However this amendment is disgusting.
I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break security on the web.
11–20 of 67 posts
However this amendment is disgusting.
I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break security on the web.
I also hope that our community produces tools to allow the cert stack on our OSes to be purged of these certificates.
Wow. Does the EU intend on basically killing their economies? Online commerce is a huge deal and would be heavily impacted if people didn't trust their connections.
If this goes through without change the browser vendors should implement an UX which allows the user to disable these root certificates; ideally within different contexts. I also hope that our community produces tools to allow the cert stack on our OSes to be purged of these certificates.
EDIT: for clarification, they banned disclosing it in initial communications like emails. They can do same for browsers. Apple also successfully banned apps from disclosing links to buying stuff online etc.
Wow. Does the EU intend on basically killing their economies? Online commerce is a huge deal and would be heavily impacted if people didn't trust their connections.
Wow. Does the EU intend on basically killing their economies? Online commerce is a huge deal and would be heavily impacted if people didn't trust their connections.
Why would people worry? We already have mobile phones, televisions, cars, etc., continuously monitoring and sending private information about ourselves and our relatives to external parties that we may don't even know about. This -if comes to be true- would just mean that more parties could have access to our data. But who cares once we are already giving it for free?
Next they will ban other certs other than their own. Like Dubai did or Monaco.
https://community.qbix.com/t/the-coming-war-on-end-to-end-en...
Does this mean they would essentially be able to MITM attack all traffic?
https://security.stackexchange.com/questions/189647/what-hap...
I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…