Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

241–250 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#242
post #235

Earlier quoted context omitted.

If you're a domain owner monitoring your own domains, a certificate is suspicious if it was not issued by one of the CAs that you use (e.g. you use Let's Encrypt, but you see a certificate for your domain in CT that was issued by Certinomis). If you keep an inventory of all of your certificates, then you can also cross-reference certificates from CT against your inventory, and flag any certificate that isn't in your…

That makes sense, thank you. Follow-up question: presumably, a state actor with dominion or leverage over a CA can coerce said CA into issuing a certificate, right?

Yes, though eventually the state actor would run out of CAs to coerce as all the CAs in their country get distrusted.

The threat of distrust means CAs have a very strong incentive to contest any government orders, since if they comply their business is destroyed.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#243
post #65

Earlier quoted context omitted.

Wow, a lot of those quotes are damning.

Doubt it is a particularly unbiased sample though, so probably not a good idea to draw any strong conclusions from reading it.

“it is a historic mistake to not want to tax at the appropriate levels the profits of multinational companies which act globally and don’t pay the taxes they owe.”

  - Jean-Claude Juncker ...Prime minister of ....Luxembourg

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#244

Earlier quoted context omitted.

The interesting part with the EU is that all policy (proposed and accepted) is actually all organized, findable and out in the open on the internet (and even translated to all official member state languages IIRC)... if you have the mindset of a bureaucrat and know the system. I know because my ex did European Studies and knew how to navigate those websites. I for the life of me cannot figure out how she did it if I…

As someone else said, sounds like an interesting project to scrape, organize, and somehow "re-surface" that data in a much more accessible manner (how? I don't know; I've never done such a project before). Obviously it should be said that such a project shouldn't be needed in the first place in an ideal world, but it does sound like something I might be interested in chipping in regardless (and a great learning oppor…

I am the last person to suggest throwing AI at a random problem, but this actually sounds like a good match for LLM training/prompting...

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#246

Earlier quoted context omitted.

It’s intriguing to observe this phenomena on HN where any posts critical of the EU will get downvoted, even though it is natural for any country or block to try various means to show or enforce its power. And before someone says otherwise, I’ve seen this playing out hundreds of times.

The post was typical anti gov tin foil hat nonsense. You see the same types of posts from people who like camping out on compounds in the mid west complaining about “the feds”

There is nothing about protectionism or a government flexing its power that can be construed as "tin foil hat nonsense" though.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#247

Earlier quoted context omitted.

It is a digital certificate standard. Browser certificates is only a tiny part of it, that wasn't why it was made. Having a standard for digital certificates is a good thing, it makes it easy to switch document signer provider etc since they all are forced to implement the same interface.

>it makes it easy to switch document signer provider etc since they all are forced to implement the same interface. eIDAS was introduced in 2016. Now 7 years later there still isn't a API specification for interoperability (there are drawings though https://blog.eid.as/new-apis-for-the-eidas-ecosystem/ ) In the meantime, any digital signature done in EU must be done with a certificate issued only by the "select" CA t…

Why is that website using a domainhack (with a non-EU ccTLD) rather than a proper .eu domain? Doesn't exactly inspire confidence that these people should have anything to do with security standards.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#248
post #243

Earlier quoted context omitted.

Doubt it is a particularly unbiased sample though, so probably not a good idea to draw any strong conclusions from reading it.

“it is a historic mistake to not want to tax at the appropriate levels the profits of multinational companies which act globally and don’t pay the taxes they owe.” - Jean-Claude Juncker ...Prime minister of ....Luxembourg

Mr LuxLeaks said that eh?

I mean, I'm not saying Juncker is great, just that reading the random collection of quotes on wikiquotes might not be the best way to judge his work.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#249
post #241

People are already self censoring what they really think on social media, this will push people to self censor in private convos. At that point you’ve got to wonder what happens to democracy, when people are afraid to exchange ideas

I think it's what some people are pushing for, how else can the Lisboa treaty be explained? Surely they weren't that short sighted.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#250
post #97

Very concerning. As a slight aside though, it is not a "secret law". All EU laws are published on its website in every official language, and the vast majority of laws (including this one) must be publicly ratified by the directly elected European Parliament before coming effective. They should tone down this kind of sensationalist clickbait that I would expect to find in UK tabloids. They probably think it helps the…

Why can’t Mozilla publish the agreed-upon changes? Are the drafts currently classified? If so, I think it’s okay to bell ring.

I don't think "classified" is the right word, but they haven't been published. They were leaked to various third parties, who got them to Mozilla / EFF / the other folks writing letters of protest today. Those parties haven't published the full text themselves, to protect the identity of the leaker.
Post reply on HN