Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

221–230 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#221
post #41

The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…

"When it becomes serious, you have to lie'"

    - Jean-Claude Juncker

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#222

Candid question : if this is european legislation, how browser editor would handle this regional specific requirement ? Provide several flavor of their browser ? I doubt people and companies from outside europe would agree to use a european flavored version of their browser.

In the past, browsers needed to have "export-grade cryptography", because the USA considered ciphers a weapon, thus subject to export rescriction. And this ended up playing a crucial role in downgrade attacks later on. So I would say yes, they already had to handle a similar situation in the past.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#223
post #213

Earlier quoted context omitted.

University grades are standardised already. This is useful because it allows people to work in other countries, digitally signing them prevents fraud. This is just one use case for eIDAS, then you have things like interacting with different government institutions, banks, et cetera, et cetera. There are a lot of people who live in/work/visit other EU countries as is their near absolute right. We should therefore stan…

Great, very good! Now if you want to standardize encrypted communication, please do it with the help of security researchers, not like this.

Other than this questionable browser CA thing, do you think there are any specific flaws with the crypto system presented in eIDAS.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#224
post #211
post #206

Earlier quoted context omitted.

She was nominated by the European Council (=Heads of gov't of EU countries) because the EU parliament is a divided mess and the leading parties have no internal cohesion whatsoever. Parties at the european level are disparate coalitions between national parties and MEPs follow the national party line. The decision was made by national governments and rubber-stamped by the parliament. This is fundamentally different f…

Having a prominent MP leader like that is one of my second least favorite part of parliamentary governments[1]. Politics and governance aren't so simple that one person will ever be found that fairly represents the majority of the populace because the majority of the populace can't agree on multiple things. It's better for the majority of the power in governments to be devolved down to MPs voting on matters with the…

> We're a people with a wide spectrum of beliefs - we should be represented by a wide spectrum of MPs... never by a single voice.

This is a fair statement. I'm not from the EU but I think it's true for basically any society. Also a lot of the dysfunction in the EU is obviously by design and it's supposed to instill cooperation and deliberation between different stakeholders.

Still, in politics "getting things done" is very important, imo much more important than representation because the main job of a government is to govern and a fairly balanced government that fails to govern will lose support very quickly and become unrepresentative/useless. Also if someone can't get things done, others will do it and force their hand, like the case of the election of the EU commission president. Or practically everything the UN does.

The good thing about a government by a single party or a well defined coalition is that you know what they roughly stand for, what they don't stand for, who is for them and who is against. You can support them or vote against them. In an election one side wins. Being an incumbent is difficult so in the next the other side wins, they are supposed to balance each other that way.

What is the alternative of a de facto coalition between the right, center-left and liberals? Which of these is really in power? Who are you going to vote for if you don't like where the things are headed?

Looking at the EU parliament (or the parliaments of many EU countries) the main alternatives are fascism-lite and actual fascism. That's the risk of plethoric supranational governing bodies like the EU or very large coalition governments, they rob people of viable democratic alternatives.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#225
Maybe LLms can help people more effectively engage with their political representatives on topics like this.

I’m increasingly convinced that this type of legislation will continue to proliferate until legislation banning it is not pushed for and put in place.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#226
post #78

Earlier quoted context omitted.

It got downvoted since it says this regulation isn't made to spy on people. People want to believe it was made for a sinister purpose and not just due to naivete. If you look around you see plenty of people that gets upvoted and are critical of EU, so that isn't it.

We had a recent MITM on jabber.ru[1] conducted by Germany, a EU state that was only detected because they failed to renew the MITM cert. I have no reason to believe making this easier isn’t one of the goals of EIDAS. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/

How can you make this any easier? The ergonomics of letsencrypt are probably better than anything the EU could come up with.

Fair chance they'll just keep using letsencrypt.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#227

To protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?

That's illegal then. But the pihole won't do the trick, you need to remove the mandated certs from your browsers certstore. If these certs are used for legitimate places (e.g. EU or state websites, and I'll bet they will) you then will get a certificate error. Of course there is still HSTS, but that's not supported by all tech using TLS.

> If these certs are used for legitimate places (e.g. EU or state websites, and I'll bet they will) you then will get a certificate error.

Prediction: If this passes, users having to bypass cert errors will be the new cookie popup.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#228

Earlier quoted context omitted.

But the plans were on display…” “On display? I eventually had to go down to the cellar to find them.” “That’s the display department.” “With a flashlight.” “Ah, well, the lights had probably gone.” “So had the stairs.” “But look, you found the notice, didn’t you?” “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Bewa…

The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system. I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I…

Sounds like it might be a good web-scraping project for a civic-minded group or individual: scrape the sites, unify and organize them into something more approachable and discoverable.

I know in the US we have orgs like Code for America and events like National Day of Civic Hacking. Does the EU have similar groups and events? I wonder if this could be presented to something like that.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#229
post #182

Earlier quoted context omitted.

> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

> 1. Is this proactively monitored for? And how? And by whom? Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com ( https://groups.google.com/g/mozilla.dev.security.policy/c/fy... ) and Certinomis issuing for test.com ( https://bugzilla.mozilla.org/show_bug.cgi?id=1496088 ). Both CAs were eventual…

Can you help me intuit what a suspicious certificate might look like in practice?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#230
post #224
post #211

Earlier quoted context omitted.

Having a prominent MP leader like that is one of my second least favorite part of parliamentary governments[1]. Politics and governance aren't so simple that one person will ever be found that fairly represents the majority of the populace because the majority of the populace can't agree on multiple things. It's better for the majority of the power in governments to be devolved down to MPs voting on matters with the…

> We're a people with a wide spectrum of beliefs - we should be represented by a wide spectrum of MPs... never by a single voice. This is a fair statement. I'm not from the EU but I think it's true for basically any society. Also a lot of the dysfunction in the EU is obviously by design and it's supposed to instill cooperation and deliberation between different stakeholders. Still, in politics "getting things done" i…

I think you pointed the defining aspect here. Having many opinions is inefficient but representative. Having one winner is efficient but lopsided. You can't have the cake and eat it, so each society had to decide which way (and revisit the decision over time).
Post reply on HN