Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

21–30 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#21
post #16
post #13

Earlier quoted context omitted.

Oh yeah if encryption is broken only for browsers no big deal right

Governments still can't see your requests to servers under normal circumstances with this law. The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at "e2e.com" when you are on another site, and in those cases the only difference from now is that your browser will display "secure" instead of "invalid cert". There is no oth…

"The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at e2e.com"

That will be (or already is) done at ISP level. It will probably be fully automated, where they just put a court order number into a form, and it automatically just catches all your traffic in gear that's installed at the ISP.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#25

How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?

People get very hung up on what people can technically do, but the domains of the browser or OS that doesn’t follow these rules will simply be blocked at the DNS level so that you can’t download them any more. The relevant entities such as companies developing or using said non-compliant projects will be fined, and any natural persons jailed outright, à la Stallman’s The Right To Read.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#26
post #21
post #16

Earlier quoted context omitted.

Governments still can't see your requests to servers under normal circumstances with this law. The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at "e2e.com" when you are on another site, and in those cases the only difference from now is that your browser will display "secure" instead of "invalid cert". There is no oth…

"The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at e2e.com" That will be (or already is) done at ISP level. It will probably be fully automated, where they just put a court order number into a form, and it automatically just catches all your traffic in gear that's installed at the ISP.

It is only undetectable if the site actually uses the vulnerable certificates. Otherwise you can see that the government is spying on you since the browser tells you what certificate it got (Telling you what certificate was used is a part of eIDAS). There is no way the government will replace certificates like that on an automated basis, it is too easy for people to notice and make a big deal about.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#27
post #14
post #11

Earlier quoted context omitted.

> This is still very bad. Yes, potentially, but it isn't "another kind of chat control".

It's another side of the efforts of going around encryption, chat controls deals with communication services, this one with browsers

But this doesn't force browsers and sites to use weak encryption. It is very different.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#28

How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?

Unfortunately the whole world population is addicted to ~5 sites/apps on the web who will play the game.

If Debian patches this out, you won't be able to access those sites. That's a living edge case for them.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#30
post #19

So what happens to open source browsers? Will they be forced to implement it? Are the governments going to audit the code to make sure no one is releasing a version that has removed the government certs or are they going to outlaw open source browsers? Again, this is not going to catch anyone with half a braincell that is trying to do something. This is just going to catch everyone else. I wonder if this will tie int…

> I wonder if this will tie into the BS that Google was trying to implement that would make it impossible to modify the webpage using adblocker

Very likely, yes. Also note that a similar client-side CSAM scanning feature was rolled out by Apple with a similar anticipation, and shortly after we saw the proposal of Chatcontrol and the like.

> So what happens to open source browsers?

See my other comment on the same thread[1].

[1] https://news.ycombinator.com/item?id=38110667

Post reply on HN