Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

131–140 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#131

I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…

Singapore has a venerable public ID system also, SingPass. Its been around since 2003 in some form. I cannot comment on its verified security, but appears to be reasonably ok. Banks use their own authn systems though.

Re: Some observations on the final text of the European Digital Identity framework

#132

Earlier quoted context omitted.

Yeah I wish I could get one as a foreigner. I only get a shitty piece of green paper that doesn't last more than a few months in a wallet. And I have to wait 10 years to change my citizenship over too. Now that the extreme-right party won the Dutch elections last week I'd really like to change it. South Americans can change it over after only 5 years. But not EU citizens strangely.

Didn’t you get an NIE? I had one immediately (so did my whole family), the card wasn’t paper, and it was treated as identical to the Spanish ID. And yes it was super convenient certificates and all. I had to use the certs once and was afraid (due to past experience) but honestly it “just worked”. Maybe EU citizens don’t get an NIE, though? I’m from further away.

The NIE that non EU foreigners get is indeed plastic, also referred to as a TIE sometimes.

However us EU citizens get the scrap of paper thingy. There's no photo on it either, we're supposed to use it alongside our EU photo ID.

Re: Some observations on the final text of the European Digital Identity framework

#133
post #73

Earlier quoted context omitted.

I frequently travel to the EU and the amount of cookie banners is decidedly higher.

I also notice German sites constantly nag you, Dutch seems to be a little less obnoxious. What's also interesting is that Germany, sticklers if I've ever seen any, is full of nonconsentual walls where you "of your free will with no negative consequences to deny" have to click "consent" or become a paid subscriber. If the data protection authority or the law is to be believed, that's not freely given consent Quite hil…

>If the data protection authority or the law is to be believed, that's not freely given consent

It's not. You can report this to an appropriate civil authority and in theory it'll be resolved (possibly with a fine). In practice the authorities are still so overwhelmed by GDPR that they will only look at the most severe high profile cases. Fingers crossed one day it'll improve...

Re: Some observations on the final text of the European Digital Identity framework

#134
post #110

Earlier quoted context omitted.

i'm mobile. probably got the wrong url. only have bookmarks for the ca certs https://www.gov.br/iti/pt-br/assuntos/repositorio/repositori...

But what do you need these certs for, is there a national website that gets an "insecure" warning if you visit it with a foreign version of Firefox?

yeah, the tax preparation website and others.

Re: Some observations on the final text of the European Digital Identity framework

#135
post #126

Earlier quoted context omitted.

Well sort of, it allows government to create a falsified certificate for other sites like Google sites (man in the middle attack). When the browser forum/certificate authority wise up to it's use, they've then got to prove it's causing harm and get approval from authorities to remove it (authorities can take their sweet time responding to the request).

Sorry, I mean, browsers today ship with a list of sites that specify a cert that must be in the chain for it to be considered valid, e.g., only trust a facebook.com cert if it's from XYZ CA. Depending on the wording of the law, it seems like it could require browsers to ignore this requirement for government issued certificates, hence bypassing the cert pinning and allowing them to intercept traffic to e.g., Facebook…

Sorry I see what you're saying, I think you're right. Perhaps a browser fork for non-EU folk? Far from ideal.

Re: Some observations on the final text of the European Digital Identity framework

#136

Earlier quoted context omitted.

At least your Spanish DNIe contains an X.509 certificate you can access via PKCS#11 that Just Works, both for authentication and signature. You can even use it for SSH!

Yeah I wish I could get one as a foreigner. I only get a shitty piece of green paper that doesn't last more than a few months in a wallet. And I have to wait 10 years to change my citizenship over too. Now that the extreme-right party won the Dutch elections last week I'd really like to change it. South Americans can change it over after only 5 years. But not EU citizens strangely.

You can get a digital certificate, such as the idCAT (the FNMT also issues them). I have mine loaded into a smart card because that's just how I roll, but either way it's equivalent to the DNIe; you can use it to authenticate to all the government agencies.

Re: Some observations on the final text of the European Digital Identity framework

#137

Earlier quoted context omitted.

Yeah I wish I could get one as a foreigner. I only get a shitty piece of green paper that doesn't last more than a few months in a wallet. And I have to wait 10 years to change my citizenship over too. Now that the extreme-right party won the Dutch elections last week I'd really like to change it. South Americans can change it over after only 5 years. But not EU citizens strangely.

Didn’t you get an NIE? I had one immediately (so did my whole family), the card wasn’t paper, and it was treated as identical to the Spanish ID. And yes it was super convenient certificates and all. I had to use the certs once and was afraid (due to past experience) but honestly it “just worked”. Maybe EU citizens don’t get an NIE, though? I’m from further away.

That is a TIE, upon which is marked your NIE. There is no certificate installed in it that I know of, just the "normal" contactless biometric travel document stuff like a passport.

The green paper slip is a certificate of registration of EU citizen in Spain, upon which is also marked with their NIE.

Re: Some observations on the final text of the European Digital Identity framework

#138
post #71

Earlier quoted context omitted.

> eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats. The flipside is that while it may be a "voluntary consortium", all major browsers are developed by entities based in the US, that are therefore subject to Nation…

EU governments will be even more subject to pressure from the US. I don't understand how anyone could doubt they will comply with every request from the US government. The difference is that the current decision makers only have power because other people trust them voluntarily. That makes them accountable, and it means a whistleblower can do much more to limit the damage by leaking the fact they are giving after to…

> the current decision makers only have power because other people trust them voluntarily.

Not really. Plenty of EU citizens don't trust Microsoft, Google or Apple. But there's no practical alternative. The government of an individual EU country has a lot more accountability than that.

Re: Some observations on the final text of the European Digital Identity framework

#139
post #138

Earlier quoted context omitted.

EU governments will be even more subject to pressure from the US. I don't understand how anyone could doubt they will comply with every request from the US government. The difference is that the current decision makers only have power because other people trust them voluntarily. That makes them accountable, and it means a whistleblower can do much more to limit the damage by leaking the fact they are giving after to…

> the current decision makers only have power because other people trust them voluntarily. Not really. Plenty of EU citizens don't trust Microsoft, Google or Apple. But there's no practical alternative. The government of an individual EU country has a lot more accountability than that.

They can install an open-source OS/browser and ignore Microsoft, Google, and Apple. There is nothing they can realistically do when they don't trust a government.

Governments ultimately derive their power from their ability to impose their will by violence. That makes them inherently less accountable than organizations that you are free to ignore.

Re: Some observations on the final text of the European Digital Identity framework

#140
post #138

Earlier quoted context omitted.

> the current decision makers only have power because other people trust them voluntarily. Not really. Plenty of EU citizens don't trust Microsoft, Google or Apple. But there's no practical alternative. The government of an individual EU country has a lot more accountability than that.

They can install an open-source OS/browser and ignore Microsoft, Google, and Apple. There is nothing they can realistically do when they don't trust a government. Governments ultimately derive their power from their ability to impose their will by violence. That makes them inherently less accountable than organizations that you are free to ignore.

Someone who doesn't trust a government can move countries, particularly in the EU. I'd argue that it's actually easier to avoid a given EU government than to use an OS/browser combination that's not controlled by US entities.
Post reply on HN