Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

301–310 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#301
post #42

Does anyone know what the supposed benefits are for this kind of bill? Are proponents overtly advocating for increased surveillance ability?

I believe that the stated/claimed intent is to create cross-country, bloc-wide digital signature interoperability and acceptance standards. The theory being that you can "digitally sign" things with a national ID (e.g. a smart card), and have that recognised anywhere in the EU. That would, in theory, help to reduce and simplify bureaucracy, especially for people moving between countries in the EU (a process which can…

Oh! That is a good way to conflate the issue. "It's for signing and verification."

That definitely has almost nothing to do with TLS and browsers. Why does my browser need to verify national ID cards? (no need to answer that)

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#302

To protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?

TLS 1.3 encrypts server certificate, so it will not be possible to filter such connections out using just passive inspection.

Instead of a pihole, you'd run a https proxy that doesn't trust the certs i guess.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#303

Earlier quoted context omitted.

From Mozilla's post: The text goes on to ban browsers from applying security checks to these EU keys and certificates except those pre-approved by the EU’s IT standards body - ETSI.

It's not a "security check" it's just informing the user about their certs...

the certs let the authorities issue new certs for anyone they want, e.g. your email provider, and your browser won't be allowed to verify whether those certifications are valid or not, to notify the user

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#304
post #191

Earlier quoted context omitted.

Your representatives that you voted into parliament did, however.

Von der Leyen is President of the European Council. The parliament had nothing to do with it. The council is made up of the prime ministers of the EU member countries, which also were not voted for seats in the EC. Likewise there was no vote on the Lisboa treaty which effectively put the EC above the parliament and outside its jurisdiction.

I was not very clear on what I meant, sorry for that.

I meant that whatever the government metaphorical "you" voted in, has voice in EC.

In fact current Lisboa treaty came into effect after previous reform attempt was torpedoed in part for "taking away sovereignty" by giving more power to European Parliament vs European Council - where the national governments have power.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#306
post #295

Earlier quoted context omitted.

> When you get a degree you get a transcript where all local grades are translated to to ECTS, which you then would use to apply for jobs https://www.google.com/search?q=%22job+application%22+%22ECT... gets me only a handful of results and a warning that 'It looks like there aren't many great matches for your search' Do (m)any European employers know about this scheme?

Job applications in Europe typically list a degree that is required, rarely the score that an applicant is expected to have received. Nonetheless, ECTS scoring is nowadays awarded to every degree that is obtained in a country that is a signatory to the Bologna accord. To answer your question, it is an established standard. https://en.wikipedia.org/wiki/Bologna_Process#Signatories

> ECTS scoring is nowadays awarded to every degree that is obtained in a country that is a signatory to the Bologna accord

It seems that ECTS is indeed useful to those who move internationally between institutions during a course of study (Erasmus and similar).

I'm struggling to detect much of a use case once a qualification is achieved and someone's looking for work.

> To answer your question, it is an established standard

OK, but so is Esperanto :)

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#307
post #153
post #132

Earlier quoted context omitted.

As I understand it, the EU Parliament engages through the trilogues. Once agreement has been reached there, final approval is indeed more of a rubberstamp. (But: I'm just somewhat interested in the subject; I'm not an expert on the process.)

Once an agreement has been reached, the Parliament can still reject the proposed law (which can easily happen because a conciliatory committee does not represent all the factions in parliament and of course public outcry/petitions can change opinions).

That's the definition of a "rubber stamp". They technically have the ability to reject, but they rarely do.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#308

Earlier quoted context omitted.

You criminalize the platform where it's published. The laws for that have been conjured in 2018.

The second they do that the entire internet is going to download it to see what the fuss is about. While they could legally do that, it's going to blow up in their face if they did it. I remember the old crypto export wars in the US and OpenBSD being based in Canada so they could ship string crypto in SSH.

Did you mean strong crpyto? String crypto makes no sense in the context.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#309
post #284

Earlier quoted context omitted.

You are sending letters to your friend and getting their replies back in the mail. You know your government delivers your letters and they could open them and read them, but you trust your government to keep your info private and use this power well. The current regulation would mean any government can peek at your letters, and even if they got caught peeking or letting their friends read your letters, your mail carr…

Thanks, but I wasn't actually looking for an analogy. I'm trying to understand things like how the government (or whatever actor) would gain access to browser history via a MITM attack for instance.

Any MITM attack is always going to be going forward, not in reverse, at least to capture authentication sessions (and then you can root around in someone's account).

1. Compromised WiFi networks ("McDonald's Free Wifi")

2. BGP Hijacks (these tend to get noticed)

3. Malware running a local proxy (Malware can try to inject it's own cert into the store too but that cert would be compromised by CT/AV/etc. A proxy with a valid gov cert would be much harder to detect.)

4. Compromised cell sites (stingray type devices)

5. Mistyped urls, often in combo with spear phishing.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#310
post #273

Could someone link to some actually helpful writeups on eIDAS? The linked article doesn't mention what eIDAS is about, only vague but strongly worded language about it having to be stopped, with no justifications or even what it is. The comments too are less helpful than usual. A lot FUD and anti-EU sentiment (which may or may not be warranted, but there's very little objective reasoning going on). Addendum: yes, peo…

[flagged]
Post reply on HN