Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

211–220 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#211
post #206
post #191

Earlier quoted context omitted.

Your representatives that you voted into parliament did, however.

She was nominated by the European Council (=Heads of gov't of EU countries) because the EU parliament is a divided mess and the leading parties have no internal cohesion whatsoever. Parties at the european level are disparate coalitions between national parties and MEPs follow the national party line. The decision was made by national governments and rubber-stamped by the parliament. This is fundamentally different f…

Having a prominent MP leader like that is one of my second least favorite part of parliamentary governments[1]. Politics and governance aren't so simple that one person will ever be found that fairly represents the majority of the populace because the majority of the populace can't agree on multiple things. It's better for the majority of the power in governments to be devolved down to MPs voting on matters with the executive branch just being a formality for PR on the local and international stage - as well as being entrusted with emergency powers if we ever need to get anything done.

We're a people with a wide spectrum of beliefs - we should be represented by a wide spectrum of MPs... never by a single voice.

1. My first being whenever a single party actually wins a majority.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#212
post #182

Earlier quoted context omitted.

> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

> 1. Is this proactively monitored for? And how? And by whom? Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com ( https://groups.google.com/g/mozilla.dev.security.policy/c/fy... ) and Certinomis issuing for test.com ( https://bugzilla.mozilla.org/show_bug.cgi?id=1496088 ). Both CAs were eventual…

[deleted]

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#213

Earlier quoted context omitted.

eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…

> signing official documents like grades from school I have no Earthly idea why a) this needs to be done digitally, or b) for the EU to be involved (at EU level) with this. Unfortunately if you pitch mission creep vs the principle of subsidiarity, the former wins every time.

University grades are standardised already. This is useful because it allows people to work in other countries, digitally signing them prevents fraud.

This is just one use case for eIDAS, then you have things like interacting with different government institutions, banks, et cetera, et cetera.

There are a lot of people who live in/work/visit other EU countries as is their near absolute right. We should therefore standardise technology on the EU level to make their lives easier.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#214
post #91
post #86

Earlier quoted context omitted.

It is "easily", because current commercially available "firewall" appliances include that kind of capabilities. Just a few clicks, install a CA certificate, add a logging endpoint, done. Certain regulated industries like finance and medicine are required to use those. All chats are instantly intercepted and logged. And the way to spy on people via a certificate authority is exactly as described, you get a CA that sig…

Maybe browsers shouldn't hardcode those things? If they let you blacklist CAs you could do that yourself or via a plugin. There is nothing preventing browsers from implementing that, and have a one click button "don't trust compromised CAs". Could even had that during install as a toggle, would satisfy every legal requirement. If this means users gets more power over what CAs to trust then that is a good thing.

> If this means users gets more power over what CAs to trust then that is a good thing.

Do you really think your average user is going to go into the browser and manually distrust root CAs? We have learned again and again that good security is "secure by default", not "secure after arcane configuration".

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#215
post #41

The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…

The worst part is that this is still better than how most governments currently work. At least there is a chance to give feedback. Also, keep in mind that this is in the context of getting all member states of the EU to agree on something. People kicking up a fuss is the default situation because of conflicting interests between different states. Make no mistake about how I feel about this though: it's still pretty h…

> People kicking up a fuss is the default situation because of conflicting interests between different states.

In some cases less between the states and more between gonvernment and people. The european parliament is elected by the people. But many important matters are defined by the comission consisting of representatives of the member states governments.

Of course the different governments are also elected. But as part of the comission they can act against the will of the people and later blame the EU.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#216
post #213

Earlier quoted context omitted.

> signing official documents like grades from school I have no Earthly idea why a) this needs to be done digitally, or b) for the EU to be involved (at EU level) with this. Unfortunately if you pitch mission creep vs the principle of subsidiarity, the former wins every time.

University grades are standardised already. This is useful because it allows people to work in other countries, digitally signing them prevents fraud. This is just one use case for eIDAS, then you have things like interacting with different government institutions, banks, et cetera, et cetera. There are a lot of people who live in/work/visit other EU countries as is their near absolute right. We should therefore stan…

Great, very good! Now if you want to standardize encrypted communication, please do it with the help of security researchers, not like this.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#217

Earlier quoted context omitted.

eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…

> eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Did we need laws to "unify" all the standards we successfully use today, like IP, UDP, TCP, HTTP, TLS, Certificate Transparency, HTML, ECMAScript, CSS, DNS, DMARC, DKIM, SSH, etc.? Laws are not the right tool for this. And law makers don't have the necessary expertise.

It’s either laws or market forces, both have drawbacks.

While eIDAS seems like a great idea to coerce member states into adopting a common standard, it just also happens to sneak EU-centralist ideology in, and total digital surveillance is the 0th application of that ideology.

The big catch with EU is: once you opt in, opting out is very difficult.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#218

Just adding a perspective (not necessarily mine, I'm still on the fence) supporting this legislation from a tech-literate person in the EU. The digital administration in my country has made my life so much easier. We all have mandatory ID cards since decades ago, but now they have a chip with some certs for auth, signing, etc. I can check my taxes, fill government forms, see any traffic tickets, sign official documen…

You should read the letter, it's worse than that. It makes these gov CA's unrejectable, along with providing a means of tracking your activity. Essentially, it's like giving your least trusted eu country access to your browsing history and some of your decrypted traffic. They could have reduced scope, but looking at effects perhaps that's not what they actual want.

It makes these gov CA's unrejectable

That part I understood

along with providing a means of tracking your activity. Essentially, it's like giving your least trusted eu country access to your browsing history and some of your decrypted traffic.

This one though, not quite. Can you explain in layman terms, maybe by means of a practical example, how this would work exactly and what is needed for it?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#219
post #191

Earlier quoted context omitted.

I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process .. I mean, I certainly did not vote for Ursula von der Leyen either.

Your representatives that you voted into parliament did, however.

How would you know, who I voted for?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#220
post #166

Earlier quoted context omitted.

Yes, but: 1. Major browsers (Chrome, Safari, Edge) only accept certificates which are published in Certificate Transparency logs. 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. So it's not really viable to use the existing CA system for MitM attacks. The eIDAS proposal would: 1. Prevent browsers from distrusting CAs which are used in MitM attacks. 2. Ban mandatory…

> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

> 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

Pretty much every browser distrusted the root certificate from Spain's FNMT-RCM for a decade, so I think the answer's yes.

Post reply on HN