Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

231–240 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#231
post #223

Earlier quoted context omitted.

Great, very good! Now if you want to standardize encrypted communication, please do it with the help of security researchers, not like this.

Other than this questionable browser CA thing, do you think there are any specific flaws with the crypto system presented in eIDAS.

Alright, so I am not a security researcher so actual security researchers may not share my views. Also, as mentioned in the site, the full text of the new regulation is not public yet. And finally, I have only skimmed whatever text is available given that it's over 100 pages and I skipped over most of the EDIW stuff (it's a really complex system that I can't understand/audit in 20 mins).

But with that out of the way, no I don't have any other complaints, I think the regulation is generally a move in the right direction.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#232

For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/

But it doesn't enable covert surveillance. Even without Certificate Transparency, the change in server certificate is visible to the client. Initiatives like Let's Encrypt could make it visible to server operators, too. The browser UI will present those new qualified certificates and existing certificates differently anyway, so I'm not sure if this is going to work.

The bigger issue is that for this in order to work at all, the regulation must have provisions for issuing fake assertions of existing identities to law enforcement and other security services. The predecessor didn't seem to have that. This is different from providing fake identification documents for undercover operations because as far as I understand it, those use are usually mostly made-up and do not impersonate another person.

We would have to read the actual text of the proposed regulation to know the details, but both sides (legislators and those fueling the outrage machine) do not really want us to form our own opinion and hide the draft text from us.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#233
post #47
post #35

Earlier quoted context omitted.

Re: Russia - SberBank, which is used by the vast majority of population, voluntarily switched to a new Russian government-controlled CA. This move aimed to coerse people to install this CA's cert under false premises and to let the state splice https if needs be. The goal was bloody obvious and it has never been about the "robustness" of infrastructure. They just want to take away people's Internet privacy.

I hope you are simply not familiar with the situation and not FUDing around. The "false premise" was that GlobalSign has refused to issue new certificates for Sberbank and there were several cases of CAs revoking existing certificates. They eventually have found a CA (Harica DV) which was willing to issue new certificates, but it was not clear at the time that such CA will be found and the new certificates can be rev…

Leaving a source for other readers: https://www.bleepingcomputer.com/news/security/russia-create...

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#234
post #213

Earlier quoted context omitted.

> signing official documents like grades from school I have no Earthly idea why a) this needs to be done digitally, or b) for the EU to be involved (at EU level) with this. Unfortunately if you pitch mission creep vs the principle of subsidiarity, the former wins every time.

University grades are standardised already. This is useful because it allows people to work in other countries, digitally signing them prevents fraud. This is just one use case for eIDAS, then you have things like interacting with different government institutions, banks, et cetera, et cetera. There are a lot of people who live in/work/visit other EU countries as is their near absolute right. We should therefore stan…

> University grades are standardised already

... for some value of "standardised"?

UK[0]: First, 2:1, 2:2, Third

Germany[1]: 1 to 5

France[2]: "on a scale from 0-20"

[0] https://www.imperial.ac.uk/students/success-guide/ug/assessm... [1] https://www.uni-passau.de/en/international/coming-to-passau/... [2] https://u-paris.fr/en/higher-education-in-france/

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#235
post #182

Earlier quoted context omitted.

> 1. Is this proactively monitored for? And how? And by whom? Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com ( https://groups.google.com/g/mozilla.dev.security.policy/c/fy... ) and Certinomis issuing for test.com ( https://bugzilla.mozilla.org/show_bug.cgi?id=1496088 ). Both CAs were eventual…

Can you help me intuit what a suspicious certificate might look like in practice?

If you're a domain owner monitoring your own domains, a certificate is suspicious if it was not issued by one of the CAs that you use (e.g. you use Let's Encrypt, but you see a certificate for your domain in CT that was issued by Certinomis). If you keep an inventory of all of your certificates, then you can also cross-reference certificates from CT against your inventory, and flag any certificate that isn't in your inventory.

If you're a security researcher monitoring other people's domains, you have to rely on heuristics - e.g. if a domain has a long history of getting certs from a major US CA, and then suddenly a tiny European CA issues them a certificate, that's pretty suspicious. When I found the example.com certificate misissued by Symantec, I though it was suspicious because it was also valid for subdomains like products.example.com and support.example.com, which don't make sense for a domain that's reserved for documentation purposes. ICANN operates example.com, so I emailed their security team to confirm that they did not authorize the certificate.

The system works best if domain owners are monitoring their own domains, because only they know for sure if a certificate is authorized or not.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#236
post #182

Earlier quoted context omitted.

> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

> 1. Is this proactively monitored for? And how? And by whom? Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com ( https://groups.google.com/g/mozilla.dev.security.policy/c/fy... ) and Certinomis issuing for test.com ( https://bugzilla.mozilla.org/show_bug.cgi?id=1496088 ). Both CAs were eventual…

That's your smoking gun? CAs that issued certificates for example.com and test.com? You genuinely believe that the only possibility here is a vast conspiracy to defraud and steal?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#237

Earlier quoted context omitted.

They'd probably be fined into submission if they don't though.

If it gets to that point, one alternative would be creating some ad-hoc non profits that are on paper not controlled by them (but in practice they are) and then giving up the control of their respective browsers to said non-profits. But it won't get to that point. I don't really think the US government would be ok with a regulation like this, either, and they have even more bargaining power than tech companies.

You think the EU's lawyers will be fooled by a scheme you cooked up in an HN comment?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#238
post #182

Earlier quoted context omitted.

> 1. Is this proactively monitored for? And how? And by whom? Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com ( https://groups.google.com/g/mozilla.dev.security.policy/c/fy... ) and Certinomis issuing for test.com ( https://bugzilla.mozilla.org/show_bug.cgi?id=1496088 ). Both CAs were eventual…

That's your smoking gun? CAs that issued certificates for example.com and test.com? You genuinely believe that the only possibility here is a vast conspiracy to defraud and steal?

> You genuinely believe that the only possibility here is a vast conspiracy to defraud and steal?

Care to point out where I said that?

example.com and test.com are real domains, and their owners did not authorize those certificates to be issued, so issuing them was a serious breach of the trust which CAs are expected to uphold. Furthermore, the discovery of these certificates led to investigations which turned up additional issues which are documented in detail here:

https://wiki.mozilla.org/CA/Symantec_Issues

https://wiki.mozilla.org/CA/Certinomis_Issues

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#239
post #235

Earlier quoted context omitted.

Can you help me intuit what a suspicious certificate might look like in practice?

If you're a domain owner monitoring your own domains, a certificate is suspicious if it was not issued by one of the CAs that you use (e.g. you use Let's Encrypt, but you see a certificate for your domain in CT that was issued by Certinomis). If you keep an inventory of all of your certificates, then you can also cross-reference certificates from CT against your inventory, and flag any certificate that isn't in your…

That makes sense, thank you.

Follow-up question: presumably, a state actor with dominion or leverage over a CA can coerce said CA into issuing a certificate, right?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#240

Earlier quoted context omitted.

But the plans were on display…” “On display? I eventually had to go down to the cellar to find them.” “That’s the display department.” “With a flashlight.” “Ah, well, the lights had probably gone.” “So had the stairs.” “But look, you found the notice, didn’t you?” “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Bewa…

The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system. I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I…

As someone else said, sounds like an interesting project to scrape, organize, and somehow "re-surface" that data in a much more accessible manner (how? I don't know; I've never done such a project before).

Obviously it should be said that such a project shouldn't be needed in the first place in an ideal world, but it does sound like something I might be interested in chipping in regardless (and a great learning opportunity).

Post reply on HN