Live data from Hacker News

Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

eidas-open-letter.org

21–30 of 67 posts

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#21
post #15

If this goes through without change the browser vendors should implement an UX which allows the user to disable these root certificates; ideally within different contexts. I also hope that our community produces tools to allow the cert stack on our OSes to be purged of these certificates.

Then they’ll ban that UX. Just like US banned the ability to disclose how much taxes you pay for airline tickets EDIT: for clarification, they banned disclosing it in initial communications like emails. They can do same for browsers. Apple also successfully banned apps from disclosing links to buying stuff online etc.

I can still see taxes and fees when I'm booking a flight. I just checked on delta.com . I can see the total taxes and fees, and the breakdown of what they are and how much each one is. I'm in the US.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#23
post #2

"In summary, we strongly warn against the currently proposed trilogue agreement, as it fails to properly respect the right to privacy of citizens and secure online communications; without establishing proper safeguards as outlined above, it instead substantially increases the potential for harm." The Open Source Security Foundation (OpenSSF) has co-signed the Industry Joint Statement on Article 45 in the EU’s eIDAS R…

Good morning. It has actually been happening all around the world, not just in the EU. Given how governments encroached on crypto and ad tech and social tech and in the last 10 years, the writing is on the wall for end-to-end encryption next. They have to know ALL your communications:

I wrote a summary of the countries in the world that have already undermined it, banned it or on the way to banning it:

https://community.qbix.com/t/the-coming-war-on-end-to-end-en...

To be clear: EU here is backdooring https encryption. While also moving to ban end-to-end encryption (Spain leading the way).

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#24

I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…

HPKP was generally not recommended even when it was still around due to the danger of breaking your site. https://scotthelme.co.uk/im-giving-up-on-hpkp/

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#25
post #21
post #15

Earlier quoted context omitted.

Then they’ll ban that UX. Just like US banned the ability to disclose how much taxes you pay for airline tickets EDIT: for clarification, they banned disclosing it in initial communications like emails. They can do same for browsers. Apple also successfully banned apps from disclosing links to buying stuff online etc.

I can still see taxes and fees when I'm booking a flight. I just checked on delta.com . I can see the total taxes and fees, and the breakdown of what they are and how much each one is. I'm in the US.

I remember HN from over a decade ago: https://www.cntraveler.com/stories/2012-01-31/spirit-airline...

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#26

Could we work around this by moving encryption to the application/website layer with client certificates? Please let me know if you see any reason this wouldn't work.

You still have a bootstrapping problem. How do we establish what application-layer signatures are valid when a member state can forge a certificate for any origin at the transport-layer?

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#27
post #23
post #2

"In summary, we strongly warn against the currently proposed trilogue agreement, as it fails to properly respect the right to privacy of citizens and secure online communications; without establishing proper safeguards as outlined above, it instead substantially increases the potential for harm." The Open Source Security Foundation (OpenSSF) has co-signed the Industry Joint Statement on Article 45 in the EU’s eIDAS R…

Good morning. It has actually been happening all around the world, not just in the EU. Given how governments encroached on crypto and ad tech and social tech and in the last 10 years, the writing is on the wall for end-to-end encryption next. They have to know ALL your communications: I wrote a summary of the countries in the world that have already undermined it, banned it or on the way to banning it: https://commun…

The pushback against ad tech - or more precisely tracking tech - is hardly the same thing. One of the EU's moves will greatly improve privacy, another one will harm it.

A world is possible where we have end-to-end encryption AND a ban on profiling people online without their consent.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#28

I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…

We already have such system: DANE + DNSSEC. Unfortunately browsers vendors do not implement it.

Interesting - I know DNSSEC (great solution) but haven't seen DANE. From a quick glance it looks like an obvious solution which should be implemented by the browser vendors and top sites.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#29
post #23

Earlier quoted context omitted.

Good morning. It has actually been happening all around the world, not just in the EU. Given how governments encroached on crypto and ad tech and social tech and in the last 10 years, the writing is on the wall for end-to-end encryption next. They have to know ALL your communications: I wrote a summary of the countries in the world that have already undermined it, banned it or on the way to banning it: https://commun…

The pushback against ad tech - or more precisely tracking tech - is hardly the same thing. One of the EU's moves will greatly improve privacy, another one will harm it. A world is possible where we have end-to-end encryption AND a ban on profiling people online without their consent.

Sure, and a world is possible when we have other types of tech, too. For example we can have zero-knowledge proofs to access online sites and prove we’re over 18. But the UK government has already passed a law requiring all websites to KYC their members with a passport. And Utah recently passed a law also protecting children on social sites and I asked their politicians directly how they will enforce it — a likely candidate will be requiring ID from everyone.

But the governments when all is said and done don’t care about your privacy.

https://www.biometricupdate.com/202309/uk-passes-online-safe...

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#30
post #24

I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…

HPKP was generally not recommended even when it was still around due to the danger of breaking your site. https://scotthelme.co.uk/im-giving-up-on-hpkp/

We're already all used to running ad/script block on our clients so accept a certain level of breakage. It's just a part of the cost of using the web that some sites are crap (youtube being the big one nowadays) but in the end we just "route around them" (they die).
Post reply on HN