Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

161–170 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#162
post #142

Earlier quoted context omitted.

web-browsers shall ensure

The only requirement is that browsers displays the data. The browser can add "warning, this certificate is potentially compromised" when it displays it, nothing in the current document says browsers aren't allowed to say that, just that the browser has to be aware of the certificate. It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Go…

Technically correct. But if Firefox displays a big red warning when someone's grandma goes to her favourite recipe website, and Safari (or Chrome) just display the website to grandma (and to the officer on duty, but who cares) - how long will Firefox survive?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#163
If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack.

For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA

The CA system in browsers is inherently broken and it allows state actors to MITM you and see all your traffic if they: 1. have ability to capture IP traffic (requires cooperation with ISP) 2. have ability to generate rogue certificate via cooperation with CA

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#164
post #142

Earlier quoted context omitted.

web-browsers shall ensure

The only requirement is that browsers displays the data. The browser can add "warning, this certificate is potentially compromised" when it displays it, nothing in the current document says browsers aren't allowed to say that, just that the browser has to be aware of the certificate. It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Go…

It's not clear that a warning would be allowed. In particular, the new paragraph 45(2a) prohibits mandatory checks on eIDAS certificates.

Mozilla has proposed text[1] that would make clear that the requirement is only to display identity information, but this text has not been adopted.

[1] https://securityriskahead.eu/wp-content/uploads/2023/09/Mozi...

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#165
post #41

The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…

But the plans were on display…” “On display? I eventually had to go down to the cellar to find them.” “That’s the display department.” “With a flashlight.” “Ah, well, the lights had probably gone.” “So had the stairs.” “But look, you found the notice, didn’t you?” “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Bewa…

The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system.

I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I try now.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#166
post #163

If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…

Yes, but:

1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs.

2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers.

So it's not really viable to use the existing CA system for MitM attacks.

The eIDAS proposal would:

1. Prevent browsers from distrusting CAs which are used in MitM attacks.

2. Ban mandatory checks (such as Certificate Transparency) on certificates unless the EU agrees to them.

That creates a system that is very viable for government MitM attacks.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#167
post #163

If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…

The browser/CA forum’s requirement to log all issuances into the CT log takes care of this; the EU mandate hardly has such requirements while still mandating the inclusion of root certs. The approach of the browser/CA forum vs EIDAS cannot be equated for this reason.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#168
post #163

If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…

It's not like Beijing CA can issue a rogue certifcate and suddenly a malicious actor would be able to decrypt all your internet traffic. You would have to connect to a service that uses those certificates in the first place.

An interesting experiment would be to log all certificates used by the sites you normally use, say for a month, and then look at the list for anything shady. I have no ideia if an extension exists that would allow such and experiment, but the resulting list would be much more useful.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#169
post #163

If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…

> For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA

For someone living in the West, what are the consequences of deleting or distrusting those CAs?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#170
post #166
post #163

If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…

Yes, but: 1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs. 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. So it's not really viable to use the existing CA system for MitM attacks. The eIDAS proposal would: 1. Prevent browsers from distrusting CAs which are used in MitM attacks. 2. Ban mandatory…

> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers.

Thats reassuring but, not knowing much about this, I have a couple of questions:

1. Is this proactively monitored for? And how? And by whom?

2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

Post reply on HN