Earlier quoted context omitted.
If "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked. This is still very bad.
> This is still very bad. Yes, potentially, but it isn't "another kind of chat control".
Last Chance to fix eIDAS: Secret EU law threatens Internet security
141–150 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#142Earlier quoted context omitted.
IIRC one cannot tell the browser to not trust root CAs, that's why all the fuss.
Why shouldn't you be able to do that? Seems like a simple thing to implement. I get why they want a hardcoded list, but I don't get why you can't add a way to block parts of that hardcoded list.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#143Earlier quoted context omitted.
It is a digital certificate standard. Browser certificates is only a tiny part of it, that wasn't why it was made. Having a standard for digital certificates is a good thing, it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.
>it makes it easy to switch document signer provider etc since they all are forced to implement the same interface. eIDAS was introduced in 2016. Now 7 years later there still isn't a API specification for interoperability (there are drawings though https://blog.eid.as/new-apis-for-the-eidas-ecosystem/ ) In the meantime, any digital signature done in EU must be done with a certificate issued only by the "select" CA t…
article 25 of EIDAS 1. An electronic signature shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#144Earlier quoted context omitted.
eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…
> Browsers already had their own standard that they think is better than eIDAS Unlike the Browser/CA forum rules which are security focused, EIDAS comes from a government mandate first and foremost, so the concern isn’t entirely subjective as you suggest. > "and browsers should also do this" instead of there being some conspiracy behind it The law isn’t RFC 2119 where there is a distinction between SHOULD and MUST: t…
> Unlike the Browser/CA forum rules which are security focused, EIDAS comes from a government mandate first and foremost, so the concern isn’t entirely subjective as you suggest.
I didn't say this was subjective. My argument was that it is easy to see why EU would do this without having surveillance in mind. They just wanted all certificates to follow the same standard, the main part of these standards were document signing and they thought web sites are documents so we add them as well to the standard.
> so bringing up “should” in this context isn’t helping the point you’re typing to make.
I didn't make a distinction between should and must there, that wasn't my point at all. What was hard to understand there? This bill is first and foremost about document signing, and then they added a clause that it also applies to browsers. That is the main part of my argument.
A bill that first and foremost targets document signing doesn't seem like it was obviously made to add spying on browsers, if that is what they wanted they would have labeled it "web protection bill" or something like they did with the chat one, they aren't afraid of saying it is about spying when that is what they want.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#145Earlier quoted context omitted.
A proper solution for MitM is mandatory independent certificate transparency, not outright denial of national CAs support in browsers. A German National CA should not be able to issue certificates for .ru in the first place and having a clear record of misbehavior in CT is probably not something operators of such CA would like to have even when pressured by intelligence agencies. Browsers should get their shit togeth…
Browsers do have this, although this measure is only selectively applied for certain CAs where misissuance has been an issue (There was a Indian CA for which this was used, need to look around MDSP for the link. I’ll post it shortly.)
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#146Ignorant question: what happens if Mozilla or Brave or whoever says fuck that, we're not complying? What's the enforcement mechanism for non-EU-based devs publishing FOSS freely on the global internet?
The enforcement mechanism is to warn and then ban non-compliant. There are just too few playeds in the field here. It would take only two major browser development companies to make the world 99% compliant. And the rest is statistical error no matter how safe and secure they are.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#147Earlier quoted context omitted.
> This is still very bad. Yes, potentially, but it isn't "another kind of chat control".
Yes, I agree. The crying wolf is too much sometimes. Accepting certificates from a given issuer does not give them the issuer the right to impersonate others
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#148Earlier quoted context omitted.
>it makes it easy to switch document signer provider etc since they all are forced to implement the same interface. eIDAS was introduced in 2016. Now 7 years later there still isn't a API specification for interoperability (there are drawings though https://blog.eid.as/new-apis-for-the-eidas-ecosystem/ ) In the meantime, any digital signature done in EU must be done with a certificate issued only by the "select" CA t…
> Now 7 years later there still isn't a API specification for interoperability The standard existed 2016, I did a short stint for a company that was implemented eIDAS back then. They even have a test suite you can use to check how well you comply with the standard: https://ec.europa.eu/digital-building-blocks/wikis/display/D... It is very archaic to work with though, but at least they try to have a standard.
The real value in eIDAS would be "unlocked" if they would release a proper API specification with which a digital signatures application would integrate with any EIDAS CA to emit/sign certificates. And then enforce that any eIDAS compliant CA would implement this API.
In practice that means any company/digital signatures product could do a integration with this API once and then be able to use ANY certification authority they want/need/offer best prices for certificates.
Without this API, eIDAS is just a marketing moniker because the power belongs to the selected Certification Authorities. They set the prices, they choose WHOM can integrate with them to isse certificates and there is NO interoperability between them. This doesnt allow for a open market and makes the top players control everything while shouting "standards" and "eIDAS".....
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#149The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…
But the plans were on display…”
“On display? I eventually had to go down to the cellar to find them.”
“That’s the display department.”
“With a flashlight.”
“Ah, well, the lights had probably gone.”
“So had the stairs.”
“But look, you found the notice, didn’t you?”
“Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.
Douglas Adams wasn't far off.Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#150From: https://data.consilium.europa.eu/doc/document/ST-14959-2022-... Article 45(2): "Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certific…
> The proposed legislation also prevents the introduction of security checks when verifying the certificates used for encrypted web traffic in Art 45, (2a). As written, this language requires that the EU’s website certificates not be subjected to any mandatory requirements beyond those specified in ETSI standards.
This is awful, as it would forbid browsers from requiring Certificate Transparency, or banning a weak hash algorithm (like SHA-1), or requiring post-quantum keys unless the EU agrees to it.