Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

101–110 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#101

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

Here in Switzerland we have SwissID and it's absolutely terrible.

It doesn't run on my phone because it's supposedly "rooted". I have a new Pixel phone with AOSP and the boot loader unlocked. The app behaves like malware or spyware because they make assumptions about end user devices.

Then they only support SMS based 2FA, none of the standards like TOTP or HOTP.

There is this weird sense of superiority or superior quality with the "Made in Switzerland" label. It may be true for a watch, but it's far from true when it comes to software and technology otherwise. Everything is mostly trash.

Re: Some observations on the final text of the European Digital Identity framework

#102
post #73

Earlier quoted context omitted.

I frequently travel to the EU and the amount of cookie banners is decidedly higher.

I also notice German sites constantly nag you, Dutch seems to be a little less obnoxious. What's also interesting is that Germany, sticklers if I've ever seen any, is full of nonconsentual walls where you "of your free will with no negative consequences to deny" have to click "consent" or become a paid subscriber. If the data protection authority or the law is to be believed, that's not freely given consent Quite hil…

By my understanding of words, even the best 10% of cookie popups are mostly not really "freely given consent".

But I know I'm not a lawyer, and my lack of understanding of the technical jargon in law is likely to be similar to the lack of understanding of technical web jargon in the old screenshot of someone looking at the JS console by accident and thinking it was a secret police thingie: https://images.app.goo.gl/4SPUwbQ1uY2r5oHcA

Re: Some observations on the final text of the European Digital Identity framework

#103
post #25

Earlier quoted context omitted.

> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.

A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.

What's your concern with Galileo? Many experts consider it to be the best GNSS currently available:[1]

> The US constellation isn’t as accurate as the newer networks, said Roberts, the Sydney-based professor. “It used to be GPS was out in front,” he said. Now, though, the EU’s Galileo is in the lead, with China’s BeiDou close behind, he said.

[1] https://www.bloomberg.com/news/articles/2023-09-20/russia-s-...

Re: Some observations on the final text of the European Digital Identity framework

#104

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

[flagged]

Re: Some observations on the final text of the European Digital Identity framework

#105

So here's a scenario I haven't seen brought up yet. Elbonian hackers manage to steal the singing key of kneebonia who is part of the EU (and also does IT as well as you would expect a European national government to do) They start publishing a ton of their own certs and start MITM everything out the wazoo. In the current environment this is noted by the community quickly they respond and revoke the Kneebonian cert, t…

Your case is exactly the same as some entity stealing the ability to issue passports for a country. Insinuating that people issuing national identifications don't understand the issue of forging said documents is some ridiculous techbro arrogance. We've been dealing with this shit for centuries and those "beaurocrats" you're insulting have probably gone through more more cases of fraud and forgery than you ever thought about in your life.

Re: Some observations on the final text of the European Digital Identity framework

#106

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

BankID has been a security nightmare with a lot of fraud. It's relatively easy to get a BankID in someone else's name, which then allows the fraudsters to do anything in your name, including stealing everything you have.[1]

This is a great example of when privatization is a bad idea. Fraud is clearly a loss for the society, but the banks couldn't care less. A more secure solution would cost more for them, and it's someone else who has to carry the burden.

Fortunately, BankID doesn't fulfill the EU's security requirements, so Sweden finally has to make a proper eID, despite the bank-friendly politicians (Sweden is very "pro-business") not wanting to.[2]

[1] https://www.svt.se/nyheter/lokalt/uppsala/filippa-lurades-av...

[2] https://www.sweclockers.com/nyhet/37412-statlig-e-legitimati...

Re: Some observations on the final text of the European Digital Identity framework

#107
post #71

Earlier quoted context omitted.

> eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats. The flipside is that while it may be a "voluntary consortium", all major browsers are developed by entities based in the US, that are therefore subject to Nation…

> all major browsers are developed by entities based in the US, that are therefore subject to National Security Letters Those browsers are Open Source. (Well, Firefox is, and Chrome's core is even though Chrome isn't). If they tried to ship a MITM-enabling mechanism it'd be obvious. > I mean sure, you have to accept the government of Greece's certificate because they're the legitimate authority They're not the author…

> If they tried to ship a MITM-enabling mechanism it'd be obvious.

A straight up blocklist wouldn't be though. Just treat it like a CRL entry or something.

> They're not the authority for arbitrary domains on the Internet, no.

Agreed. But they're the authority for Greek domains. If anything, it's letting some other entity issue certificates for those that's strange.

Re: Some observations on the final text of the European Digital Identity framework

#108

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

BankID has been a security nightmare with a lot of fraud. It's relatively easy to get a BankID in someone else's name, which then allows the fraudsters to do anything in your name, including stealing everything you have.[1] This is a great example of when privatization is a bad idea. Fraud is clearly a loss for the society, but the banks couldn't care less. A more secure solution would cost more for them, and it's so…

But the scam described in the first link is not much different than what is plaguing Microsoft Authenticator in phishing mails. Sending a QR code and getting someone to scan it to steal OTP access.

It's still much better than anything we had before, and it is after all 20 years old. So I can see that there is room for improvement.

So what is a better eID implementation? Freja?

Re: Some observations on the final text of the European Digital Identity framework

#109
post #104

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

[flagged]

This is an interesting point of view. This also pertains to root certificates in browsers however. Would a better way be not to setup a body to monitor certificates issued to police certificates for their own CA and ensure any offending certificate is immediately removed and to bring in laws to penalise the offending CA.

Instead they're prying a new threat vector open wide.

Re: Some observations on the final text of the European Digital Identity framework

#110

Earlier quoted context omitted.

The problem seems to be "wrong domain", not "CA not recognized". You sure you have the right URL?

i'm mobile. probably got the wrong url. only have bookmarks for the ca certs https://www.gov.br/iti/pt-br/assuntos/repositorio/repositori...

But what do you need these certs for, is there a national website that gets an "insecure" warning if you visit it with a foreign version of Firefox?
Post reply on HN