If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
Last Chance to fix eIDAS: Secret EU law threatens Internet security
171–180 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#172Earlier quoted context omitted.
Yes, but: 1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs. 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. So it's not really viable to use the existing CA system for MitM attacks. The eIDAS proposal would: 1. Prevent browsers from distrusting CAs which are used in MitM attacks. 2. Ban mandatory…
> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#173If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
It's not like Beijing CA can issue a rogue certifcate and suddenly a malicious actor would be able to decrypt all your internet traffic. You would have to connect to a service that uses those certificates in the first place. An interesting experiment would be to log all certificates used by the sites you normally use, say for a month, and then look at the list for anything shady. I have no ideia if an extension exist…
Now, there are CAA DNS records, which serve the purpose of restricting the CAs that can sign a particular domain, which would of course be ignored by the malicious actor, but _could_ be checked by the end user's browser. But to the best of my knowledge, no browser does that.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#174[flagged]
So you don't need to know anything to use all-caps and throw around LIARS.
Article 45
Requirements for qualified certificates for WEBSITE AUTHENTICATION
1. Qualified certificates for WEBSITE AUTHENTICATION shall meet the requirements laid down in Annex IV. Evaluation of compliance with the requirements laid down in Annex IV shall be carried out in accordance with the specifications and standards referred to in paragraph 4.
2. Qualified certificates for WEBSITE AUTHENTICATION referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certificates for WEBSITE AUTHENTICATION referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#175Earlier quoted context omitted.
A proper solution for MitM is mandatory independent certificate transparency, not outright denial of national CAs support in browsers. A German National CA should not be able to issue certificates for .ru in the first place and having a clear record of misbehavior in CT is probably not something operators of such CA would like to have even when pressured by intelligence agencies. Browsers should get their shit togeth…
> Browsers should get their shit together and add proper support of domain-limited CAs They do in fact support this - e.g. Mozilla trusts KamuSM only for .tr [1], Chrome limited ANSSI to French TLDs [2]. However, there is no indication that the EU would be willing to accept such constraints on their national CAs. If you look at several of the current national European CAs, they routinely issue for generic TLDs like .…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#176If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…
It's not like Beijing CA can issue a rogue certifcate and suddenly a malicious actor would be able to decrypt all your internet traffic. You would have to connect to a service that uses those certificates in the first place. An interesting experiment would be to log all certificates used by the sites you normally use, say for a month, and then look at the list for anything shady. I have no ideia if an extension exist…
With certificate logs there is a chance, I don’t know how high, to catch 1).
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#177Earlier quoted context omitted.
But the plans were on display…” “On display? I eventually had to go down to the cellar to find them.” “That’s the display department.” “With a flashlight.” “Ah, well, the lights had probably gone.” “So had the stairs.” “But look, you found the notice, didn’t you?” “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Bewa…
The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system. I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#178Earlier quoted context omitted.
How do you ban a FOSS?
"One cannot hang a song, sure, but one can hang a singer". There are not so many places where people can get Firefox or Chromium, even fewer places where they can get source code of the named browsers. [EDIT] grammar
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#179Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#180Earlier quoted context omitted.
> Browsers already had their own standard that they think is better than eIDAS Unlike the Browser/CA forum rules which are security focused, EIDAS comes from a government mandate first and foremost, so the concern isn’t entirely subjective as you suggest. > "and browsers should also do this" instead of there being some conspiracy behind it The law isn’t RFC 2119 where there is a distinction between SHOULD and MUST: t…
I don't get what your point is here, you said this and that is what I argued against, your points here does nothing to defend this: "For anyone who’s about to say that surveillance isn’t the point of this legislation". > Unlike the Browser/CA forum rules which are security focused, EIDAS comes from a government mandate first and foremost, so the concern isn’t entirely subjective as you suggest. I didn't say this was…
- Make sure there is an open standard (is there?)
- Fund and promote its open source development
- Have an industry lobbyist non-profit to onboard individual businesses
If the goal is to ”promote standards” the way this is being done does not seem to be aligned the 50 years of software industry standard development, with the examples like TCP/IP, PNG, AV1 and so on.