Earlier quoted context omitted.
It would be impossible for them to force me to blindly accept a government issued ID card as true, and it would be insane for me to comply with such a demand. The same is true here, I won't run a browser or OS that complies with these regulations and as far as I can tell, they can't realistically make me. The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply…
They could comply and treat them like self signed certificates with a click through screen. "This website's certificate is issued by CA. Are you sure you want to proceed?"
Some observations on the final text of the European Digital Identity framework
121–130 of 153 posts
Re: Some observations on the final text of the European Digital Identity framework
#122So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?
[flagged]
Re: Some observations on the final text of the European Digital Identity framework
#123Re: Some observations on the final text of the European Digital Identity framework
#124Earlier quoted context omitted.
It would be impossible for them to force me to blindly accept a government issued ID card as true, and it would be insane for me to comply with such a demand. The same is true here, I won't run a browser or OS that complies with these regulations and as far as I can tell, they can't realistically make me. The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply…
They could comply and treat them like self signed certificates with a click through screen. "This website's certificate is issued by CA. Are you sure you want to proceed?"
Re: Some observations on the final text of the European Digital Identity framework
#125So here's a scenario I haven't seen brought up yet. Elbonian hackers manage to steal the singing key of kneebonia who is part of the EU (and also does IT as well as you would expect a European national government to do) They start publishing a ton of their own certs and start MITM everything out the wazoo. In the current environment this is noted by the community quickly they respond and revoke the Kneebonian cert, t…
Your case is exactly the same as some entity stealing the ability to issue passports for a country. Insinuating that people issuing national identifications don't understand the issue of forging said documents is some ridiculous techbro arrogance. We've been dealing with this shit for centuries and those "beaurocrats" you're insulting have probably gone through more more cases of fraud and forgery than you ever thoug…
Re: Some observations on the final text of the European Digital Identity framework
#126Earlier quoted context omitted.
I wonder if this would require browsers to allow government certs in place of their own pinned certs (e.g., chrome pins certs for google sites and maybe others I believe, if a non matching cert is used then the connection is rejected).
Well sort of, it allows government to create a falsified certificate for other sites like Google sites (man in the middle attack). When the browser forum/certificate authority wise up to it's use, they've then got to prove it's causing harm and get approval from authorities to remove it (authorities can take their sweet time responding to the request).
Depending on the wording of the law, it seems like it could require browsers to ignore this requirement for government issued certificates, hence bypassing the cert pinning and allowing them to intercept traffic to e.g., Facebook.
I'm not sure how many sites do this, I think Google's own do, and maybe some of the other big names use it as well, but I'm not certain.
Re: Some observations on the final text of the European Digital Identity framework
#127> We were concerned about the phrasing of Article 45, that lays down a requirement for browsers to recognize any certificate ... So same as today but with less steps? Most govs are already in you browser/OS CA list. And every single government force you to download their own cert and add to your browser at some point. There's no way to add that cert and say "limit this to gov.in only"! after you added that cert it is…
The game is not over just because you trust a CA. If they sign a certificate for a domain, they have to also publish that they did (in the CT logs) before browsers will accept it. If they do so for an entity that didn't ask for it, that will be investigated by browser and OS vendors and it may easily end up with the CA becoming untrusted.
Re: Some observations on the final text of the European Digital Identity framework
#128Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.
> Cookie banners happened because US devs didn't steelman EU regs. This is one of the dumbest narratives I see on HN all the time. A community of people who build things for a living should know better. Think of regulation as software designed to create an outcome in the real world. If everyone is wrongly using/interpreting your software…the problem is not “everyone.” The problem is the design of your software.
Re: Some observations on the final text of the European Digital Identity framework
#129So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?
[flagged]
Re: Some observations on the final text of the European Digital Identity framework
#130Earlier quoted context omitted.
Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…
an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.