Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

141–150 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#141
post #72
post #32

Earlier quoted context omitted.

The thing is that you can currently choose which org to give that power, and at least so far, those orgs have acted in line with wanting you to choose them (i.e. on your behalf).

Can you though? The loose consensus model means there's little accountability and no practical way to opt out of listening to a particular entity that you don't trust. There are tales of essentially "someone with an @google.com email" being able to tell a CA to stop issuing certificates to particular undesirables, and the CA complying.

You can, to a limited extent. If e.g. Google were to start censoring news.ycombinator.com by blocklisting its CAs, I could switch browsers to view it anyway. (Or vice versa, if there's a big security issue and one browser (who still trusts the relevant CAs) was vulnerable and another one was not, I might then consider switching browsers.)

Re: Some observations on the final text of the European Digital Identity framework

#142
post #140

Earlier quoted context omitted.

They can install an open-source OS/browser and ignore Microsoft, Google, and Apple. There is nothing they can realistically do when they don't trust a government. Governments ultimately derive their power from their ability to impose their will by violence. That makes them inherently less accountable than organizations that you are free to ignore.

Someone who doesn't trust a government can move countries, particularly in the EU. I'd argue that it's actually easier to avoid a given EU government than to use an OS/browser combination that's not controlled by US entities.

That's frankly ridiculous. Moving countries is expensive, and there are a limited number of countries in the EU and the world. If you can't afford to move or don't trust any of them, you are out of luck.

Installing an open-source OS and browser is free and the options are practically unlimited as anyone is free to create a new alternative.

Re: Some observations on the final text of the European Digital Identity framework

#143
post #141
post #72

Earlier quoted context omitted.

Can you though? The loose consensus model means there's little accountability and no practical way to opt out of listening to a particular entity that you don't trust. There are tales of essentially "someone with an @google.com email" being able to tell a CA to stop issuing certificates to particular undesirables, and the CA complying.

You can, to a limited extent. If e.g. Google were to start censoring news.ycombinator.com by blocklisting its CAs, I could switch browsers to view it anyway. (Or vice versa, if there's a big security issue and one browser (who still trusts the relevant CAs) was vulnerable and another one was not, I might then consider switching browsers.)

> If e.g. Google were to start censoring news.ycombinator.com by blocklisting its CAs, I could switch browsers to view it anyway.

You could if it got to that point, but the CA would almost certainly "voluntarily" stop issuing certificates to news.ycombinator.com rather than face the risk of being blocklisted, and there's no way for you to opt out of that.

Re: Some observations on the final text of the European Digital Identity framework

#144
post #140

Earlier quoted context omitted.

Someone who doesn't trust a government can move countries, particularly in the EU. I'd argue that it's actually easier to avoid a given EU government than to use an OS/browser combination that's not controlled by US entities.

That's frankly ridiculous. Moving countries is expensive, and there are a limited number of countries in the EU and the world. If you can't afford to move or don't trust any of them, you are out of luck. Installing an open-source OS and browser is free and the options are practically unlimited as anyone is free to create a new alternative.

> Installing an open-source OS and browser is free and the options are practically unlimited

There's what, two and a half real options? Even open-source applications wilfully cut off any non-mainstream OS (see the whole systemd saga). "Anyone is free to create a new browser", sure, but in practice it's now so expensive that even Microsoft had to give up. I've absolutely got more practical choices of country.

Re: Some observations on the final text of the European Digital Identity framework

#145
post #144

Earlier quoted context omitted.

That's frankly ridiculous. Moving countries is expensive, and there are a limited number of countries in the EU and the world. If you can't afford to move or don't trust any of them, you are out of luck. Installing an open-source OS and browser is free and the options are practically unlimited as anyone is free to create a new alternative.

> Installing an open-source OS and browser is free and the options are practically unlimited There's what, two and a half real options? Even open-source applications wilfully cut off any non-mainstream OS (see the whole systemd saga). "Anyone is free to create a new browser", sure, but in practice it's now so expensive that even Microsoft had to give up. I've absolutely got more practical choices of country.

