Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

181–190 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#181
post #163

If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…

> For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA For someone living in the West, what are the consequences of deleting or distrusting those CAs?

probably none

If you run into some websites which use them the browser will tell you that the certificate is invalid; you can always reinstall them if you prefer.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#182
post #166

Earlier quoted context omitted.

Yes, but: 1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs. 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. So it's not really viable to use the existing CA system for MitM attacks. The eIDAS proposal would: 1. Prevent browsers from distrusting CAs which are used in MitM attacks. 2. Ban mandatory…

> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

> 1. Is this proactively monitored for? And how? And by whom?

Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com (https://groups.google.com/g/mozilla.dev.security.policy/c/fy...) and Certinomis issuing for test.com (https://bugzilla.mozilla.org/show_bug.cgi?id=1496088). Both CAs were eventually distrusted. (But Certinomis will be back once eIDAS is adopted!)

Domain owners can use Certificate Transparency Monitors to learn about suspicious certificates for their own domains. Here are some monitors:

https://crt.sh/ - allows you to search for certificates for a domain

https://github.com/SSLMate/certspotter/ - open source tool which notifies you when a certificate is issued for one of your domains

https://sslmate.com/certspotter/ - commercial service that does the same, operated by my company

> 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

In 2017, Chrome and Firefox distrusted Symantec, which was at the time the world's largest certificate authority: https://security.googleblog.com/2017/09/chromes-plan-to-dist...

Symantec hadn't even issued MitM certs - they were just grossly incompetent. Distrusting them was very painful, but necessary to uphold the integrity of the CA system, and demonstrated conclusively that there is no such thing as a too-big-to-fail CA.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#184
post #41

The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…

The worst part is that this is still better than how most governments currently work. At least there is a chance to give feedback. Also, keep in mind that this is in the context of getting all member states of the EU to agree on something. People kicking up a fuss is the default situation because of conflicting interests between different states. Make no mistake about how I feel about this though: it's still pretty h…

I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process ..

I mean, I certainly did not vote for Ursula von der Leyen either.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#185

For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/

eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…

> eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards.

Did we need laws to "unify" all the standards we successfully use today, like IP, UDP, TCP, HTTP, TLS, Certificate Transparency, HTML, ECMAScript, CSS, DNS, DMARC, DKIM, SSH, etc.? Laws are not the right tool for this. And law makers don't have the necessary expertise.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#186
post #142

Earlier quoted context omitted.

web-browsers shall ensure

The only requirement is that browsers displays the data. The browser can add "warning, this certificate is potentially compromised" when it displays it, nothing in the current document says browsers aren't allowed to say that, just that the browser has to be aware of the certificate. It is similar to how Chrome displays a warning when you visit some sites. You can visit the site anyway, but you get a warning since Go…

Even without the 45 (2a), displayed in a user-friendly manner could already be interpreted to prevent prominent warnings

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#187

Earlier quoted context omitted.

It's not like Beijing CA can issue a rogue certifcate and suddenly a malicious actor would be able to decrypt all your internet traffic. You would have to connect to a service that uses those certificates in the first place. An interesting experiment would be to log all certificates used by the sites you normally use, say for a month, and then look at the list for anything shady. I have no ideia if an extension exist…

No, that's not needed at all. If the malicious actor can man-in-the-middle traffic to victimsite.com (say using a BGP hijack), they can serve HTTPS traffic to the end user from their MITM server, secured with a certificate issued to "victimsite.com" that is issued by their own CA, and the MITM can then in turn communicate to the real victimsite.com using HTTPS secured by the real site's certificate, signed by its own…

This will get noticed in a matter of seconds.

But if your own government tells your own isp to reroute just your traffic over some MITM proxy, it's only you there to notice, and most probably, you won't.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#188
post #177

Earlier quoted context omitted.

The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system. I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I…

EU website makes the IBM and HP websites seem user-friendly and easy. I tried engaging with some of the Open Source stuff a few years ago, and I definitely felt like I needed a "European Studies" PhD to be able to navigate all of that.

A really good friend of mine created the first version of eur-lex.europa (hopefully it's that one, it was a website for lawyers to find European legislation and case law), he barely finished his first internship at the time, only had one true web project on his belt (and two weeks of intensive formation), and was spectacularly underpaid (not for his inexistant qualifications, but for the work he did).

I thought he did a good work, but I was a student too so maybe I was just impressed with basic stuff (highly likely).

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#189

Earlier quoted context omitted.

You can manually distrust hardcoded CAs in all common browsers. But even now, this is rarely used because it is tedious, there are roughly a hundred active CAs. And depending on how that law will be interpreted by courts, manually distrusting might be considered illegal.

> manually distrusting might be considered illegal It is just a display change, all the law says is: "For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner." I don't see how adding a warning icon or block icon instead of the lock hurts would be banned. To me it seems like so much here is based on baseless assumptions.

to me at this point it seems like you're trying to defend this law a-priori...

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#190
post #163

If you are concerned by this proposals, then you should check out current CAs trusted by your browser - all those CAs can issue rogue certificates trusted by your browser, that can be used in MITM attack. For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA The CA system in browsers is inherently broken and it allows state actors to MITM you…

> For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA For someone living in the West, what are the consequences of deleting or distrusting those CAs?

You lose nothing, gain nothing. It's hard for china to reroute your traffic, and even if they did, what can they do to you after that?

It's your own government that can actually do something bad to you.

(unless you're doing some really really nasty stuff, and china wants to eliminate you for those reasons, and is willing to create a large international incident because of that).

Post reply on HN