Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

261–270 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#262
post #120
post #81

Earlier quoted context omitted.

Yes, because CA level attacks are basically nonexistent and not a very big deal since they require you to control the targets internet connection. The moment people learn that the US government could control a CA and your internet provider to spy on you maybe that will change. But as is people think it is too much work for governments to bother with it.

> Yes, because CA level attacks are basically nonexistent and not a very big deal. I'd call that bs, CA level attacks are very unlikely to be detected, so we know little about their prevalence. (you edited your comment to add... that it requires you to control the targets internet connection?? And "the moment people learn that thenUS government could control (a CA) and your internet provider to spy on you maybe that…

ops I guess I destroyed my comment by mistake, and I can't edit it anymore...

It originally was

* I'd call that bs, CA level attacks are very unlikely to be detected, so we know little about their prevalence.

With tls becoming ubiquitous they're now indispensable*

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#263

It's worth noting that the technical team have a github where issue such as this can be raised. https://github.com/eu-digital-identity-wallet

Why are they hosting this on GitHub and not on EU infrastructure?

1. The EU infrastructure sucks. 2. Reach. Lower the barrier = easier for everyone to contribute.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#264
post #218

Earlier quoted context omitted.

You should read the letter, it's worse than that. It makes these gov CA's unrejectable, along with providing a means of tracking your activity. Essentially, it's like giving your least trusted eu country access to your browsing history and some of your decrypted traffic. They could have reduced scope, but looking at effects perhaps that's not what they actual want.

It makes these gov CA's unrejectable That part I understood along with providing a means of tracking your activity. Essentially, it's like giving your least trusted eu country access to your browsing history and some of your decrypted traffic. This one though, not quite. Can you explain in layman terms, maybe by means of a practical example, how this would work exactly and what is needed for it?

You are sending letters to your friend and getting their replies back in the mail.

You know your government delivers your letters and they could open them and read them, but you trust your government to keep your info private and use this power well.

The current regulation would mean any government can peek at your letters, and even if they got caught peeking or letting their friends read your letters, your mail carrier can't do anything. They aren't even allowed to ban the other governments friend from reading your mail.

If you had a friend who tried to help you write in secret code to avoid these other governments or strangers from reading your mail, they would be risking jail time.

Not only do you have to trust your government, but you must trust every government in the EU and if they get caught misbehaving, nobody can do anything about it.

(Practically, any government can MITM any ssl connection and read or alter things at will.)

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#265
So, the law says browsers have to trust eIDAS keys, but it doesn't say browsers can't complain about it, right?

Like, put the eIDAS keys in a special "signed under protest" trust root, and throw up a bunch of scary warnings about how the EU is forcing Mozilla to trust those keys whenever they are used. Phrase it so that people who think "SSL warning" means "click advanced and 'i know the risks'" understand that this is equivalent to letting the CIA read your text messages.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#266

Does anyone know what the supposed benefits are for this kind of bill? Are proponents overtly advocating for increased surveillance ability?

EU bureaucrats are annoyed that ~100% of the trust decisions are made outside the EU (given that majority of browsers and the trust stores like Microsoft, Android, Java etc., are operated from US). They see it as the issue about the third part of security triade of confidentiality, integrity and availability. In short, they fear that EU company can theoretically be put out of business on a whim of US entity which is unaccountable to EU poeple (by revoking the cert in case of e-commerce, or trust bits in case of CA, or "TSP" as it's called in eIDAS). Hence the prohibition from distrusting certs unless ETSI (which is accountable to EU people) agrees.

Most of the commenters here miss the point, because they concentrate on confidentiality and integrity (cf. any post about MITM). They are of course correct that this creates capability to intercept TLS connections. They still miss the point that EU bureaucrats see it as reasonable tradeoff (which I don't think it is, but that's their POV).

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#267

Earlier quoted context omitted.

Indeed: the goals are justifiable and very much welcome, in my opinion. Yet, I do not understand what CAs and the global TLS/PKI ecosystem have to do with the goals.

> Yet, I do not understand what CAs and the global TLS/PKI ecosystem have to do with the goals. Technically that is also digital signing. The regulators probably thought that all kinds of digital signing should be included in this bill and just slapped something down for browsers while they were at it.

My guess is that someone saw the value (rightly) in being able to do "good" digital signatures on the web (better than docusign in terms of integrity/proof), and that meant (in their head) those certificates have to work in the web browser.

Which, if you don't understand web trust and PKI, means a bit of searching online will tell you that you need your browser to trust the CAs you use for digital signatures.

Which is of course not true - you can (and should) present an "untrusted" (i.e. not a server authentication) certificate as your client certificate or for signatures, as there's different trust bits and use-cases for different kinds of certificates.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#268

Earlier quoted context omitted.

eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…

> eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Did we need laws to "unify" all the standards we successfully use today, like IP, UDP, TCP, HTTP, TLS, Certificate Transparency, HTML, ECMAScript, CSS, DNS, DMARC, DKIM, SSH, etc.? Laws are not the right tool for this. And law makers don't have the necessary expertise.

There are also great many standards we use today that were unified and enforced through laws.

Open any law on produce, construction, cars, industrial equipment (and a million others), and you'll find thousands of specs and standards mandated by law, and for a reason.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#269
post #41

The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…

But the plans were on display…” “On display? I eventually had to go down to the cellar to find them.” “That’s the display department.” “With a flashlight.” “Ah, well, the lights had probably gone.” “So had the stairs.” “But look, you found the notice, didn’t you?” “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Bewa…

It's sad, but this actually happened.

There was an episode of the Mark Thomas Comedy Product where he describes how they were trying to find the spending habits of EU MPs, but they were in a basement with no electronic devices allowed, so they hired an army of students to run up and down with notebooks and pens and relay all the information to more students upstairs who had to type it all up and put it online.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#270
Not just "internet security". There has been discussion that they want to use eIDAS for a lot of things like identification in general and even a health passport.

Consider that last thing. We have this thing called bodily integrity [1], which guarantees everybody has self-ownership regarding their body and thus what can be done with it.

However, in the COVID period, it was clear as day that those who govern us dont give a rats ass about something like bodily integrity and going as far as taking away freedom of movement in order to make people comply with injecting themselves with a - until this very day - experimental vaccine.

Now consider what TPTB could do with a powerful toy like eIDAS.

So no, it is not "just" about internet security. Its about slowly and surely stripping away every human right you have as a EU citizen.

[1] https://en.wikipedia.org/wiki/Bodily_integrity

Post reply on HN