I have no idea what you are talking about. There are literally infinite alternatives because you can freely modify any open-source alternative in infinite ways.

No one is going to kick down your door and shoot you if you try to make a new browser or OS from scratch, like they would if you tried to make a new government, but there is really no reason to make a browser from scratch.

Microsoft didn't need to trust Google to fork Chromium, they didn't give up any power to Google and have exactly the same ability to influence web standards as if they had reinvented the browser. If they disagree with a choice the Chromium developers made, they can change it and keep the rest. The same applies to anyone who wants to do the same.

When it comes to certificate authorities, you don't even need to modify the browser or OS because they already allow you to add and remove authorities. The main reason people don't tend to do that is because they have no reason to. If you tried to start a new one, the natural thing to ask would be why I should trust you over the established certificate authorities. If your answer is that I don't have a choice because you have the backing of an army and police force that you will use against me if I don't, it doesn't exactly fill me with confidence.

The current certificate authorities don't need to threaten anyone with violence to secure their position, and they operate with significantly more transparency than any government I know of. Compared to governments, they are also much safer to trust because they rely on consent rather than force. A compromised or malicious certificate authority won't shoot you for trying to replace it, it has no enforcement mechanism beyond inertia.

Re: Some observations on the final text of the European Digital Identity framework

#146

Earlier quoted context omitted.

A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.

What's your concern with Galileo? Many experts consider it to be the best GNSS currently available:[1] > The US constellation isn’t as accurate as the newer networks, said Roberts, the Sydney-based professor. “It used to be GPS was out in front,” he said. Now, though, the EU’s Galileo is in the lead, with China’s BeiDou close behind, he said. [1] https://www.bloomberg.com/news/articles/2023-09-20/russia-s-...

Thanks for backing up your point with a link. I agree that Galileo is more accurate than the much older GPS system. On the other hand, the GPS system became fully operational in 1995 as far as I understand, and the Galileo system is yet to be fully operational almost a decade after the original target date.

Re: Some observations on the final text of the European Digital Identity framework

#147
post #143
post #141

Earlier quoted context omitted.

You can, to a limited extent. If e.g. Google were to start censoring news.ycombinator.com by blocklisting its CAs, I could switch browsers to view it anyway. (Or vice versa, if there's a big security issue and one browser (who still trusts the relevant CAs) was vulnerable and another one was not, I might then consider switching browsers.)

> If e.g. Google were to start censoring news.ycombinator.com by blocklisting its CAs, I could switch browsers to view it anyway. You could if it got to that point , but the CA would almost certainly "voluntarily" stop issuing certificates to news.ycombinator.com rather than face the risk of being blocklisted, and there's no way for you to opt out of that.

Hmm yeah that's a good point, not much you can do about that as a user.

Re: Some observations on the final text of the European Digital Identity framework

#148
post #144

Earlier quoted context omitted.

> Installing an open-source OS and browser is free and the options are practically unlimited There's what, two and a half real options? Even open-source applications wilfully cut off any non-mainstream OS (see the whole systemd saga). "Anyone is free to create a new browser", sure, but in practice it's now so expensive that even Microsoft had to give up. I've absolutely got more practical choices of country.

I have no idea what you are talking about. There are literally infinite alternatives because you can freely modify any open-source alternative in infinite ways. No one is going to kick down your door and shoot you if you try to make a new browser or OS from scratch, like they would if you tried to make a new government, but there is really no reason to make a browser from scratch. Microsoft didn't need to trust Googl…

> When it comes to certificate authorities, you don't even need to modify the browser or OS because they already allow you to add and remove authorities. The main reason people don't tend to do that is because they have no reason to.

They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFlare (who are pretty low on my list of entities I want to trust) instead. Now that browsers have mostly succeeded in forcing HTTPS everywhere, expect them to start turning the screws.

> The current certificate authorities don't need to threaten anyone with violence to secure their position, and they operate with significantly more transparency than any government I know of.

