Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

61–70 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#61
post #52
post #21

Earlier quoted context omitted.

I filed the obvious bug against Firefox ten years ago :( https://bugzilla.mozilla.org/show_bug.cgi?id=953322

Do browsers check the CAA records for a domain if they exist? Seems like that would solve the issue.

No, and the standard (RFC 6844) says they must not. That's because, in the eyes of the standard, a CAA record is applicable at time of issuance, but a valid certificate could have been previously issued (and still be valid), even though you've moved to a new CAA record for your next certificate.

"Relying Applications MUST NOT use CAA records as part of certificate validation."

For what you're looking for, DANE (RFC 6698) would be more useful and enable the browser to check the presented certificate against DNS (so effectively CAA on the client).

Re: Some observations on the final text of the European Digital Identity framework

#62
The discussion around eIDAS lacks the nuance of digital sovereignty. You can have issues all you want with the legal text, but what we have here is a one-sided take that completely ignores any aspirations to digital sovereignty. U.S. already has shown it is willing to use major infrastructure to deal with its adversaries. That was shown as it weaponized the SWIFT payments system. U.S. routinely seizes domains owned by its U.S.-based registries.

Browser vendors are not democratically ran institutions. One browser is owned by an ad broker and seller; the other browser is owned by an astroturfed* org that is 80% funded by the said ad broker and seller. Browsers not being allowed to stop their European users from accessing their European websites IS what I want. I do not want it to be possible for U.S. to coerce browsers to take out root stores to my bank, for instance.

And as for security requirements, that's just a load of BS. eIDAS is A+B, not A or B. The security requirements in the legal text are equivalent or higher that of cabforum's, minus the certificate transparency bit. And that's a fair critique. Such mechanism needs to be discussed and plausibly adopted. And we have the democratic institutions for that discourse. It's called ETSI. And browser vendors are welcome to participate in ETSI and give their suggestions of allowing certificate transparency. They aren't doing that; in good faith anyway! They're not participating in a democratic standards body, instead they're running propaganda campaigns trying to rile up their users.

To sum up, I want EU to gain digital sovereignty. Some of critiques are valid (I certainly don't like EV-style UI prescriptions), others are just bullshit. Bullshit we saw before GDPR. "The internet is going to be destroyed!". The internet wasn't destroyed. The internet is better after GDPR. Democratic institutions are good, ad funded browsers engaging in practices with zero accountability aren't.

*plausibly hyperbole; but I'm not sure seeing that Mozilla has shown itself to be useless, as it took pro-Google position in search engine anti-trust case

Re: Some observations on the final text of the European Digital Identity framework

#63

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

I don't want my bank to be an ID provider. I don't trust any bank, the problem is I just can't do without them in this world. But I have no doubt their goals are opposite to my own. They datamine and exploit us.

In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.

Re: Some observations on the final text of the European Digital Identity framework

#64

Earlier quoted context omitted.

an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.

At least your Spanish DNIe contains an X.509 certificate you can access via PKCS#11 that Just Works, both for authentication and signature. You can even use it for SSH!

Yeah I wish I could get one as a foreigner. I only get a shitty piece of green paper that doesn't last more than a few months in a wallet.

And I have to wait 10 years to change my citizenship over too. Now that the extreme-right party won the Dutch elections last week I'd really like to change it.

South Americans can change it over after only 5 years. But not EU citizens strangely.

Re: Some observations on the final text of the European Digital Identity framework

#65
post #44

Earlier quoted context omitted.

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…

I'm in the same boat, lost my BankID and with it everything it unlocks. I live 20000km from Sweden and can't easily make that trip, especially during the covid travel restrictions. Letters with notarised copies of ID were quickly dismissed by the bank. Hopefully I'll get there next year...

Re: Some observations on the final text of the European Digital Identity framework

#66
post #60

Earlier quoted context omitted.

At least your Spanish DNIe contains an X.509 certificate you can access via PKCS#11 that Just Works, both for authentication and signature. You can even use it for SSH!

Can confirm. I just renewed my Spanish DNIe last summer and not only was the whole process super smooth and took only a few minutes, but the certificate works on Linux out of the box! DNIe was crap for many years, but credit where credit is due, it has improved a lot . On the other hand I also have the Japanese digital ID card (マイナンバーカード), and what a piece of crap. If you ever hear that Japan is the most technologica…

Japan was miles ahead in the early 2000s but as some say, being ahead can also be a burden. And as a deeply traditional society they tend to cling to things that work. I heard that even faxes are still used there. In Austria too by the way but that's more because of an obscure legal status thing.

Re: Some observations on the final text of the European Digital Identity framework

#67

Earlier quoted context omitted.

an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.

At least your Spanish DNIe contains an X.509 certificate you can access via PKCS#11 that Just Works, both for authentication and signature. You can even use it for SSH!

Can the Spanish ID card be used for code signing (e.g. signed installers for Windows) and for S/MIME?

Can anyone here provide an example document / thing with a valid Spanish ID signature?

Re: Some observations on the final text of the European Digital Identity framework

#68
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

> Cookie banners happened because US devs didn't steelman EU regs.

This is one of the dumbest narratives I see on HN all the time. A community of people who build things for a living should know better.

Think of regulation as software designed to create an outcome in the real world.

If everyone is wrongly using/interpreting your software…the problem is not “everyone.” The problem is the design of your software.

Re: Some observations on the final text of the European Digital Identity framework

#69

The discussion around eIDAS lacks the nuance of digital sovereignty. You can have issues all you want with the legal text, but what we have here is a one-sided take that completely ignores any aspirations to digital sovereignty. U.S. already has shown it is willing to use major infrastructure to deal with its adversaries. That was shown as it weaponized the SWIFT payments system. U.S. routinely seizes domains owned b…

> The security requirements in the legal text are equivalent or higher that of cabforum's, minus the certificate transparency bit. And that's a fair critique. Such mechanism needs to be discussed

No, under no circumstances should browser vendors be forced to "discuss" the development and application of higher security standards with an adversary with a vested interest in holding those standards back. You cannot have a reasonable "discussion" with an entity that claims a regulatory veto.

Certificate Transparency is a great example: it's a reliable way to detect MITM certificates. "Here's an established industry standard for detecting improperly issued certificates and rejecting them to prevent interception of communication, allowing revocation of misused CAs." "So what happens when law enforcement uses a CA to issue a certificate for interception pertaining to a warrant?" "Like we said, it detects improperly issued certificates and rejects them to prevent interception of communications, so we'd detect that and revoke the CA." Further conversation after that point goes very differently depending on whether the governmental entity is empowered to veto or not.

> browser vendors are welcome to participate in ETSI and give their suggestions of allowing certificate transparency

"suggestions"? It's their software; any mechanism that attempts to prevent them from defining their own stronger security standards is broken and should be destroyed via every possible route.

If you want digital sovereignty, make a case for your requirements with the software people want to use. If that case is "we want to reduce security", you should lose; if you don't something is very wrong with the process.

Re: Some observations on the final text of the European Digital Identity framework

#70

Earlier quoted context omitted.

Browsers are allowed to ask permission to remove them if they are compromised. They still have to receive that permission before they can do it.

I believe it is well understood by now that users tend to ignore security warnings; anyone serious about computer security will not accept this as a solution. We don't even apply security-critical patches reliably.

Lately I've found browsers no longer let me click past SSL errors (at least, not without digging deep through the settings panel first).
Post reply on HN