Earlier quoted context omitted.
The enforcement mechanism is to warn and then ban non-compliant. There are just too few playeds in the field here. It would take only two major browser development companies to make the world 99% compliant. And the rest is statistical error no matter how safe and secure they are.
How do you ban a FOSS?
Last Chance to fix eIDAS: Secret EU law threatens Internet security
251–260 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#252It's worth noting that the technical team have a github where issue such as this can be raised. https://github.com/eu-digital-identity-wallet
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#253For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/
But it doesn't enable covert surveillance. Even without Certificate Transparency, the change in server certificate is visible to the client. Initiatives like Let's Encrypt could make it visible to server operators, too. The browser UI will present those new qualified certificates and existing certificates differently anyway, so I'm not sure if this is going to work. The bigger issue is that for this in order to work…
Changes to server certificates happen all the time -- every 60 days or so, if you're getting certs from Let's Encrypt. Browsers can't tell their users every time a certificate changes because the users will just get notification-blindness and be trained to click past the warnings.
Let's Encrypt doesn't help server operators see this; I really not sure what you mean by that. Certificate Transparency would help server operators see this, but the new law text forbids browsers from requiring CT for these certs!
The law doesn't have to solve the problem of how security services will assert fake identities. Each member state can solve that internally. Allegedly, given the recent report of a hijack against jabber.ru and xmpp.ru, they already have. The problem is that, when they do, no one else has any recourse. No other member state can say "hey, don't hijack my websites!", no citizen can say "hey, don't hijack my traffic!", and no browser can say "hey, you issued a false certificate, we don't trust you anymore!".
Fundamentally, the whole issue with eIDAS comes down to one thing: you cannot mandate trust. By definition. If it's mandated, it isn't trust, it's something else. By mandating that browsers "trust" certain CAs, they're breaking the entire trust model of the internet.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#254If it's mandated, it isn't trust. It's something else. By mandating that browsers "trust" certain CAs, they're breaking the entire trust model of the internet.
My only question is whether they truly don't understand this, do understand it but don't care, or are actively interested in destroying that trust.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#255Earlier quoted context omitted.
That makes sense, thank you. Follow-up question: presumably, a state actor with dominion or leverage over a CA can coerce said CA into issuing a certificate, right?
Yes, though eventually the state actor would run out of CAs to coerce as all the CAs in their country get distrusted. The threat of distrust means CAs have a very strong incentive to contest any government orders, since if they comply their business is destroyed.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#256Earlier quoted context omitted.
> manually distrusting might be considered illegal It is just a display change, all the law says is: "For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner." I don't see how adding a warning icon or block icon instead of the lock hurts would be banned. To me it seems like so much here is based on baseless assumptions.
No, manually distrusting will probably be considered illegal. "Browsers shall ensure", no exceptions: https://news.ycombinator.com/item?id=38109691 I would also urge you to refrain from using terminology such as "baseless assumptions" when your own assumptions are so easily refuted by directly reading the text of the proposal.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#257I’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?
Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#258Earlier quoted context omitted.
I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process .. I mean, I certainly did not vote for Ursula von der Leyen either.
Your representatives that you voted into parliament did, however.
The council is made up of the prime ministers of the EU member countries, which also were not voted for seats in the EC.
Likewise there was no vote on the Lisboa treaty which effectively put the EC above the parliament and outside its jurisdiction.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#259Earlier quoted context omitted.
Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…
Laws are not created by the commission. Laws can be proposed by the commission, but must pass an unanimous vote by the council (made up of a representative of the government of every country) and pass a qualified majority vote in the EU parliament.
The Commission is the sole source of legislation. The Council cannot change EU law against the will of the Commission, so in practice it's a rubber stamp body that just always votes yes to everything.
This is what I'm saying in another comment: HN is flooded with incorrect claims about how the EU actually works, always in the direction of making it sound more accountable than it actually is.