Earlier quoted context omitted.
The worst part is that this is still better than how most governments currently work. At least there is a chance to give feedback. Also, keep in mind that this is in the context of getting all member states of the EU to agree on something. People kicking up a fuss is the default situation because of conflicting interests between different states. Make no mistake about how I feel about this though: it's still pretty h…
I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process .. I mean, I certainly did not vote for Ursula von der Leyen either.
Last Chance to fix eIDAS: Secret EU law threatens Internet security
191–200 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#192eIDAS is a cartel created to protect the business interests of EU biggest certification authorities.
It is a digital certificate standard. Browser certificates is only a tiny part of it, that wasn't why it was made. Having a standard for digital certificates is a good thing, it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#193Earlier quoted context omitted.
The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system. I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I…
EU website makes the IBM and HP websites seem user-friendly and easy. I tried engaging with some of the Open Source stuff a few years ago, and I definitely felt like I needed a "European Studies" PhD to be able to navigate all of that.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#194The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…
Wow, a lot of those quotes are damning.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#195Earlier quoted context omitted.
The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system. I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I…
EU website makes the IBM and HP websites seem user-friendly and easy. I tried engaging with some of the Open Source stuff a few years ago, and I definitely felt like I needed a "European Studies" PhD to be able to navigate all of that.
Another issue is basically the legal analogy of how certain difficult programming languages impose a selection bias on who actually is willing to learn it, which then leads to an echo-chamber culture where most people underestimate the issues with the programming language.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#196Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#197Earlier quoted context omitted.
You can manually distrust hardcoded CAs in all common browsers. But even now, this is rarely used because it is tedious, there are roughly a hundred active CAs. And depending on how that law will be interpreted by courts, manually distrusting might be considered illegal.
> manually distrusting might be considered illegal It is just a display change, all the law says is: "For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner." I don't see how adding a warning icon or block icon instead of the lock hurts would be banned. To me it seems like so much here is based on baseless assumptions.
I would also urge you to refrain from using terminology such as "baseless assumptions" when your own assumptions are so easily refuted by directly reading the text of the proposal.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#198Earlier quoted context omitted.
I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process .. I mean, I certainly did not vote for Ursula von der Leyen either.
Your representatives that you voted into parliament did, however.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#199For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/
eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…
I have no Earthly idea why a) this needs to be done digitally, or b) for the EU to be involved (at EU level) with this.
Unfortunately if you pitch mission creep vs the principle of subsidiarity, the former wins every time.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#200Earlier quoted context omitted.
> For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA For someone living in the West, what are the consequences of deleting or distrusting those CAs?
You lose nothing, gain nothing. It's hard for china to reroute your traffic, and even if they did, what can they do to you after that? It's your own government that can actually do something bad to you. (unless you're doing some really really nasty stuff, and china wants to eliminate you for those reasons, and is willing to create a large international incident because of that).