Last Chance to fix eIDAS: Secret EU law threatens Internet security
101–110 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#102eIDAS is a cartel created to protect the business interests of EU biggest certification authorities.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#103Earlier quoted context omitted.
A key idea behind all of this is to sell "qualified certificates". Which is another way of saying "expensive certificates". In the past, CAs sold EV certificates which gave you a nice green look in the browser bar and no security advantage (arguably security downsides, because you cannot automate it). That was good business, until browsers decided that this makes no sense and scraped any special treatment for EV cert…
>Which is another way of saying "expensive certificates". True, basically eIDAS is a cartel. With the help of EU legislation, some Certification Authorities banded together and are now saying that certificates emited by anyone but them are not good. And obviously they fully controll the pricing for the "good" certificates.
For very specific needs like electronic signatures, "seals" and an interesting one I hadn't heard before, timestamping (proving that an electronic document has existed at that timestamp), not for general computing.
Also, considering Bulgaria has 5 CAs on the official list, with 2 others as potential, the claims of a shady cartel of "big Cert" being behind this is laughable.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#104To protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#105Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.
New Firefox plugin: "Disable EU Certs"
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#106Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.
New Firefox plugin: "Disable EU Certs"
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#107To protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?
Of course there is still HSTS, but that's not supported by all tech using TLS.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#108Very concerning. As a slight aside though, it is not a "secret law". All EU laws are published on its website in every official language, and the vast majority of laws (including this one) must be publicly ratified by the directly elected European Parliament before coming effective. They should tone down this kind of sensationalist clickbait that I would expect to find in UK tabloids. They probably think it helps the…
Also, this: > and will be presented to the public and parliament for a rubber stamp before the end of the year That's not how the EU parliament works, they're not just a rubber stamp. The topic is sufficiently grave without the need for clickbait and painfully obvious exaggerations.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#109The digital administration in my country has made my life so much easier. We all have mandatory ID cards since decades ago, but now they have a chip with some certs for auth, signing, etc. I can check my taxes, fill government forms, see any traffic tickets, sign official documents from my home thanks to this. However, as far as I understand, this relies on my user agent accepting some particular CAs. This is critical, to the point of my browser preventing me access to some parts of the administration if the CA is not up to date or recognised or whatever.
What this legislation proposes, if I understand it correctly, is putting in the hands of the government the power to administer (part of) this CA infrastructure. As with many EU-related legislation, this forcefully transfers power from private (often American) entities to EU governments. I guess when trust in your government is higher or equal to trust on private firms, this doesn't sound so bad.
Not saying this is right or wrong, but maybe this helps understand why many people in the EU may not be so against this type of legislation.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#110Very concerning. As a slight aside though, it is not a "secret law". All EU laws are published on its website in every official language, and the vast majority of laws (including this one) must be publicly ratified by the directly elected European Parliament before coming effective. They should tone down this kind of sensationalist clickbait that I would expect to find in UK tabloids. They probably think it helps the…