Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

11–20 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#11
post #9
post #8

There is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security. For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a ris…

If "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked. This is still very bad.

> This is still very bad.

Yes, potentially, but it isn't "another kind of chat control".

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#12
post #9
post #8

There is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security. For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a ris…

If "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked. This is still very bad.

Wouldn't a client certificate from e2echat protect that kind of attack ? Since even when a man in the middle offers u a server cert u accept, the e2echat servers can't validate the client certificate from you anymore

(Still bad but would at least protect connections from ever talking to e2echats servers)

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#13
post #8

There is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security. For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a ris…

Oh yeah if encryption is broken only for browsers no big deal right

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#14
post #11
post #9

Earlier quoted context omitted.

If "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked. This is still very bad.

> This is still very bad. Yes, potentially, but it isn't "another kind of chat control".

It's another side of the efforts of going around encryption, chat controls deals with communication services, this one with browsers

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#16
post #13
post #8

There is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security. For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a ris…

Oh yeah if encryption is broken only for browsers no big deal right

Governments still can't see your requests to servers under normal circumstances with this law.

The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at "e2e.com" when you are on another site, and in those cases the only difference from now is that your browser will display "secure" instead of "invalid cert". There is no other difference.

So to orchestrate an attack they would need to build an webbapp that is sufficient similar for you not to notice, take over your internet connection and break the certification process.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#17
If certificates issued by those CAs will be tied to independent (from EU) certificate transparency (CT) services and to specific national top-level domains, then I am completely fine with this. After a big number of websites in Russia (including the biggest bank in the country) have effectively lost access to the CA infrastructure used by commonly used browsers, I don't think any honest person can say that the current status quo is robust enough. So it looks like EU simply hedges against this potential infrastructure risk.

To mitigate the MitM risk I believe that CT and limiting CA to specific top-level domains (so a hypothetical RU CA would not be able to issue certificates for .eu or .com) should be sufficient enough.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#18
post #11
post #9

Earlier quoted context omitted.

If "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked. This is still very bad.

> This is still very bad. Yes, potentially, but it isn't "another kind of chat control".

Yes, I agree. The crying wolf is too much sometimes.

Accepting certificates from a given issuer does not give them the issuer the right to impersonate others

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#19
So what happens to open source browsers? Will they be forced to implement it? Are the governments going to audit the code to make sure no one is releasing a version that has removed the government certs or are they going to outlaw open source browsers?

Again, this is not going to catch anyone with half a braincell that is trying to do something. This is just going to catch everyone else.

I wonder if this will tie into the BS that Google was trying to implement that would make it impossible to modify the webpage using adblockers etc. making it so you can't navigate the web if you are using a uncertified browser.

Post reply on HN