Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

281–290 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#281
post #153
post #132

Earlier quoted context omitted.

As I understand it, the EU Parliament engages through the trilogues. Once agreement has been reached there, final approval is indeed more of a rubberstamp. (But: I'm just somewhat interested in the subject; I'm not an expert on the process.)

Once an agreement has been reached, the Parliament can still reject the proposed law (which can easily happen because a conciliatory committee does not represent all the factions in parliament and of course public outcry/petitions can change opinions).

You’re conflating two things. Yes, the EP CAN reject. In practice, it rarely ever DOES.

How the democratic process actually works is important. Public outcry often happens after something becomes LOCAL law (i.e. a few years or months down the road) implemented in a member state. The usual defense from EU-enthusiasts is then “you should have engaged in public debate, it’s too late now”. That should tell you something about the visibility and publicity of the process.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#282
post #242

Earlier quoted context omitted.

That makes sense, thank you. Follow-up question: presumably, a state actor with dominion or leverage over a CA can coerce said CA into issuing a certificate, right?

Yes, though eventually the state actor would run out of CAs to coerce as all the CAs in their country get distrusted. The threat of distrust means CAs have a very strong incentive to contest any government orders, since if they comply their business is destroyed.

In some very prominent countries there are laws with extreme consequences which not only prevent companies from contesting and not complying, but even prevent them ever disclosing such requests.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#283
Honest question, so please bear with me.

How would an EU government that uses the Internet for servicing its citizens tell those citizens that the site they are accessing to provide very sensitive information is realy the government's and not some other actor's mitm'ed snooping conduit without having control of their own root CA?

Is demanding browsers distributed to EU citizens to carry this certificate different from demanding phone companies to route emergency service numbers correctly?

Ofc I can see the 'dark' potential for a mandated cert. Is this realy different from current browsers ubiquitously storing trusted root certificates from CA's issued by private companies residing in states with very serious compelled secret goverment access laws and regulations?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#284
post #218

Earlier quoted context omitted.

It makes these gov CA's unrejectable That part I understood along with providing a means of tracking your activity. Essentially, it's like giving your least trusted eu country access to your browsing history and some of your decrypted traffic. This one though, not quite. Can you explain in layman terms, maybe by means of a practical example, how this would work exactly and what is needed for it?

You are sending letters to your friend and getting their replies back in the mail. You know your government delivers your letters and they could open them and read them, but you trust your government to keep your info private and use this power well. The current regulation would mean any government can peek at your letters, and even if they got caught peeking or letting their friends read your letters, your mail carr…

Thanks, but I wasn't actually looking for an analogy. I'm trying to understand things like how the government (or whatever actor) would gain access to browser history via a MITM attack for instance.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#285

Call it surveillance or whatever. It really isn’t. Trust and power as manifested by modern technology was and should be a reflection of real life trust and power. Historically, human societies’ governing bodies had all the power to exert as they wish on their citizens. Past couple decades were a deviation from this normal, not in the real but in the online world. You could work against the values of your own governme…

Where'd you get this idea of starlink in Gaza

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#286
post #242

Earlier quoted context omitted.

Yes, though eventually the state actor would run out of CAs to coerce as all the CAs in their country get distrusted. The threat of distrust means CAs have a very strong incentive to contest any government orders, since if they comply their business is destroyed.

In some very prominent countries there are laws with extreme consequences which not only prevent companies from contesting and not complying, but even prevent them ever disclosing such requests.

True, but then they will be found out and distrusted. So basically they'll lose business because of the government of the country they are established in.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#287
post #213

Earlier quoted context omitted.

University grades are standardised already. This is useful because it allows people to work in other countries, digitally signing them prevents fraud. This is just one use case for eIDAS, then you have things like interacting with different government institutions, banks, et cetera, et cetera. There are a lot of people who live in/work/visit other EU countries as is their near absolute right. We should therefore stan…

> University grades are standardised already ... for some value of "standardised"? UK[0]: First, 2:1, 2:2, Third Germany[1]: 1 to 5 France[2]: "on a scale from 0-20" [0] https://www.imperial.ac.uk/students/success-guide/ug/assessm... [1] https://www.uni-passau.de/en/international/coming-to-passau/... [2] https://u-paris.fr/en/higher-education-in-france/

Since you obviously ignorant of how it works. When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs. Of course in the tech industry grades or even whole degrees are generally disregarded but in finance and other fields they of course, are.

https://en.wikipedia.org/wiki/ECTS_grading_scale

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#288
post #287

Earlier quoted context omitted.

> University grades are standardised already ... for some value of "standardised"? UK[0]: First, 2:1, 2:2, Third Germany[1]: 1 to 5 France[2]: "on a scale from 0-20" [0] https://www.imperial.ac.uk/students/success-guide/ug/assessm... [1] https://www.uni-passau.de/en/international/coming-to-passau/... [2] https://u-paris.fr/en/higher-education-in-france/

Since you obviously ignorant of how it works. When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs. Of course in the tech industry grades or even whole degrees are generally disregarded but in finance and other fields they of course, are. https://en.wikipedia.org/wiki/ECTS_grading_scale

> When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs

https://www.google.com/search?q=%22job+application%22+%22ECT... gets me only a handful of results and a warning that 'It looks like there aren't many great matches for your search'

Do (m)any European employers know about this scheme?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#289

From: https://data.consilium.europa.eu/doc/document/ST-14959-2022-... Article 45(2): "Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certific…

What they should do is to create an EU CA and all countries to have subordinate CAs. Then you only have to have one CA added to the browser list that ca be added/removed at will or only added when interacting with the government and then removed from the browser.

For non-tech people I am pretty sure someone could write a program that does this automatically - like two buttons, one saying you need to access the government and another that says you don't want to access the government anymore.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#290
post #284

Earlier quoted context omitted.

You are sending letters to your friend and getting their replies back in the mail. You know your government delivers your letters and they could open them and read them, but you trust your government to keep your info private and use this power well. The current regulation would mean any government can peek at your letters, and even if they got caught peeking or letting their friends read your letters, your mail carr…

Thanks, but I wasn't actually looking for an analogy. I'm trying to understand things like how the government (or whatever actor) would gain access to browser history via a MITM attack for instance.

They wouldn't gain access to previous browser history, but as soon as they issue a certificate for a website they can get ISPs to use that certificate for MITM.
Post reply on HN