Live data from Hacker News

Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

eidas-open-letter.org

31–40 of 67 posts

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#31

I had a comment, but I think the tide has passed the point where there is any value or wisdom in speaking against the intelligence agencies.

I would say it's not speaking against the intel agencies. The intelligence community protects us from many threats (terrorists, foreign organized crime, etc.). However, they are human, and make mistakes in the name of self-preservation, zeal for their mission, and in some cases greed.

The intel agencies of different countries act as checks and balances against each other, to some degree. In some countries there are enough different intel agencies that they act as checks and balances against each other.

However, the voice of the public is a great additional check on their behavior, especially when amplified by mainstream media and social media. Our elected officials want to be re-elected. Many will change their tune if they feel there is enough outcry that it might affect their poll numbers. And this is the only legal way to effect change in many countries.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#32

Could we work around this by moving encryption to the application/website layer with client certificates? Please let me know if you see any reason this wouldn't work.

You still have a bootstrapping problem. How do we establish what application-layer signatures are valid when a member state can forge a certificate for any origin at the transport-layer?

Ideally through hardware keys, but I see how that's hard to adopt. It's not entirely unrealistic though in the context of Play Store/App Store for the first download of an app from Google/Apple servers to be protected in transport by hardware keys.

Do the web browsers & operating systems face the same bootstrapping problem at the moment? At some point they must get their first certificate without using a certificate protected connection?

Edit - in the context of service which exists pre regulation, the client certificate could also be derived from the user's existing login credentials.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#33
post #25
post #21

Earlier quoted context omitted.

I can still see taxes and fees when I'm booking a flight. I just checked on delta.com . I can see the total taxes and fees, and the breakdown of what they are and how much each one is. I'm in the US.

I remember HN from over a decade ago: https://www.cntraveler.com/stories/2012-01-31/spirit-airline...

Oh wow, what a way to spin it!

Well, if Spirit Airlines is in fact being ingenuous, then they're -at best- one of the good guys demonstrating Why We Can't Have Nice Things.

What happens is that -in some countries I've visited- people can legally advertise a particular sticker price, and then when you actually go to pay, you pay a very different amount. That threw me for a loop the first time I encountered it. I felt they were being tremendously dishonest.

Where I live, you are totally permitted and encouraged to also provide an itemized price breakdown, but the sticker price is what I'm paying you at the end of the day. No surprises for the consumer.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#34
post #5

Good timing I think to remind you of the upcoming Firefox changes as discussed here https://news.ycombinator.com/item?id=38009663 EDIT: for context

As I commented there, you've misunderstood this change.

There's a difference between certificates distributed with the OS and certificates added to the OS by a user. Right now Firefox ignores both.

This change ONLY picks up the certificates added to the OS by a user. Firefox will continue to ignore the certificates included with the OS store by default.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#35

I had a comment, but I think the tide has passed the point where there is any value or wisdom in speaking against the intelligence agencies.

I would say it's not speaking against the intel agencies. The intelligence community protects us from many threats (terrorists, foreign organized crime, etc.). However, they are human, and make mistakes in the name of self-preservation, zeal for their mission, and in some cases greed. The intel agencies of different countries act as checks and balances against each other, to some degree. In some countries there are e…

Making porn sites KYC is likely something that the public wants. There have been numerous cases of nude pics of minors ending up on "amateur" porn sites.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#36
post #5

Good timing I think to remind you of the upcoming Firefox changes as discussed here https://news.ycombinator.com/item?id=38009663 EDIT: for context

As I commented there, you've misunderstood this change. There's a difference between certificates distributed with the OS and certificates added to the OS by a user. Right now Firefox ignores both. This change ONLY picks up the certificates added to the OS by a user. Firefox will continue to ignore the certificates included with the OS store by default.

Literally in the bugzilla entry is stated either by user or administrator so either you misunderstood or you need to raise this directly to the bug for correction

EDIT: for clarity, something I should have done from the beginning, I checked the affected code, they clearly remove warnings around security.enterprise_roots.enabled preference and enable it by default. This is the preference that was added back in the day to control if the browser will allow root certificates added to the OS no matter the source (user or system context) and now they change it to true by default. I think this provides more clarity but feel free to search the affected code for references that indicate that only part of the root certificate store is trusted

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#38

I had a comment, but I think the tide has passed the point where there is any value or wisdom in speaking against the intelligence agencies.

I would say it's not speaking against the intel agencies. The intelligence community protects us from many threats (terrorists, foreign organized crime, etc.). However, they are human, and make mistakes in the name of self-preservation, zeal for their mission, and in some cases greed. The intel agencies of different countries act as checks and balances against each other, to some degree. In some countries there are e…

> The intelligence community protects us from many threats (terrorists, foreign organized crime, etc.

Do you have any evidence for this?

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#39
post #37
post #3

Dupe from yesterday: Last Chance to fix eIDAS: Secret EU law threatens Internet security - https://news.ycombinator.com/item?id=38109494 - Nov 2023 (280 comments)

That's a related but different page on the same topic

It has the letter literally in the first sentence. Do we need to have a story about ever possible page on this? Of course not.
Post reply on HN