH!
On the other hand I also have the Japanese digital ID card (マイナンバーカード), and what a piece of crap. If you ever hear that Japan is the most technologically advanced country in the world: no, it is not.