Live data from Hacker News

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

theregister.com

21–30 of 73 posts

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#21
post #12
post #5

Earlier quoted context omitted.

This future is just O.K. because in the age of digital weapons what else is supposed for governments to be? The problem is that HTTPS is too government-addicted thing while a decent anti-MITM feature might/should be just a Diffie-Hellman without any identity-preserving features, I mean just E2EE. At least for sites like HN (not banks).

Duffie-Hellman can be MITMed if nothing checks that the value you get from the other party actually comes from the intended other party. I.e., an identity check.

That is OK if the talk is not about bank or currency exchange.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#22
post #15

From the perspective of European govs: Why should only US entities (and companies like Cloudflare, Amazon or Google) be allowed to get access to communications content ? It’s very logical that Europe wants to do the same.

Then they should encourage European companies to do it, no legislate and muscle their way in.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#23
We really need to go back to days of police actually going through the trouble of investigating and catching criminals - at least in principle.

Now every government security agency dreams of having complete access to the communications of everyone so they don't go through the trouble of doing their job. First UK, now EU.

Although I'm generally closer to the EU mentality of trusting the governments more than the corporations, this aspiration of the governments is just too much even if the European governments were perfect(they are far from it).

IMHO these are good intentioned ideas by the people who are responsible of providing security, it's just that they are too narrow minded brainchild of incompetent bureaucrats.

"How easy would my job be if I was able to access the communications between terrorists/pedos/spies etc."

Yeah right, we all exist to make your job easier and that's the top priority over everything else.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#24
post #8
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

>innate distrust in their government, something most EU citizens don't have Was that a joke?

Not OP, but it's a pretty American perspective to see Europeans as very complacent with what their government does. If not a joke, this is probably where the sentiment stems from.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#27
post #18

>This enables the government of any EU member state to issue website certificates for interception and surveillance Wouldn't this be very easy to identify?

The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the help of ISPs etc).

Yes, but you will see that the certificate authority suddenly switches to the Hungarian government, while reading an article.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#28
> This enables the government of any EU member state to issue website certificates for interception and surveillance which can be used against every EU citizen, even those not resident in or connected to the issuing member state.

This is already possible though, all a state needs to do for that is to bribe Microsoft[1] like Tunisia did ~20 years ago to include a government intelligence agency's root certificate that can then be used for MitM.

[1] and/or Apple and Google, if they want to target mobile devices as well.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#29
post #22
post #15

From the perspective of European govs: Why should only US entities (and companies like Cloudflare, Amazon or Google) be allowed to get access to communications content ? It’s very logical that Europe wants to do the same.

Then they should encourage European companies to do it, no legislate and muscle their way in.

It is much, much easier to wait for someone else to do all the difficult stuff, and then write a rule that if you don't also get the same stuff that you can lock people in a box or take some of their money.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#30
post #13
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

I think many EU citizens have a distrust in other EU governments than their own, and this sounds like it would allow all EU governments to intercept all EU citizens.

It would allow all EU governments to intercept everyone on the planet if that CA is root in every browser install.
Post reply on HN