"We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0]
Last Chance to fix eIDAS: Secret EU law threatens Internet security
41–50 of 314 posts
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#42Does anyone know what the supposed benefits are for this kind of bill? Are proponents overtly advocating for increased surveillance ability?
Something better than typing your name and trusting a third party to do email verification for a digital signature certainly sounds like it could have advantages for doing business though.
I believe the issues identified here seem to stem from a (very) over-enthusiastic desire to have certificate acceptance everywhere (i.e. prevent discriminating against one country's citizens by excluding their ID card CA), without understanding the different types of trust chains and certificate chains. Presumably scattered with a bit of technical naivety as well. The concept itself is (probably?) fine, as long as it doesn't try to force browsers or SSL verifiers to accept or trust certificates they don't want to.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#43Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.
I guess this is where client attestation comes into play.
I suspect if this ever does play out, it could result in fewer people using "EU spec" browsers, and more people using the international overseas version, thus undermining the entire intention of the policy proposal.
It seems a pretty safe bet no browser maker would ship these CAs to users outside of the EU (and maybe EEA).
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#44Earlier quoted context omitted.
It is only undetectable if the site actually uses the vulnerable certificates. Otherwise you can see that the government is spying on you since the browser tells you what certificate it got (Telling you what certificate was used is a part of eIDAS). There is no way the government will replace certificates like that on an automated basis, it is too easy for people to notice and make a big deal about.
If a nonprofit like Let’s Encrypt can perform automated certificate renewal with a few API calls, so can the government. Also, MITMs are a thing and getting the EIDAS certs in the root store will show that the certs in question are trusted, which is all that really matters because there is no way for users to know what certificates were actually installed by the website owner.
TLDR: If you are worried about security you can always install a plugin to get back the old behavior. This just says that browsers should be able to trust them, not that you have to configure your browser to trust them.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#45Earlier quoted context omitted.
It's another side of the efforts of going around encryption, chat controls deals with communication services, this one with browsers
But this doesn't force browsers and sites to use weak encryption. It is very different.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#46Does anyone know what the supposed benefits are for this kind of bill? Are proponents overtly advocating for increased surveillance ability?
I believe that the stated/claimed intent is to create cross-country, bloc-wide digital signature interoperability and acceptance standards. The theory being that you can "digitally sign" things with a national ID (e.g. a smart card), and have that recognised anywhere in the EU. That would, in theory, help to reduce and simplify bureaucracy, especially for people moving between countries in the EU (a process which can…
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#47If certificates issued by those CAs will be tied to independent (from EU) certificate transparency (CT) services and to specific national top-level domains, then I am completely fine with this. After a big number of websites in Russia (including the biggest bank in the country) have effectively lost access to the CA infrastructure used by commonly used browsers, I don't think any honest person can say that the curren…
Re: Russia - SberBank, which is used by the vast majority of population, voluntarily switched to a new Russian government-controlled CA. This move aimed to coerse people to install this CA's cert under false premises and to let the state splice https if needs be. The goal was bloody obvious and it has never been about the "robustness" of infrastructure. They just want to take away people's Internet privacy.
The "false premise" was that GlobalSign has refused to issue new certificates for Sberbank and there were several cases of CAs revoking existing certificates. They eventually have found a CA (Harica DV) which was willing to issue new certificates, but it was not clear at the time that such CA will be found and the new certificates can be revoked at any moment after a new wave of sanctions or simply after a strongly worded warning from Washington or Brussels. Relying on a relatively minor Greek CA for bank operations is clearly not a good strategy in their situation.
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#48I’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?
Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…
The commission President is proposed by the council (the heads of states) and appointed by parliament.
I’m not aware of the EU arresting random US citizens for breaking laws like the gdpr, you’re thinking of America and the DMCA
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#49Earlier quoted context omitted.
But this doesn't force browsers and sites to use weak encryption. It is very different.
This forces browsers to accept all the CAs approved by the EU states, and you can be certain that some of them will be used for decrypting (and if needed modifying) the traffic
Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security
#50Does anyone know what the supposed benefits are for this kind of bill? Are proponents overtly advocating for increased surveillance ability?
With certificates from a government CA containing your name, address and maybe other data like tax ID, the certificate becomes that imprint, digitally signed and hard to fake. So I guess the next step after this directive is in place will be to require such government certificates for all European websites instead of the usual domain-validated WebCA ones. For a modest fee going into the pockets of some government cronies, of course.