Last Chance to fix eIDAS: Secret EU law threatens Internet security
161–170 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#162Earlier quoted context omitted.
web-browsers shall ensure
The only requirement is that browsers displays the data. The browser can add "warning, this certificate is potentially compromised" when it displays it, nothing in the current document says browsers aren't allowed to say that, just that the browser has to be aware of the certificate. It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Go…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#163For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA
The CA system in browsers is inherently broken and it allows state actors to MITM you and see all your traffic if they: 1. have ability to capture IP traffic (requires cooperation with ISP) 2. have ability to generate rogue certificate via cooperation with CA
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#164Earlier quoted context omitted.
web-browsers shall ensure
The only requirement is that browsers displays the data. The browser can add "warning, this certificate is potentially compromised" when it displays it, nothing in the current document says browsers aren't allowed to say that, just that the browser has to be aware of the certificate. It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Go…
Mozilla has proposed text[1] that would make clear that the requirement is only to display identity information, but this text has not been adopted.
[1] https://securityriskahead.eu/wp-content/uploads/2023/09/Mozi...
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#165The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…
But the plans were on display…” “On display? I eventually had to go down to the cellar to find them.” “That’s the display department.” “With a flashlight.” “Ah, well, the lights had probably gone.” “So had the stairs.” “But look, you found the notice, didn’t you?” “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Bewa…
I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I try now.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#166If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs.
2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers.
So it's not really viable to use the existing CA system for MitM attacks.
The eIDAS proposal would:
1. Prevent browsers from distrusting CAs which are used in MitM attacks.
2. Ban mandatory checks (such as Certificate Transparency) on certificates unless the EU agrees to them.
That creates a system that is very viable for government MitM attacks.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#167If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#168If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
An interesting experiment would be to log all certificates used by the sites you normally use, say for a month, and then look at the list for anything shady. I have no ideia if an extension exists that would allow such and experiment, but the resulting list would be much more useful.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#169If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
For someone living in the West, what are the consequences of deleting or distrusting those CAs?
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#170If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
Yes, but: 1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs. 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. So it's not really viable to use the existing CA system for MitM attacks. The eIDAS proposal would: 1. Prevent browsers from distrusting CAs which are used in MitM attacks. 2. Ban mandatory…
Thats reassuring but, not knowing much about this, I have a couple of questions:
1. Is this proactively monitored for? And how? And by whom?
2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?