Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

101–110 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#102

eIDAS is a cartel created to protect the business interests of EU biggest certification authorities.

It is a digital certificate standard. Browser certificates is only a tiny part of it, that wasn't why it was made. Having a standard for digital certificates is a good thing, it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#103
post #62

Earlier quoted context omitted.

A key idea behind all of this is to sell "qualified certificates". Which is another way of saying "expensive certificates". In the past, CAs sold EV certificates which gave you a nice green look in the browser bar and no security advantage (arguably security downsides, because you cannot automate it). That was good business, until browsers decided that this makes no sense and scraped any special treatment for EV cert…

>Which is another way of saying "expensive certificates". True, basically eIDAS is a cartel. With the help of EU legislation, some Certification Authorities banded together and are now saying that certificates emited by anyone but them are not good. And obviously they fully controll the pricing for the "good" certificates.

> True, basically eIDAS is a cartel. With the help of EU legislation, some Certification Authorities banded together and are now saying that certificates emited by anyone but them are not good

For very specific needs like electronic signatures, "seals" and an interesting one I hadn't heard before, timestamping (proving that an electronic document has existed at that timestamp), not for general computing.

Also, considering Bulgaria has 5 CAs on the official list, with 2 others as potential, the claims of a shady cartel of "big Cert" being behind this is laughable.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#104

To protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?

TLS 1.3 encrypts server certificate, so it will not be possible to filter such connections out using just passive inspection.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#105

Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.

New Firefox plugin: "Disable EU Certs"

EU court: serves Mozilla a court order to add the extension to the blocklist.xml file, a global blocklist of all extension IDs that users can’t install.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#106

Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.

New Firefox plugin: "Disable EU Certs"

Soon: "Mozilla removes plugin from website and prevents installation for weakening security"

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#107

To protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?

That's illegal then. But the pihole won't do the trick, you need to remove the mandated certs from your browsers certstore. If these certs are used for legitimate places (e.g. EU or state websites, and I'll bet they will) you then will get a certificate error.

Of course there is still HSTS, but that's not supported by all tech using TLS.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#108
post #98

Very concerning. As a slight aside though, it is not a "secret law". All EU laws are published on its website in every official language, and the vast majority of laws (including this one) must be publicly ratified by the directly elected European Parliament before coming effective. They should tone down this kind of sensationalist clickbait that I would expect to find in UK tabloids. They probably think it helps the…

Also, this: > and will be presented to the public and parliament for a rubber stamp before the end of the year That's not how the EU parliament works, they're not just a rubber stamp. The topic is sufficiently grave without the need for clickbait and painfully obvious exaggerations.

https://en.wikipedia.org/wiki/Formal_trilogue_meeting

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#109
Just adding a perspective (not necessarily mine, I'm still on the fence) supporting this legislation from a tech-literate person in the EU.

The digital administration in my country has made my life so much easier. We all have mandatory ID cards since decades ago, but now they have a chip with some certs for auth, signing, etc. I can check my taxes, fill government forms, see any traffic tickets, sign official documents from my home thanks to this. However, as far as I understand, this relies on my user agent accepting some particular CAs. This is critical, to the point of my browser preventing me access to some parts of the administration if the CA is not up to date or recognised or whatever.

What this legislation proposes, if I understand it correctly, is putting in the hands of the government the power to administer (part of) this CA infrastructure. As with many EU-related legislation, this forcefully transfers power from private (often American) entities to EU governments. I guess when trust in your government is higher or equal to trust on private firms, this doesn't sound so bad.

Not saying this is right or wrong, but maybe this helps understand why many people in the EU may not be so against this type of legislation.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#110

Very concerning. As a slight aside though, it is not a "secret law". All EU laws are published on its website in every official language, and the vast majority of laws (including this one) must be publicly ratified by the directly elected European Parliament before coming effective. They should tone down this kind of sensationalist clickbait that I would expect to find in UK tabloids. They probably think it helps the…

"Agreed behind closed doors" would probably be better than "Secret Law" but I guess its a question of brevity.
Post reply on HN