Live data from Hacker News

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

theregister.com

11–20 of 73 posts

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#11
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

If you have nothing to hide, right...

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#12
post #5

Government turned Hacker, what a beautiful future!

This future is just O.K. because in the age of digital weapons what else is supposed for governments to be? The problem is that HTTPS is too government-addicted thing while a decent anti-MITM feature might/should be just a Diffie-Hellman without any identity-preserving features, I mean just E2EE. At least for sites like HN (not banks).

Duffie-Hellman can be MITMed if nothing checks that the value you get from the other party actually comes from the intended other party. I.e., an identity check.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#13
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

I think many EU citizens have a distrust in other EU governments than their own, and this sounds like it would allow all EU governments to intercept all EU citizens.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#14
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

You can't be serious. If this gets implemented, trust in the EU will be greatly reduced. And maybe I do trust the EU, but not each individual country that will implement this this?

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#16
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

Eh, I'm an EU citizen and the whole NSA surveillance program cooperation shows that my government (Denmark) can't be trusted when it comes to surveillance capabilities.

Also I certainly don't trust Hungary under their current government even if I trusted my own government.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#17
post #4

This is insane, and we should hurry up and prepare the technical ways to ensure we know it if we are served a different cert than everybody else. There's ongoing work on this field, but it is now a priority to have it ready.

It exists and works already: Certificate Transparency logs, HSTS and Cert Pinning are “protecting”.

The first may have the side-effect (or intended ?) to inform US companies which websites you are visiting upon addition of new entries though…

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#18

>This enables the government of any EU member state to issue website certificates for interception and surveillance Wouldn't this be very easy to identify?

The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the help of ISPs etc).

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#19
The current internet is essentially so secure, it doesn't need or have a properly walled-off of underground of people who value secure communications. In the west few people outside actual criminals practice it strictly.

> EFF warns incoming rules may return web 'to the dark ages of 2011'

I don't want this law to pass, but I have fond memories of some of the communities that existed back then. If it passes, I at the very least hope like-minded people find a reason to congregate and practice fuckery again.

Obviously (for now) this law is easy to "opt out of" as a user - just download your browser from a mirror outside the EU, or remove the EU certs manually on your end. It's also a dumb law because it makes traffic interception trivially detectable by the end user - the EU is telling you that they're going to use these root certs for it! If they think nobody is going to modify their browser to POST not-safe-for-life imagery whenever such a cert is detected, they're probably wrong.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#20
post #8
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

>innate distrust in their government, something most EU citizens don't have Was that a joke?

It must be sarcasm.

In reality, people don’t have the time to read up on these issues to build an opinion in the first place. The most potent media corporations that could’ve amplified this issue for the general public are effectively propaganda machines for whoever pays the most or has the biggest guns to their heads.

It’s a sad state of affairs. Most of the public are unaware that a cage is being built around them.

But those who do have some understanding about these threats, they certainly are increasingly more distrustful.

Post reply on HN