Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

151–160 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#152

How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?

the law can be interpreted as making it illegal, even for end users (it deals with "web-browsers", not "web browser vendors")

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#153
post #132
post #98

Earlier quoted context omitted.

Also, this: > and will be presented to the public and parliament for a rubber stamp before the end of the year That's not how the EU parliament works, they're not just a rubber stamp. The topic is sufficiently grave without the need for clickbait and painfully obvious exaggerations.

As I understand it, the EU Parliament engages through the trilogues. Once agreement has been reached there, final approval is indeed more of a rubberstamp. (But: I'm just somewhat interested in the subject; I'm not an expert on the process.)

Once an agreement has been reached, the Parliament can still reject the proposed law (which can easily happen because a conciliatory committee does not represent all the factions in parliament and of course public outcry/petitions can change opinions).

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#154
post #142

Earlier quoted context omitted.

Why shouldn't you be able to do that? Seems like a simple thing to implement. I get why they want a hardcoded list, but I don't get why you can't add a way to block parts of that hardcoded list.

web-browsers shall ensure

The only requirement is that browsers displays the data. The browser can add "warning, this certificate is potentially compromised" when it displays it, nothing in the current document says browsers aren't allowed to say that, just that the browser has to be aware of the certificate.

It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Google thinks it is bad.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#155

Earlier quoted context omitted.

They'd probably be fined into submission if they don't though.

If it gets to that point, one alternative would be creating some ad-hoc non profits that are on paper not controlled by them (but in practice they are) and then giving up the control of their respective browsers to said non-profits. But it won't get to that point. I don't really think the US government would be ok with a regulation like this, either, and they have even more bargaining power than tech companies.

then the non-profits would be breaking the law

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#156

Earlier quoted context omitted.

EU court: serves Mozilla a court order to add the extension to the blocklist.xml file, a global blocklist of all extension IDs that users can’t install.

Sure, and thereby begins yet another game of whack-a-mole as people create ever more elaborate workarounds.

and as ever less people have the working workaround

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#157
Contrary to the majority of opinions here, I see this as a reasonable development for the state’s sovereignty, which will positively affect the decentralisation of certificate authorities. I hope that unprofessional negligence by European authorities will produce enough precedents and evidence to show that certificate authorities can’t be trusted blindly, and we will end up with transparent certificate authorities and web browsers which will audit every certificate with public logs with the help of History Trees.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#158
post #91

Earlier quoted context omitted.

Maybe browsers shouldn't hardcode those things? If they let you blacklist CAs you could do that yourself or via a plugin. There is nothing preventing browsers from implementing that, and have a one click button "don't trust compromised CAs". Could even had that during install as a toggle, would satisfy every legal requirement. If this means users gets more power over what CAs to trust then that is a good thing.

You can manually distrust hardcoded CAs in all common browsers. But even now, this is rarely used because it is tedious, there are roughly a hundred active CAs. And depending on how that law will be interpreted by courts, manually distrusting might be considered illegal.

> manually distrusting might be considered illegal

It is just a display change, all the law says is:

"For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner."

I don't see how adding a warning icon or block icon instead of the lock hurts would be banned. To me it seems like so much here is based on baseless assumptions.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#159
Wow - this one really crept up on me, after years of seeing it shot down in flames by people who actually understand the technology, and the implications (not least, the security implications). I wonder if the recent passing of the UK act emboldened them..?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#160
post #125

Earlier quoted context omitted.

The enforcement mechanism is to warn and then ban non-compliant. There are just too few playeds in the field here. It would take only two major browser development companies to make the world 99% compliant. And the rest is statistical error no matter how safe and secure they are.

How do you ban a FOSS?

"One cannot hang a song, sure, but one can hang a singer". There are not so many places where people can get Firefox or Chromium, even fewer places where they can get source code of the named browsers. [EDIT] grammar
Post reply on HN