If this goes through without change the browser vendors should implement an UX which allows the user to disable these root certificates; ideally within different contexts. I also hope that our community produces tools to allow the cert stack on our OSes to be purged of these certificates.
Then they’ll ban that UX. Just like US banned the ability to disclose how much taxes you pay for airline tickets EDIT: for clarification, they banned disclosing it in initial communications like emails. They can do same for browsers. Apple also successfully banned apps from disclosing links to buying stuff online etc.
Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
21–30 of 67 posts
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#22Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#23"In summary, we strongly warn against the currently proposed trilogue agreement, as it fails to properly respect the right to privacy of citizens and secure online communications; without establishing proper safeguards as outlined above, it instead substantially increases the potential for harm." The Open Source Security Foundation (OpenSSF) has co-signed the Industry Joint Statement on Article 45 in the EU’s eIDAS R…
I wrote a summary of the countries in the world that have already undermined it, banned it or on the way to banning it:
https://community.qbix.com/t/the-coming-war-on-end-to-end-en...
To be clear: EU here is backdooring https encryption. While also moving to ban end-to-end encryption (Spain leading the way).
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#24I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#25Earlier quoted context omitted.
Then they’ll ban that UX. Just like US banned the ability to disclose how much taxes you pay for airline tickets EDIT: for clarification, they banned disclosing it in initial communications like emails. They can do same for browsers. Apple also successfully banned apps from disclosing links to buying stuff online etc.
I can still see taxes and fees when I'm booking a flight. I just checked on delta.com . I can see the total taxes and fees, and the breakdown of what they are and how much each one is. I'm in the US.
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#26Could we work around this by moving encryption to the application/website layer with client certificates? Please let me know if you see any reason this wouldn't work.
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#27"In summary, we strongly warn against the currently proposed trilogue agreement, as it fails to properly respect the right to privacy of citizens and secure online communications; without establishing proper safeguards as outlined above, it instead substantially increases the potential for harm." The Open Source Security Foundation (OpenSSF) has co-signed the Industry Joint Statement on Article 45 in the EU’s eIDAS R…
Good morning. It has actually been happening all around the world, not just in the EU. Given how governments encroached on crypto and ad tech and social tech and in the last 10 years, the writing is on the wall for end-to-end encryption next. They have to know ALL your communications: I wrote a summary of the countries in the world that have already undermined it, banned it or on the way to banning it: https://commun…
A world is possible where we have end-to-end encryption AND a ban on profiling people online without their consent.
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#28I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…
We already have such system: DANE + DNSSEC. Unfortunately browsers vendors do not implement it.
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#29Earlier quoted context omitted.
Good morning. It has actually been happening all around the world, not just in the EU. Given how governments encroached on crypto and ad tech and social tech and in the last 10 years, the writing is on the wall for end-to-end encryption next. They have to know ALL your communications: I wrote a summary of the countries in the world that have already undermined it, banned it or on the way to banning it: https://commun…
The pushback against ad tech - or more precisely tracking tech - is hardly the same thing. One of the EU's moves will greatly improve privacy, another one will harm it. A world is possible where we have end-to-end encryption AND a ban on profiling people online without their consent.
But the governments when all is said and done don’t care about your privacy.
https://www.biometricupdate.com/202309/uk-passes-online-safe...
Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform
#30I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…
HPKP was generally not recommended even when it was still around due to the danger of breaking your site. https://scotthelme.co.uk/im-giving-up-on-hpkp/