Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

31–40 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#31
post #28

How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?

Unfortunately the whole world population is addicted to ~5 sites/apps on the web who will play the game. If Debian patches this out, you won't be able to access those sites. That's a living edge case for them.

I think the right way of dealing with this is to have a button to switch between secure mode and insecure/government mode.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#32

Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.

I guess this is where client attestation comes into play.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#34
post #7

I’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?

Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU.

The EU likes passing internet related legislation because of:

1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that they don't like much, namely successful American companies. The EU loves passing extra-territorial laws and seeing people jump, it makes them feel like a big power bloc which is the whole aim of the EU project to begin with.

2. The revenue from it. Tech companies either fight or they try to obey, but the laws are vague and easily reinterpreted. This yields massive fines which go straight into the EU coffers, money which is then spent on purchasing loyalty both of the elected political elites (via post-election-loss sinecures and enormous "pensions" that start being paid out long before retirement), and the population itself (via EU branded projects and grants).

3. The unaccountability of it. EU law is created by the Commission which does whatever it wants. By treaty it is accountable to nothing except itself and it is the highest power in Europe. In that situation why not spend all your time on easily achieved upper-class luxury agenda items like internet regulation, which feels futuristic and cool, instead of messy stuff that bothers the regular citizens like illegal immigration, where you don't want to do it and failure comes easy?

That's why there's a constant flood of tech-related regulation coming from the EU. Seeing this specific act in isolation is a mistake, it's just the continuation of a long term trend.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#35
post #17

If certificates issued by those CAs will be tied to independent (from EU) certificate transparency (CT) services and to specific national top-level domains, then I am completely fine with this. After a big number of websites in Russia (including the biggest bank in the country) have effectively lost access to the CA infrastructure used by commonly used browsers, I don't think any honest person can say that the curren…

Re: Russia - SberBank, which is used by the vast majority of population, voluntarily switched to a new Russian government-controlled CA. This move aimed to coerse people to install this CA's cert under false premises and to let the state splice https if needs be. The goal was bloody obvious and it has never been about the "robustness" of infrastructure. They just want to take away people's Internet privacy.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#36
post #29

[flagged]

I have no idea if you are right, but calling people liars as the first statement and extensively using capitalisation greatly undermines your message.

He might be right. Browsers come with CAs from EU states (or agencies controlled by states) for the last 10 years (at least). I work for a public admin in Spain and our site uses one of such CAs and browsers accept it without problems. So I believe that eIDAS has to do with personal identification rather than TLS.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#37

[flagged]

It's not. Read the documents linked to from the article. The law clearly refers to certificates with domain names in them, not client certificates. Actually the bigger impact of this seems to be that you wouldn't be able to host websites anonymously anymore, making WHOIS privacy meaningless, because the law appears to mandate that all certificates contain legal identities in them.

Annex IV:

Qualified certificates for website authentication shall contain:

(b) a set of data unambiguously representing the qualified trust service provider issuing the qualified certificates including at least the Member State in which that provider is established and:

for a legal person: the name and, where applicable, registration number as stated in the official records,

for a natural person: the person’s name;

...

(e) the domain name(s) operated by the natural or legal person to whom the certificate is issued;

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#40
post #26
post #21

Earlier quoted context omitted.

"The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at e2e.com" That will be (or already is) done at ISP level. It will probably be fully automated, where they just put a court order number into a form, and it automatically just catches all your traffic in gear that's installed at the ISP.

It is only undetectable if the site actually uses the vulnerable certificates. Otherwise you can see that the government is spying on you since the browser tells you what certificate it got (Telling you what certificate was used is a part of eIDAS). There is no way the government will replace certificates like that on an automated basis, it is too easy for people to notice and make a big deal about.

If a nonprofit like Let’s Encrypt can perform automated certificate renewal with a few API calls, so can the government.

Also, MITMs are a thing and getting the EIDAS certs in the root store will show that the certs in question are trusted, which is all that really matters because there is no way for users to know what certificates were actually installed by the website owner.

Post reply on HN