Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

201–210 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#202
post #9

Earlier quoted context omitted.

If "e2echat.com" has no method to explicitly forbid your browser from accepting eIDAS certs (via a DNS record or something) then your browser will just blindly accept the compromised cert when attacked. This is still very bad.

Wouldn't a client certificate from e2echat protect that kind of attack ? Since even when a man in the middle offers u a server cert u accept, the e2echat servers can't validate the client certificate from you anymore (Still bad but would at least protect connections from ever talking to e2echats servers)

Nobody uses client certs.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#203
EU is not the only place with insane laws like this in the pipeline. USA has been trying to introduce this kind of thing (EARN IT Act 2023) as well, under the guise of "preventing child trafficking".

Terrifying times we live in where we may not even be able to keep our medical or financial information private anymore because of a handful of people voting on something they don't understand.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#205

Earlier quoted context omitted.

> For example, CAs present in Firefox, that might give you pause: Beijing Certificate Authority, China Financial CA, Guang Dong CA For someone living in the West, what are the consequences of deleting or distrusting those CAs?

You lose nothing, gain nothing. It's hard for china to reroute your traffic, and even if they did, what can they do to you after that? It's your own government that can actually do something bad to you. (unless you're doing some really really nasty stuff, and china wants to eliminate you for those reasons, and is willing to create a large international incident because of that).

>and even if they did, what can they do to you after that?

An example of what China can do is they can have their workers put pressure on you. Often this pressure is soft, nothing as direct as 'do X or we hurt you with Y'. And often the request, at least at the start, is for something legal and only a bit unethical if even that. A little information to help win a contract, maybe a way to advertise to you why you should go with their vendor for a product, maybe just asking you if a specific coworker seems to have any interest in some odd topic or passing you a resume of someone who seems a good fit for the job. If they can they'll push for more with increasing levels of silver and lead, and if not, they use what they did get to pressure elsewhere.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#206
post #191

Earlier quoted context omitted.

I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process .. I mean, I certainly did not vote for Ursula von der Leyen either.

Your representatives that you voted into parliament did, however.

She was nominated by the European Council (=Heads of gov't of EU countries) because the EU parliament is a divided mess and the leading parties have no internal cohesion whatsoever. Parties at the european level are disparate coalitions between national parties and MEPs follow the national party line. The decision was made by national governments and rubber-stamped by the parliament.

This is fundamentally different from how a PM is voted in a traditional parliamentary system where an MP leads the party during the election process and elected as PM after a clear victory or negotiations between MPs.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#207

Earlier quoted context omitted.

You lose nothing, gain nothing. It's hard for china to reroute your traffic, and even if they did, what can they do to you after that? It's your own government that can actually do something bad to you. (unless you're doing some really really nasty stuff, and china wants to eliminate you for those reasons, and is willing to create a large international incident because of that).

Unless it's gotten better, it's super easy for China.. My traffic to EU World of Warcraft servers got hijacked all the time. I don't know if it was malicious or just incompetent Chinese ISPs, but you feel that extra latency when it goes through China.

But this wasn't a bgp redirect, this was blizzard doing something... if chinese telcos acted as if they were blizzard telcos, there would be bgp filters and a lot of outrage in a matter of minutes. This is not a small deal.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#208
post #191

Earlier quoted context omitted.

I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process .. I mean, I certainly did not vote for Ursula von der Leyen either.

Your representatives that you voted into parliament did, however.

Which is relevant to his/her point (about not being able to vote on people directly), because?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#209

Earlier quoted context omitted.

No, that's not needed at all. If the malicious actor can man-in-the-middle traffic to victimsite.com (say using a BGP hijack), they can serve HTTPS traffic to the end user from their MITM server, secured with a certificate issued to "victimsite.com" that is issued by their own CA, and the MITM can then in turn communicate to the real victimsite.com using HTTPS secured by the real site's certificate, signed by its own…

This will get noticed in a matter of seconds. But if your own government tells your own isp to reroute just your traffic over some MITM proxy, it's only you there to notice, and most probably, you won't.

In an ideal world, yes, they would by shut down in seconds. Yet BGP hijacks still occur in the real world; here's one from last month: https://slowmist.medium.com/analysis-of-balancer-bgp-hijacki...

And you're certainly right about government-mandated traffic hijacking.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#210
post #34

Earlier quoted context omitted.

Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…

It’s intriguing to observe this phenomena on HN where any posts critical of the EU will get downvoted, even though it is natural for any country or block to try various means to show or enforce its power. And before someone says otherwise, I’ve seen this playing out hundreds of times.

The post was typical anti gov tin foil hat nonsense. You see the same types of posts from people who like camping out on compounds in the mid west complaining about “the feds”
Post reply on HN