Last Chance to fix eIDAS: Secret EU law threatens Internet security
151–160 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#152How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#153Earlier quoted context omitted.
Also, this: > and will be presented to the public and parliament for a rubber stamp before the end of the year That's not how the EU parliament works, they're not just a rubber stamp. The topic is sufficiently grave without the need for clickbait and painfully obvious exaggerations.
As I understand it, the EU Parliament engages through the trilogues. Once agreement has been reached there, final approval is indeed more of a rubberstamp. (But: I'm just somewhat interested in the subject; I'm not an expert on the process.)
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#154Earlier quoted context omitted.
Why shouldn't you be able to do that? Seems like a simple thing to implement. I get why they want a hardcoded list, but I don't get why you can't add a way to block parts of that hardcoded list.
web-browsers shall ensure
It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Google thinks it is bad.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#155Earlier quoted context omitted.
They'd probably be fined into submission if they don't though.
If it gets to that point, one alternative would be creating some ad-hoc non profits that are on paper not controlled by them (but in practice they are) and then giving up the control of their respective browsers to said non-profits. But it won't get to that point. I don't really think the US government would be ok with a regulation like this, either, and they have even more bargaining power than tech companies.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#156Earlier quoted context omitted.
EU court: serves Mozilla a court order to add the extension to the blocklist.xml file, a global blocklist of all extension IDs that users can’t install.
Sure, and thereby begins yet another game of whack-a-mole as people create ever more elaborate workarounds.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#157Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#158Earlier quoted context omitted.
Maybe browsers shouldn't hardcode those things? If they let you blacklist CAs you could do that yourself or via a plugin. There is nothing preventing browsers from implementing that, and have a one click button "don't trust compromised CAs". Could even had that during install as a toggle, would satisfy every legal requirement. If this means users gets more power over what CAs to trust then that is a good thing.
You can manually distrust hardcoded CAs in all common browsers. But even now, this is rarely used because it is tedious, there are roughly a hundred active CAs. And depending on how that law will be interpreted by courts, manually distrusting might be considered illegal.
It is just a display change, all the law says is:
"For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner."
I don't see how adding a warning icon or block icon instead of the lock hurts would be banned. To me it seems like so much here is based on baseless assumptions.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#159Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#160Earlier quoted context omitted.
The enforcement mechanism is to warn and then ban non-compliant. There are just too few playeds in the field here. It would take only two major browser development companies to make the world 99% compliant. And the rest is statistical error no matter how safe and secure they are.
How do you ban a FOSS?