Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

91–100 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#91
post #25

Earlier quoted context omitted.

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.

And big EU tech successes like GDPR, DMA and many others. What's your point?

This is about identity regulation, not random rockets.

Re: Some observations on the final text of the European Digital Identity framework

#92

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

> One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

Walking through a park in Shanghai, I discovered that the many vending machines throughout the park will let you specify that you want to pay cash.

You can't actually pay cash, though; the slots that would accept it have been physically removed from the machines. The only way to get something out of one of the vending machines is to send the machine an online payment.

Re: Some observations on the final text of the European Digital Identity framework

#93

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

Well, the existing eIDAS stuff already provided for mutual recognition of eIDs between EU member states, i.e. someone with Swedish BankID can use it when interacting with digital services in the whole EU.

I don't know how the new text changes this.

Re: Some observations on the final text of the European Digital Identity framework

#94
post #44

Earlier quoted context omitted.

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…

Conversely, when I cross the border into Denmark from Germany, lots of places accept only a danish payment system, to which you can only sign up with DANISH phone number!

These kind of services simply don’t care about the small percentage of tourists and expats that they exclude.

But I think the social externalities in terms of freedom of movement are significant and not priced in.

I’m not a fan of adding regulation but I think this is one of the places where it’s necessary.

Re: Some observations on the final text of the European Digital Identity framework

#95

Earlier quoted context omitted.

One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.

> One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked. Walking through a park in Shanghai, I discovered that the many vending machines throughout the park will let you specify that you want to pay cash. You can't actually pay cash, though; the slots that would accept it have been physically removed from the machines. The only way to get something out of one of the ve…

We need digital payments that allow indiscriminate access.

Re: Some observations on the final text of the European Digital Identity framework

#96

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

spot-on.

it helps to recall that ETSI, despite being some opaque standards org is made of people[1] like you and me (many not in Europe) who helped draft this abomination of a standard. This is disguised as digital identity but the interest groups are mostly law-enforcement, and the same crowd that is pushing "chatcontrol", and "regulating cryptography".

This "secret list" of experts is here[1].

And here is Tanja Lange's (repeated[2]) warning on this proposal:

>> I'm contacting you @LalicVedran & @JerkovicRomana about eIDEAS - as a cryptographer & concerned citizen. As said in eidas-open-letter.org/ & I presented in detail at the ENISA Article 19 working group it doesn't suit an open society to mandate trust. https://hyperelliptic.org/tanja/vortraege/QWACs.pdf

When Kazachstan[3][4] made people install a certificate in their citizen's browsers we (rightly) called them "Banana Republic". Look who is the Banana Republic now.

[1] Patrick Breyer on Twitter Nov 6th (in German) https://nitter.cz/echo_pbreyer/status/1721558594129219912

[2] Tanja Lange on Twitter Nov 5th https://nitter.cz/hyperelliptic/status/1721215011799142791

[3] Kazakhstan to MitM all HTTPS traffic starting Jan 1 (2015) https://news.ycombinator.com/item?id=10663843

[4] MITM on HTTPS traffic in Kazakhstan (2019) https://news.ycombinator.com/item?id=20472179

Re: Some observations on the final text of the European Digital Identity framework

#97

Earlier quoted context omitted.

At least your Spanish DNIe contains an X.509 certificate you can access via PKCS#11 that Just Works, both for authentication and signature. You can even use it for SSH!

Yeah I wish I could get one as a foreigner. I only get a shitty piece of green paper that doesn't last more than a few months in a wallet. And I have to wait 10 years to change my citizenship over too. Now that the extreme-right party won the Dutch elections last week I'd really like to change it. South Americans can change it over after only 5 years. But not EU citizens strangely.

Didn’t you get an NIE? I had one immediately (so did my whole family), the card wasn’t paper, and it was treated as identical to the Spanish ID. And yes it was super convenient certificates and all. I had to use the certs once and was afraid (due to past experience) but honestly it “just worked”.

Maybe EU citizens don’t get an NIE, though? I’m from further away.

Re: Some observations on the final text of the European Digital Identity framework

#98

Earlier quoted context omitted.

> One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked. Walking through a park in Shanghai, I discovered that the many vending machines throughout the park will let you specify that you want to pay cash. You can't actually pay cash, though; the slots that would accept it have been physically removed from the machines. The only way to get something out of one of the ve…

We need digital payments that allow indiscriminate access.

I'm pretty sure that for the use case where I want to receive a soda, we don't need digital payments at all. There is no need to involve the internet, because whoever gives me the soda must necessarily be in the same location where I am. The only thing wrong with the cash payment model is that someone went to special effort to disallow it.

In other digital-payments-in-China news, I just ordered some milk today from the store that is across the street from me. It's no great hardship for me to cross the street and buy the milk myself. However, the price of a third of a gallon of milk is 32 rmb. (USD $4.50). If I order it delivered, a courier will show up, buy the milk, and walk it up four flights of stairs to hand it over to me, and besides paying no delivery fee, my price per carton of milk falls to 22 rmb.

What really bothers me about this is that the bag came with a big receipt stapled to it showing that the delivery service paid the store 26 rmb per carton of milk. So the service was nice enough to cover the courier's fee for me at the same time that they paid me for everything I ordered through them.

Something somewhere is orchestrating a huge forced push for online payment. The economics clearly do not work on their own.

Re: Some observations on the final text of the European Digital Identity framework

#99
post #86

historically, whatever a government gets involved in usually works out amazingly well. right?

Probably on average actually true (microprocessors and the internet come to mind, creation of "modern" cash back in antiquity, the formal code of law, sanitation, etc.), but with some colossal disasters in there, too.

Re: Some observations on the final text of the European Digital Identity framework

#100
post #58

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

I wonder if this would require browsers to allow government certs in place of their own pinned certs (e.g., chrome pins certs for google sites and maybe others I believe, if a non matching cert is used then the connection is rejected).

Well sort of, it allows government to create a falsified certificate for other sites like Google sites (man in the middle attack). When the browser forum/certificate authority wise up to it's use, they've then got to prove it's causing harm and get approval from authorities to remove it (authorities can take their sweet time responding to the request).
Post reply on HN