Earlier quoted context omitted.
This future is just O.K. because in the age of digital weapons what else is supposed for governments to be? The problem is that HTTPS is too government-addicted thing while a decent anti-MITM feature might/should be just a Diffie-Hellman without any identity-preserving features, I mean just E2EE. At least for sites like HN (not banks).
Duffie-Hellman can be MITMed if nothing checks that the value you get from the other party actually comes from the intended other party. I.e., an identity check.
Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
21–30 of 73 posts
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#22From the perspective of European govs: Why should only US entities (and companies like Cloudflare, Amazon or Google) be allowed to get access to communications content ? It’s very logical that Europe wants to do the same.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#23Now every government security agency dreams of having complete access to the communications of everyone so they don't go through the trouble of doing their job. First UK, now EU.
Although I'm generally closer to the EU mentality of trusting the governments more than the corporations, this aspiration of the governments is just too much even if the European governments were perfect(they are far from it).
IMHO these are good intentioned ideas by the people who are responsible of providing security, it's just that they are too narrow minded brainchild of incompetent bureaucrats.
"How easy would my job be if I was able to access the communications between terrorists/pedos/spies etc."
Yeah right, we all exist to make your job easier and that's the top priority over everything else.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#24I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.
>innate distrust in their government, something most EU citizens don't have Was that a joke?
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#25Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#26Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#27>This enables the government of any EU member state to issue website certificates for interception and surveillance Wouldn't this be very easy to identify?
The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the help of ISPs etc).
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#28This is already possible though, all a state needs to do for that is to bribe Microsoft[1] like Tunisia did ~20 years ago to include a government intelligence agency's root certificate that can then be used for MitM.
[1] and/or Apple and Google, if they want to target mobile devices as well.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#29From the perspective of European govs: Why should only US entities (and companies like Cloudflare, Amazon or Google) be allowed to get access to communications content ? It’s very logical that Europe wants to do the same.
Then they should encourage European companies to do it, no legislate and muscle their way in.
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#30I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.
I think many EU citizens have a distrust in other EU governments than their own, and this sounds like it would allow all EU governments to intercept all EU citizens.