Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

71–80 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#71

> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats.

The flipside is that while it may be a "voluntary consortium", all major browsers are developed by entities based in the US, that are therefore subject to National Security Letters etc. (and, more insidiously, US social pressure). When the next Snowden-style revelation comes out, what's to stop the US security apparatus from blocking sites associated with it? So yeah, I see more upside than downside in my browser having at least some accountability to the EU.

> All those existing government CAs are currently audited by CA/B. If Greece gets caught misissuing certificates they can have their CA roots revoked by the browser vendors. The concern is that under eIDAS, the EU could just not revoke the certificate, and the browser vendors' hands would be tied. They'd be forced to accept known bad CAs and every cert they sign, including the spyware ones.

I mean sure, you have to accept the government of Greece's certificate because they're the legitimate authority, just like you can't refuse to accept a Greek passport because you think it looks dodgy or you've never heard of Greece. If their government is issuing bad certificates, normal government accountability mechanisms apply, just like with countries that are known to sell citizenships to the wealthy. Again that seems right and proper.

Re: Some observations on the final text of the European Digital Identity framework

#72
post #32
post #25

Earlier quoted context omitted.

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

The thing is that you can currently choose which org to give that power, and at least so far, those orgs have acted in line with wanting you to choose them (i.e. on your behalf).

Can you though? The loose consensus model means there's little accountability and no practical way to opt out of listening to a particular entity that you don't trust. There are tales of essentially "someone with an @google.com email" being able to tell a CA to stop issuing certificates to particular undesirables, and the CA complying.

Re: Some observations on the final text of the European Digital Identity framework

#73
post #22

Earlier quoted context omitted.

>Cookie banners happened because US devs didn't steelman EU regs. EU sites have the same amount of cookie banners as US ones. (ie, all major sites have one)

I frequently travel to the EU and the amount of cookie banners is decidedly higher.

I also notice German sites constantly nag you, Dutch seems to be a little less obnoxious. What's also interesting is that Germany, sticklers if I've ever seen any, is full of nonconsentual walls where you "of your free will with no negative consequences to deny" have to click "consent" or become a paid subscriber. If the data protection authority or the law is to be believed, that's not freely given consent

Quite hilarious are the sites that outright block European IP addresses, as if that way they don't have to bother with the basic human right to privacy (article 8 ECHR). More sites should do this if they have no wish to play by these morals instead of having (legal or illegal) walls!

Re: Some observations on the final text of the European Digital Identity framework

#74
post #60

Earlier quoted context omitted.

Can confirm. I just renewed my Spanish DNIe last summer and not only was the whole process super smooth and took only a few minutes, but the certificate works on Linux out of the box! DNIe was crap for many years, but credit where credit is due, it has improved a lot . On the other hand I also have the Japanese digital ID card (マイナンバーカード), and what a piece of crap. If you ever hear that Japan is the most technologica…

Japan was miles ahead in the early 2000s but as some say, being ahead can also be a burden. And as a deeply traditional society they tend to cling to things that work. I heard that even faxes are still used there. In Austria too by the way but that's more because of an obscure legal status thing.

That's not a consequence of being ahead, it's a consequence of enough time passing if you do it at all.

The more centralized a system is, the more it ossifies. The more people there are to get used to the status quo and incur large costs if anything changes, the more change gets fought. Third parties get their hooks into it, benefit from the status quo and put substantial resources behind preventing changes that are unambiguously improvements -- "institutions will try to preserve the problem to which they are the solution."

The only way to avoid it is to never build it to begin with. Or tear it down as soon as possible if you're too late to stop it from existing but not too late to have everyone fighting to preserve their rents if you try to get rid of it.

Re: Some observations on the final text of the European Digital Identity framework

#75

Earlier quoted context omitted.

A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.

On the other hand, the technocrats are beholden to actual elected officials, instead of the current situation where a group of random people selected by private companies coordinate their work by consensus without much formal structure and the members are beholden to nobody by their company boss.

Rule by consensus is basically democracy by whoever is motivated enough to show up. It seems to have an extremely good track record, especially compared with rule by central bureaucracy.

The exception is if the consensus is only among a small handful of large corporations that lack competition and then become the unaccountable technocrats. But in that case what you want from governments is not to take over as the malevolent bureaucracy, it's antitrust enforcement.

Re: Some observations on the final text of the European Digital Identity framework

#76
post #54
post #34

Earlier quoted context omitted.

The proposed certificate authorities can generate certificates for any entity, not just EU sites and not just new ones. They would have to be treated as valid, per the regulation. Trust is the critical component in the PKI infrastructure. When it’s subverted and you can’t just remove the offending authorities, then it’s not really working properly anymore.

Seems like moving to something like DANE would be a good way forward. Seems like having the site owners tell the public what cert should be expected via DNS with appropriate signatures would obviate the need for CAs. (Yes I realize that this just moves the trust anchor to the DNS root authority, but it does reduce the number of authorities you need to trust).

Lots of things would help protect against this, but this regulation purports to prevent the browser vendor from implementing any stronger security mechanisms than those specified by the regulation. If DANE prevented a certificate from one of these governmental CAs from being accepted, this regulation would try to prevent using DANE.

Re: Some observations on the final text of the European Digital Identity framework

#77

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

That's an argument to expand the system, no?

Re: Some observations on the final text of the European Digital Identity framework

#78

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

I don't want my bank to be an ID provider. I don't trust any bank, the problem is I just can't do without them in this world. But I have no doubt their goals are opposite to my own. They datamine and exploit us. In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.

There are now non-bank alternatives with similar coverage. Freja is likely the most established provider.

Re: Some observations on the final text of the European Digital Identity framework

#79
post #71

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats. The flipside is that while it may be a "voluntary consortium", all major browsers are developed by entities based in the US, that are therefore subject to Nation…

> all major browsers are developed by entities based in the US, that are therefore subject to National Security Letters

Those browsers are Open Source. (Well, Firefox is, and Chrome's core is even though Chrome isn't). If they tried to ship a MITM-enabling mechanism it'd be obvious.

> I mean sure, you have to accept the government of Greece's certificate because they're the legitimate authority

They're not the authority for arbitrary domains on the Internet, no. Only domains that have requested a certificate through that CA. This is what Certificate Transparency is for. If a Certificate Transparency log shows a CA (governmental or otherwise) issuing a certificate for somecompany.example, and the entity controlling somecompany.example didn't request that certificate, that CA has some explaining to do, and if the answer isn't "here's exactly what happened and how we'll make sure it can never happen again", the likely outcome is that browsers will stop trusting that CA.

The point of CT is that you can't silently issue MITM certificates without permanently burning an entire CA to do it.

Re: Some observations on the final text of the European Digital Identity framework

#80

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

BankID is mostly snakeoil. It's not really much more than TOTP 2fa, where you have to have shown physical ID to some of the involved organizations at some point. All the stuff they do with keys is pointless in the end, and is just theatrics to make it sound safe. The providers holds all the keys, you cannot verify that a signature is legit yourself, you wont get access to the keys they use to sign things, and a crypt…

I don't think anyone assumes it's any different than what you describe: centralised, official server than let users authenticate.

You might have wanted something else, but it's never been presented as a decentralised or open solution.

Post reply on HN