Really? Can I make a FoI request to find out why a CA refused to issue a certificate to a particular entity? Is there a right of appeal if they refuse to issue a certificate on discriminatory grounds?

Re: Some observations on the final text of the European Digital Identity framework

#149
post #148

Earlier quoted context omitted.

I have no idea what you are talking about. There are literally infinite alternatives because you can freely modify any open-source alternative in infinite ways. No one is going to kick down your door and shoot you if you try to make a new browser or OS from scratch, like they would if you tried to make a new government, but there is really no reason to make a browser from scratch. Microsoft didn't need to trust Googl…

> When it comes to certificate authorities, you don't even need to modify the browser or OS because they already allow you to add and remove authorities. The main reason people don't tend to do that is because they have no reason to. They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFla…

> They're already starting to make it more difficult. Look at what's happening with DoH where it's harder and harder to choose how your DNS queries get done and you get steered to CloudFlare (who are pretty low on my list of entities I want to trust) instead. Now that browsers have mostly succeeded in forcing HTTPS everywhere, expect them to start turning the screws.

DoH doesn't interfere with your ability to choose your own DNS provider. It only means that your DNS queries are between you and your DNS provider, free from the interference of your ISP and other third parties. It provides greater user freedom because your ISP cannot as easily force you to use their DNS provider. Nothing stops ISPs from offering DoH and some (e.g. Comcast) do offer it. Users may however benefit from using a DNS that's not affiliated with their ISP because ISPs are more vulnerable to censorship demands from governments. Usually, when a government demands that an ISP censor a website, the ISP will simply block DNS queries regarding that domain, allowing users of other DNS providers to escape the censorship. This may of course not be a long-term solution, as governments may be more likely to demand different censorship methods if fewer use the IPS DNS.

As far as I'm aware, no one has suggested that DoH should be mandatory. It is a sensible default that improves the privacy and security of most users, but a user who decides that they do not want to use DoH can simply opt out in the settings. Likewise, HTTPS is not mandatory either, and browsers will not prevent users from accessing unsecure sites. They will however warn users to make sure they are aware of the risks. As far as I'm aware, browser vendors do not benefit from users using HTTPS everywhere. They encourage its use because it is generally beneficial to users.

> Really? Can I make a FoI request to find out why a CA refused to issue a certificate to a particular entity? Is there a right of appeal if they refuse to issue a certificate on discriminatory grounds?

A FoI request is just asking the government to give you information. They will never intentionally give you anything they do not want you to have. FoI laws tend to contain enough exceptions to cover any situation, but even if you should legally receive the information, there is nothing you can realistically do to make them provide it to you. Similarly, you can ask any organization for any information, and they can refuse. The same is true with appeals. You can ask an organization to reconsider its decision and for someone else in the organization to look at it, but the decision remains within the organization. The difference is what you can do once the decision has been finally made. Will the decision maker try to force me to adhere to their decision through violent means, or am I free to ignore them and try to convince others to do the same?

The main difference regarding transparency is that more information is made public by default in the current system (what good is the ability to request information if you don't even know that the thing you wanted to request information about happened?) and that decisions are made by several separate entities that need to justify their decisions to each other in order to maintain consensus.

Re: Some observations on the final text of the European Digital Identity framework

#150

Earlier quoted context omitted.

Yeah I wish I could get one as a foreigner. I only get a shitty piece of green paper that doesn't last more than a few months in a wallet. And I have to wait 10 years to change my citizenship over too. Now that the extreme-right party won the Dutch elections last week I'd really like to change it. South Americans can change it over after only 5 years. But not EU citizens strangely.

Didn’t you get an NIE? I had one immediately (so did my whole family), the card wasn’t paper, and it was treated as identical to the Spanish ID. And yes it was super convenient certificates and all. I had to use the certs once and was afraid (due to past experience) but honestly it “just worked”. Maybe EU citizens don’t get an NIE, though? I’m from further away.

you get the certificate from FNMT, it's not related to EU or non EU AFAIK
Post reply on HN