Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

251–260 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#251
post #125

Earlier quoted context omitted.

The enforcement mechanism is to warn and then ban non-compliant. There are just too few playeds in the field here. It would take only two major browser development companies to make the world 99% compliant. And the rest is statistical error no matter how safe and secure they are.

How do you ban a FOSS?

You criminalize the platform where it's published. The laws for that have been conjured in 2018.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#253

For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/

But it doesn't enable covert surveillance. Even without Certificate Transparency, the change in server certificate is visible to the client. Initiatives like Let's Encrypt could make it visible to server operators, too. The browser UI will present those new qualified certificates and existing certificates differently anyway, so I'm not sure if this is going to work. The bigger issue is that for this in order to work…

Unfortunately this isn't how it works in practice.

Changes to server certificates happen all the time -- every 60 days or so, if you're getting certs from Let's Encrypt. Browsers can't tell their users every time a certificate changes because the users will just get notification-blindness and be trained to click past the warnings.

Let's Encrypt doesn't help server operators see this; I really not sure what you mean by that. Certificate Transparency would help server operators see this, but the new law text forbids browsers from requiring CT for these certs!

The law doesn't have to solve the problem of how security services will assert fake identities. Each member state can solve that internally. Allegedly, given the recent report of a hijack against jabber.ru and xmpp.ru, they already have. The problem is that, when they do, no one else has any recourse. No other member state can say "hey, don't hijack my websites!", no citizen can say "hey, don't hijack my traffic!", and no browser can say "hey, you issued a false certificate, we don't trust you anymore!".

Fundamentally, the whole issue with eIDAS comes down to one thing: you cannot mandate trust. By definition. If it's mandated, it isn't trust, it's something else. By mandating that browsers "trust" certain CAs, they're breaking the entire trust model of the internet.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#254
Fundamentally, the whole issue with eIDAS comes down to one thing: you cannot mandate trust.

If it's mandated, it isn't trust. It's something else. By mandating that browsers "trust" certain CAs, they're breaking the entire trust model of the internet.

My only question is whether they truly don't understand this, do understand it but don't care, or are actively interested in destroying that trust.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#255
post #242

Earlier quoted context omitted.

That makes sense, thank you. Follow-up question: presumably, a state actor with dominion or leverage over a CA can coerce said CA into issuing a certificate, right?

Yes, though eventually the state actor would run out of CAs to coerce as all the CAs in their country get distrusted. The threat of distrust means CAs have a very strong incentive to contest any government orders, since if they comply their business is destroyed.

That tracks. Thanks for helping me get a bead on this!

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#256

Earlier quoted context omitted.

> manually distrusting might be considered illegal It is just a display change, all the law says is: "For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner." I don't see how adding a warning icon or block icon instead of the lock hurts would be banned. To me it seems like so much here is based on baseless assumptions.

No, manually distrusting will probably be considered illegal. "Browsers shall ensure", no exceptions: https://news.ycombinator.com/item?id=38109691 I would also urge you to refrain from using terminology such as "baseless assumptions" when your own assumptions are so easily refuted by directly reading the text of the proposal.

I as an user decide what is user friendly to me.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#257
post #34
post #7

I’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?

Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…

Laws are not created by the commission. Laws can be proposed by the commission, but must pass an unanimous vote by the council (made up of a representative of the government of every country) and pass a qualified majority vote in the EU parliament.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#258
post #191

Earlier quoted context omitted.

I think the worst part is, that most governments work like this, but only some can dare to speak about it in the open. Now why could Juncker speak so open? Probably because he is quite disconnected from the democratic election process .. I mean, I certainly did not vote for Ursula von der Leyen either.

Your representatives that you voted into parliament did, however.

Von der Leyen is President of the European Council. The parliament had nothing to do with it.

The council is made up of the prime ministers of the EU member countries, which also were not voted for seats in the EC.

Likewise there was no vote on the Lisboa treaty which effectively put the EC above the parliament and outside its jurisdiction.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#259
post #34

Earlier quoted context omitted.

Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…

Laws are not created by the commission. Laws can be proposed by the commission, but must pass an unanimous vote by the council (made up of a representative of the government of every country) and pass a qualified majority vote in the EU parliament.

The council also uses qualified majority voting and has done for nearly a decade.

The Commission is the sole source of legislation. The Council cannot change EU law against the will of the Commission, so in practice it's a rubber stamp body that just always votes yes to everything.

This is what I'm saying in another comment: HN is flooded with incorrect claims about how the EU actually works, always in the direction of making it sound more accountable than it actually is.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#260
Does someone else think it's an extreme coincidence that we have Chat Control and now this in place? Pretty sure the negotiations around Chat Control revolve on this eIDAS being approved, that way you don't "undermine" encryption because, well, you have the keys to decrypt everything.
Post reply on HN