Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

291–300 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#291

Honest question, so please bear with me. How would an EU government that uses the Internet for servicing its citizens tell those citizens that the site they are accessing to provide very sensitive information is realy the government's and not some other actor's mitm'ed snooping conduit without having control of their own root CA? Is demanding browsers distributed to EU citizens to carry this certificate different fro…

Certificate Transparency Lists - and from what I understand, the EU does not want its CAs to publish such a list, and here lies the problem.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#292
post #6

India is also preparing legislation for OS and browser having their CA, they also launched their own web browser challenge https://iwbdc.in/ .They were earlier removed due to unauthorised issuances https://pkic.org/2014/07/24/in-the-wake-of-unauthorized-cert...

While reading the site, I wondered what is this format?

₹ 3,41,00,000

This brought me to discover the Indian numbering system [1] , another brick on the "localization is hard" wall.

https://en.m.wikipedia.org/wiki/Indian_numbering_system

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#293
post #287

Earlier quoted context omitted.

Since you obviously ignorant of how it works. When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs. Of course in the tech industry grades or even whole degrees are generally disregarded but in finance and other fields they of course, are. https://en.wikipedia.org/wiki/ECTS_grading_scale

> When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs https://www.google.com/search?q=%22job+application%22+%22ECT... gets me only a handful of results and a warning that 'It looks like there aren't many great matches for your search' Do (m)any European employers know about this scheme?

The diploma comes with an explanatory supplement (at least mine does), so employers don't really need to know about it, they just need to read (and maybe they won't do that).

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#294
post #182

Earlier quoted context omitted.

> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?

> 1. Is this proactively monitored for? And how? And by whom? Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com ( https://groups.google.com/g/mozilla.dev.security.policy/c/fy... ) and Certinomis issuing for test.com ( https://bugzilla.mozilla.org/show_bug.cgi?id=1496088 ). Both CAs were eventual…

It looks like the Symantec distrusting was done with the cooperation of Symantec, which agreed to wind things down and transfer clients to a new provider in an orderly fashion?

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#295
post #287

Earlier quoted context omitted.

Since you obviously ignorant of how it works. When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs. Of course in the tech industry grades or even whole degrees are generally disregarded but in finance and other fields they of course, are. https://en.wikipedia.org/wiki/ECTS_grading_scale

> When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs https://www.google.com/search?q=%22job+application%22+%22ECT... gets me only a handful of results and a warning that 'It looks like there aren't many great matches for your search' Do (m)any European employers know about this scheme?

Job applications in Europe typically list a degree that is required, rarely the score that an applicant is expected to have received. Nonetheless, ECTS scoring is nowadays awarded to every degree that is obtained in a country that is a signatory to the Bologna accord. To answer your question, it is an established standard.

https://en.wikipedia.org/wiki/Bologna_Process#Signatories

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#296

Honest question, so please bear with me. How would an EU government that uses the Internet for servicing its citizens tell those citizens that the site they are accessing to provide very sensitive information is realy the government's and not some other actor's mitm'ed snooping conduit without having control of their own root CA? Is demanding browsers distributed to EU citizens to carry this certificate different fro…

The first priority is ensuring citizens can answer, "how can I make sure my government isn't spying on me", to their satisfaction, and then they might start caring about the government's use-case/pretext.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#297

For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/

eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…

> since unlike browsers there is no list of trusted CAs,

This Trusted CA is such a lie. I mean we all know that Google, MS etc does ugly things with user data but apparently we have no objection to trust them with cryptography.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#298

So, the law says browsers have to trust eIDAS keys, but it doesn't say browsers can't complain about it, right? Like, put the eIDAS keys in a special "signed under protest" trust root, and throw up a bunch of scary warnings about how the EU is forcing Mozilla to trust those keys whenever they are used. Phrase it so that people who think "SSL warning" means "click advanced and 'i know the risks'" understand that this…

From Mozilla's post: The text goes on to ban browsers from applying security checks to these EU keys and certificates except those pre-approved by the EU’s IT standards body - ETSI.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#299

Earlier quoted context omitted.

How do you ban a FOSS?

You criminalize the platform where it's published. The laws for that have been conjured in 2018.

The second they do that the entire internet is going to download it to see what the fuss is about.

While they could legally do that, it's going to blow up in their face if they did it. I remember the old crypto export wars in the US and OpenBSD being based in Canada so they could ship string crypto in SSH.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#300

So, the law says browsers have to trust eIDAS keys, but it doesn't say browsers can't complain about it, right? Like, put the eIDAS keys in a special "signed under protest" trust root, and throw up a bunch of scary warnings about how the EU is forcing Mozilla to trust those keys whenever they are used. Phrase it so that people who think "SSL warning" means "click advanced and 'i know the risks'" understand that this…

From Mozilla's post: The text goes on to ban browsers from applying security checks to these EU keys and certificates except those pre-approved by the EU’s IT standards body - ETSI.

It's not a "security check" it's just informing the user about their certs...
Post reply on HN