How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?
Unfortunately the whole world population is addicted to ~5 sites/apps on the web who will play the game. If Debian patches this out, you won't be able to access those sites. That's a living edge case for them.
Last Chance to fix eIDAS: Secret EU law threatens Internet security
31–40 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#32Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#33Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#34I’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?
The EU likes passing internet related legislation because of:
1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that they don't like much, namely successful American companies. The EU loves passing extra-territorial laws and seeing people jump, it makes them feel like a big power bloc which is the whole aim of the EU project to begin with.
2. The revenue from it. Tech companies either fight or they try to obey, but the laws are vague and easily reinterpreted. This yields massive fines which go straight into the EU coffers, money which is then spent on purchasing loyalty both of the elected political elites (via post-election-loss sinecures and enormous "pensions" that start being paid out long before retirement), and the population itself (via EU branded projects and grants).
3. The unaccountability of it. EU law is created by the Commission which does whatever it wants. By treaty it is accountable to nothing except itself and it is the highest power in Europe. In that situation why not spend all your time on easily achieved upper-class luxury agenda items like internet regulation, which feels futuristic and cool, instead of messy stuff that bothers the regular citizens like illegal immigration, where you don't want to do it and failure comes easy?
That's why there's a constant flood of tech-related regulation coming from the EU. Seeing this specific act in isolation is a mistake, it's just the continuation of a long term trend.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#35If certificates issued by those CAs will be tied to independent (from EU) certificate transparency (CT) services and to specific national top-level domains, then I am completely fine with this. After a big number of websites in Russia (including the biggest bank in the country) have effectively lost access to the CA infrastructure used by commonly used browsers, I don't think any honest person can say that the curren…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#36[flagged]
I have no idea if you are right, but calling people liars as the first statement and extensively using capitalisation greatly undermines your message.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#37[flagged]
Annex IV:
Qualified certificates for website authentication shall contain:
(b) a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least the Member State in which that provider is established and:
—
for a legal person: the name and, where applicable, registration number as stated in the official records,
—
for a natural person: the person’s name;
...
(e) the domain name(s) operated by the natural or legal person to whom the certificate is issued;
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#38Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#39Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#40Earlier quoted context omitted.
"The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at e2e.com" That will be (or already is) done at ISP level. It will probably be fully automated, where they just put a court order number into a form, and it automatically just catches all your traffic in gear that's installed at the ISP.
It is only undetectable if the site actually uses the vulnerable certificates. Otherwise you can see that the government is spying on you since the browser tells you what certificate it got (Telling you what certificate was used is a part of eIDAS). There is no way the government will replace certificates like that on an automated basis, it is too easy for people to notice and make a big deal about.
Also, MITMs are a thing and getting the EIDAS certs in the root store will show that the certs in question are trusted, which is all that really matters because there is no way for users to know what certificates were actually installed by the website owner.