Honest question, so please bear with me. How would an EU government that uses the Internet for servicing its citizens tell those citizens that the site they are accessing to provide very sensitive information is realy the government's and not some other actor's mitm'ed snooping conduit without having control of their own root CA? Is demanding browsers distributed to EU citizens to carry this certificate different fro…
Last Chance to fix eIDAS: Secret EU law threatens Internet security
291–300 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#292India is also preparing legislation for OS and browser having their CA, they also launched their own web browser challenge https://iwbdc.in/ .They were earlier removed due to unauthorised issuances https://pkic.org/2014/07/24/in-the-wake-of-unauthorized-cert...
₹ 3,41,00,000
This brought me to discover the Indian numbering system [1] , another brick on the "localization is hard" wall.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#293Earlier quoted context omitted.
Since you obviously ignorant of how it works. When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs. Of course in the tech industry grades or even whole degrees are generally disregarded but in finance and other fields they of course, are. https://en.wikipedia.org/wiki/ECTS_grading_scale
> When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs https://www.google.com/search?q=%22job+application%22+%22ECT... gets me only a handful of results and a warning that 'It looks like there aren't many great matches for your search' Do (m)any European employers know about this scheme?
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#294Earlier quoted context omitted.
> 2. If a CA is discovered to have issued MitM certificates, they are swiftly distrusted by browsers. Thats reassuring but, not knowing much about this, I have a couple of questions: 1. Is this proactively monitored for? And how? And by whom? 2. If a major state-level CA was discovered to have issued a mitm cert, would browser vendors really take the commercial hit of removing or distrusting their root cert?
> 1. Is this proactively monitored for? And how? And by whom? Yes, security researchers like myself are constantly looking in CT logs for suspicious certificates, and I've found many, most notably Symantec issuing certs for example.com ( https://groups.google.com/g/mozilla.dev.security.policy/c/fy... ) and Certinomis issuing for test.com ( https://bugzilla.mozilla.org/show_bug.cgi?id=1496088 ). Both CAs were eventual…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#295Earlier quoted context omitted.
Since you obviously ignorant of how it works. When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs. Of course in the tech industry grades or even whole degrees are generally disregarded but in finance and other fields they of course, are. https://en.wikipedia.org/wiki/ECTS_grading_scale
> When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs https://www.google.com/search?q=%22job+application%22+%22ECT... gets me only a handful of results and a warning that 'It looks like there aren't many great matches for your search' Do (m)any European employers know about this scheme?
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#296Honest question, so please bear with me. How would an EU government that uses the Internet for servicing its citizens tell those citizens that the site they are accessing to provide very sensitive information is realy the government's and not some other actor's mitm'ed snooping conduit without having control of their own root CA? Is demanding browsers distributed to EU citizens to carry this certificate different fro…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#297For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes. [1] https://notes.valdikss.org.ru/jabber.ru-mitm/
eIDAS exists since there are many conflicting standards for electronic certificates. eIDAS is an effort to unify those standards. Maybe the clause where they say browsers has to add specific CA's is for spying, but eIDAS in general isn't to help spying its just there to help unify all the different electronic certificate services in EU. For example banking, signing official documents like grades from school etc, all…
This Trusted CA is such a lie. I mean we all know that Google, MS etc does ugly things with user data but apparently we have no objection to trust them with cryptography.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#298So, the law says browsers have to trust eIDAS keys, but it doesn't say browsers can't complain about it, right? Like, put the eIDAS keys in a special "signed under protest" trust root, and throw up a bunch of scary warnings about how the EU is forcing Mozilla to trust those keys whenever they are used. Phrase it so that people who think "SSL warning" means "click advanced and 'i know the risks'" understand that this…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#299Earlier quoted context omitted.
How do you ban a FOSS?
You criminalize the platform where it's published. The laws for that have been conjured in 2018.
While they could legally do that, it's going to blow up in their face if they did it. I remember the old crypto export wars in the US and OpenBSD being based in Canada so they could ship string crypto in SSH.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#300So, the law says browsers have to trust eIDAS keys, but it doesn't say browsers can't complain about it, right? Like, put the eIDAS keys in a special "signed under protest" trust root, and throw up a bunch of scary warnings about how the EU is forcing Mozilla to trust those keys whenever they are used. Phrase it so that people who think "SSL warning" means "click advanced and 'i know the risks'" understand that this…
From Mozilla's post: The text goes on to ban browsers from applying security checks to these EU keys and certificates except those pre-approved by the EU’s IT standards body - ETSI.