Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

81–90 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#81

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

I don't want my bank to be an ID provider. I don't trust any bank, the problem is I just can't do without them in this world. But I have no doubt their goals are opposite to my own. They datamine and exploit us. In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.

[deleted]

Re: Some observations on the final text of the European Digital Identity framework

#82

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

I don't want my bank to be an ID provider. I don't trust any bank, the problem is I just can't do without them in this world. But I have no doubt their goals are opposite to my own. They datamine and exploit us. In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.

Fuck iDIN. Who even fame up with that? Why bring banks into the mix? We've had DigiD for what, also almost 20 years now? Why replace something that works well? iDIN doesn't even fix the main problem, which is being usable in other EU countries.

Banks have enough data already, plus, why make a group of business arbiters of ones online identity?

Re: Some observations on the final text of the European Digital Identity framework

#83
So here's a scenario I haven't seen brought up yet.

Elbonian hackers manage to steal the singing key of kneebonia who is part of the EU (and also does IT as well as you would expect a European national government to do) They start publishing a ton of their own certs and start MITM everything out the wazoo.

In the current environment this is noted by the community quickly they respond and revoke the Kneebonian cert, they understand what is happening, they understand why it is happening, they understand why it is bad and they have a vested interest in stopping it.

Compare under the EU rules. The browser vendors cannot now revoke the cert of their own violation without risking significant penalties. They start the process of trying to get it revoked. The individuals involved are largely beauracrats and civil servants the likes of Sir Humphrey. They do not understand the technical jargon they just know the nerds are getting upset. They'll work on discussing the proposed change by evaluating a written request in the Orwellian named "Committee for Public Internet Safety and Electronic Information Security and Cyber protection" this committee meets 3 times a year on March 31st, October 16th and February 29th. In the meantime the entire underlying security model of the internet is broken.

Now some might say "well if it's an emergency they'll respond immediately there will be public outcry and people's lives being ruined." And if it becomes a big deal the EU will act promptly, they will create a taskforce immediately whose job will be to create a recommendation for individuals to serve in a committee to investigate the source of the problem and create a list of possible remediations that could resolve the problem, which it will then present to the parent committee who will draft a response..... Etc etc ad infenitum until everyone involved with the matter has died of old age, and if you think I'm exaggerating when has EU done anything quickly?

Re: Some observations on the final text of the European Digital Identity framework

#84

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

I don't want my bank to be an ID provider. I don't trust any bank, the problem is I just can't do without them in this world. But I have no doubt their goals are opposite to my own. They datamine and exploit us. In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.

In my country you can login to your government services using a bank account (the easy way) and by creating a proper account with password and everything (the hard way). Or with a proper smart card if you really need it.

Re: Some observations on the final text of the European Digital Identity framework

#85
post #82

Earlier quoted context omitted.

I don't want my bank to be an ID provider. I don't trust any bank, the problem is I just can't do without them in this world. But I have no doubt their goals are opposite to my own. They datamine and exploit us. In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.

Fuck iDIN. Who even fame up with that? Why bring banks into the mix? We've had DigiD for what, also almost 20 years now? Why replace something that works well? iDIN doesn't even fix the main problem, which is being usable in other EU countries. Banks have enough data already, plus, why make a group of business arbiters of ones online identity?

> Fuck iDIN.

100% agreed :)

> Who even fame up with that?

Guess who.. The banks did.

> Why bring banks into the mix? We've had DigiD for what, also almost 20 years now? Why replace something that works well? iDIN doesn't even fix the main problem, which is being usable in other EU countries.

It fixes the main problem for the banks which is that they were not involved. With iDIN they add another "selling point" for themselves, can sit at the table with government services as a provider and can monitor our behaviour more deeply.

It makes no sense as DigiD has worked OK (as a Dutch person living abroad it's certainly not perfect, especially the SMS 2FA option requirement for a Dutch number is super annoying, and the process of requesting access is a real PITA). At least there's an app now.

> Banks have enough data already, plus, why make a group of business arbiters of ones online identity?

It's a bad idea all around but the VVD government embraced it because they love business participation in everything.

Re: Some observations on the final text of the European Digital Identity framework

#87
post #34
post #28

Earlier quoted context omitted.

I think they are just certs to identify yourself to EU or national insititutions for procedures (filling taxes and so), like the certs some European countries issue.

The proposed certificate authorities can generate certificates for any entity, not just EU sites and not just new ones. They would have to be treated as valid, per the regulation. Trust is the critical component in the PKI infrastructure. When it’s subverted and you can’t just remove the offending authorities, then it’s not really working properly anymore.

Yes, that looks like to be the idea, to keep an option for a man in the middle attack.

Re: Some observations on the final text of the European Digital Identity framework

#88
post #77

Earlier quoted context omitted.

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

That's an argument to expand the system, no?

An argument to standardize it , yes.

One of the occiasions where a bit of EU regulation wouldn’t hurt.

Re: Some observations on the final text of the European Digital Identity framework

#89
post #78

Earlier quoted context omitted.

I don't want my bank to be an ID provider. I don't trust any bank, the problem is I just can't do without them in this world. But I have no doubt their goals are opposite to my own. They datamine and exploit us. In Holland the banks are trying to introduce their own id system too, called iDIN. But luckily the state system Digi-ID is still available too.

There are now non-bank alternatives with similar coverage. Freja is likely the most established provider.

Freja is an interesting topic for sweden. In many ways it is superior. It require either an passport or police issued id card, which it connects to using the embedded chip. It also seem to do manual checks by a human that look at the photo (taken by the app using the phone camera) and compares it to the id card. Bank id in comparison allows anyone who can log into the bank account.

That said, people do not like the wait for the manual check, and the app itself seem to get a lot of hate.

Re: Some observations on the final text of the European Digital Identity framework

#90
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

Tracking cookies. It's always been about tracking cookies, you liar.
Post reply on HN