Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

271–280 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#271
post #41

The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…

[deleted]

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#272

Earlier quoted context omitted.

eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…

> eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Did we need laws to "unify" all the standards we successfully use today, like IP, UDP, TCP, HTTP, TLS, Certificate Transparency, HTML, ECMAScript, CSS, DNS, DMARC, DKIM, SSH, etc.? Laws are not the right tool for this. And law makers don't have the necessary expertise.

I think ECMAScript my actually be a counter example, no? Isn't that also governed and funded by the European council?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#273
Could someone link to some actually helpful writeups on eIDAS? The linked article doesn't mention what eIDAS is about, only vague but strongly worded language about it having to be stopped, with no justifications or even what it is.

The comments too are less helpful than usual. A lot FUD and anti-EU sentiment (which may or may not be warranted, but there's very little objective reasoning going on).

Addendum: yes, people could look it up, but given the strong call to action ("last chance to fix eIDAS!"), I would suggest that the onus to provide clear information is on the authors. You can barely get people to care about privacy at all, let alone when so little information is provided.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#274

Earlier quoted context omitted.

> eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Did we need laws to "unify" all the standards we successfully use today, like IP, UDP, TCP, HTTP, TLS, Certificate Transparency, HTML, ECMAScript, CSS, DNS, DMARC, DKIM, SSH, etc.? Laws are not the right tool for this. And law makers don't have the necessary expertise.

I think ECMAScript my actually be a counter example, no? Isn't that also governed and funded by the European council?

There definitely isn't a law mandating Javascript engines to follow the Ecmascript standard, which would be the equivalent of what's happening here.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#275

Not just "internet security". There has been discussion that they want to use eIDAS for a lot of things like identification in general and even a health passport. Consider that last thing. We have this thing called bodily integrity [1], which guarantees everybody has self-ownership regarding their body and thus what can be done with it. However, in the COVID period, it was clear as day that those who govern us dont g…

I'm not sure I understand the point you're trying to make. Few rights are absolute. We, as a society, obviously try to prevent people from harming one another. If you're infected with a dangerous pathogen, and you refuse to do something about it on account of "bodily integrity", you will end up violating other people's bodily integrity by infecting them. That's bad, and it would certainly be within "TPTB"'s rights to stop you.

As for vaccines being "experimental", they have saved many lives, and now that the dust has settled, they seem to have done very little harm.

This all sounds rather like conspiracy nonsense, which isn't to say that eIDAS isn't stupid, but silly conspiracy nonsense like this undermines potential real concerns with eIDAS.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#276
post #134

Earlier quoted context omitted.

> Browsers should get their shit together and add proper support of domain-limited CAs They do in fact support this - e.g. Mozilla trusts KamuSM only for .tr [1], Chrome limited ANSSI to French TLDs [2]. However, there is no indication that the EU would be willing to accept such constraints on their national CAs. If you look at several of the current national European CAs, they routinely issue for generic TLDs like .…

Cool. Domain-limited CAs are a really good idea, and they don't need anything like dynamic downloading of CAA records.

CAA records only apply at the time a certificate is issued, and they only need to be considered by CAs. If the CAA record is changed later, all certificates that have already been issued continue to be valid, even if the new CAA record does not allow the issuing CA anymore. So looking at CAA records would be useless for browsers anyway.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#277

Earlier quoted context omitted.

It's not like Beijing CA can issue a rogue certifcate and suddenly a malicious actor would be able to decrypt all your internet traffic. You would have to connect to a service that uses those certificates in the first place. An interesting experiment would be to log all certificates used by the sites you normally use, say for a month, and then look at the list for anything shady. I have no ideia if an extension exist…

No, that's not needed at all. If the malicious actor can man-in-the-middle traffic to victimsite.com (say using a BGP hijack), they can serve HTTPS traffic to the end user from their MITM server, secured with a certificate issued to "victimsite.com" that is issued by their own CA, and the MITM can then in turn communicate to the real victimsite.com using HTTPS secured by the real site's certificate, signed by its own…

You are correct that no browser is looking at CAA records, because it would be wrong to do so. CAA records don't retroactively revoke certificates that have already been issued. Their only purpose is for CAs to check them before issuing a certificate.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#278
https://archive.ph/Ilhes (because it's a NRD-newly registered domain which my dns-hole blocks)

Also brief info about website (for the ones who doesn't want to visit an unknown domain without knowing):

A Mozilla website for open letter by 300+ cyber security experts, researchers and NGOs.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#279
post #6

India is also preparing legislation for OS and browser having their CA, they also launched their own web browser challenge https://iwbdc.in/ .They were earlier removed due to unauthorised issuances https://pkic.org/2014/07/24/in-the-wake-of-unauthorized-cert...

These are some of the requirements: "Ability to digitally sign documents in the browser using a crypto token" and "Support for Web3". What does that even mean? This is a serious, government-backed competition?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#280
Call it surveillance or whatever. It really isn’t. Trust and power as manifested by modern technology was and should be a reflection of real life trust and power. Historically, human societies’ governing bodies had all the power to exert as they wish on their citizens. Past couple decades were a deviation from this normal, not in the real but in the online world. You could work against the values of your own government without them being able to find and catch you. This legislation is just a correction to the resulting power imbalance, as the online world has increasingly more power on real world.

I think we’ll see the internet and digital ecosystems being segregated into separate parts with boundaries correlating to those of nation-states more and more by the year. As a member of a nation who is not exactly very comfortable with a US-dominant world, I’m all in for it. It’s a national security issue for me. Knowing that some three letter agencies on the other side of the world can surveil me against my rights as per my country’s laws. Or that payment systems (Visa/Mastercard), or Google Maps (you don’t know how vital of a service it is) or satellite internet[1] can stop working if US and her allies determine my time has come.

Developing technologies has a power-centralizing effect, and very often it creates a disadvantage for everyone else who didn’t invent the thing first. Not exactly the world I’d have pictured as a desirable one had I lived 5 centuries ago. Maybe read some Ted Kaczynski?

1: Elon Musk stopped Starlink service in Gaza. They have no communications with the outside world.

Post reply on HN