Live data from Hacker News

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

theregister.com

31–40 of 73 posts

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#31
post #7

I remember the good old days when everything was HTTP. Anyways, this is really only an issue for those who has an innate distrust in their government, something most EU citizens don't have.

I'm always genuinely confused when similar arguments come up related to privacy. Governments invading its citizens' privacy is always a problem.

They may have good intentions today, but politicians and intentions can change while the new government powers are likely never removed.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#32
post #17
post #4

This is insane, and we should hurry up and prepare the technical ways to ensure we know it if we are served a different cert than everybody else. There's ongoing work on this field, but it is now a priority to have it ready.

It exists and works already: Certificate Transparency logs, HSTS and Cert Pinning are “protecting”. The first may have the side-effect (or intended ?) to inform US companies which websites you are visiting upon addition of new entries though…

Yes, the problem is that apparently this would outlaw it.

Incidentally there a very similar sounding provision announced in the UK yesterday:

'make tech companies clear security features with the Home Office'

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#33
This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI.

Do you seriously think the intent here is to allow, say, Italy to issue a certificate and spying on german citizens? Or maybe it is to make sure italian citizens (regardless of browser vendor) can access the social security website without getting a scary warning message?

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#34
post #18

>This enables the government of any EU member state to issue website certificates for interception and surveillance Wouldn't this be very easy to identify?

The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the help of ISPs etc).

How would they get the private key? Or would this CA only allow using certs with private keys they generated instead of using CSRs?

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#35
post #8

Earlier quoted context omitted.

>innate distrust in their government, something most EU citizens don't have Was that a joke?

It must be sarcasm. In reality, people don’t have the time to read up on these issues to build an opinion in the first place. The most potent media corporations that could’ve amplified this issue for the general public are effectively propaganda machines for whoever pays the most or has the biggest guns to their heads. It’s a sad state of affairs. Most of the public are unaware that a cage is being built around them.…

> It’s a sad state of affairs. Most of the public are unaware that a cage is being built around them.

Plenty of people want the cage. I don't mean that disparagingly but don't know how else to put it.

Life is hard and can be scary, there are a lot of people who would rather have a cage with someone else in charge than deal with it themselves.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#36
Useful other side discussion here: https://news.ycombinator.com/item?id=38187479

Important to note is that the main thing everyone is up in arms about, the TLS/HTTPS certificate stuff, already got adjusted after browser makers complained about it; browser makers aren't mandated to trust any certificates for internet traffic and DNS resolution. The only real problem left is QWACs in general being a part of the proposed legislation from what I can tell.

The rest of the bill seems more aimed at providing an easier authentication method to safely export private data. Could (hopefully) be good for dealing with KYC laws.

Digital stores obtain so much information to complain with those laws and it's a giant risk with things like the GDPR. As I understand it, under this law they could just store the absolute minimum (the reference ID for the centralized system in question) and if KYC laws are ever needed by the government, they can supply the ID rather than having to store a lot of Personal Information (which is a big issue with data breaches and the like being what they are.)

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#37
post #15

From the perspective of European govs: Why should only US entities (and companies like Cloudflare, Amazon or Google) be allowed to get access to communications content ? It’s very logical that Europe wants to do the same.

European CAs can apply to be included in the root stores, and Europeans can definitely write content-delivery (CDN) and content-parsing (browser) software.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#38
post #33

This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…

You obviously didn't have to deal with the misuse of security, "for the children" pretext for interception, and crypto scare attempts...

Yes, there are too much ill conceived attempts against security that in the end will hurt everyone. It's disappointing to see it coming from EU.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#39
post #18

>This enables the government of any EU member state to issue website certificates for interception and surveillance Wouldn't this be very easy to identify?

The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the help of ISPs etc).

Wouldn't Certificate Transparency make it very visible and obvious if they did that?

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#40
post #33

This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…

> Do you seriously think the intent here is to allow, say, Italy to issue a certificate and spying on German citizens?

This legislation allows and enables it, regardless of intent.

Post reply on HN