Earlier quoted context omitted.
Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…
> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.
Some observations on the final text of the European Digital Identity framework
41–50 of 153 posts
Re: Some observations on the final text of the European Digital Identity framework
#42Earlier quoted context omitted.
In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…
Well that's dystopian.
Re: Some observations on the final text of the European Digital Identity framework
#43Earlier quoted context omitted.
In my own country, for digital signature purposes, the official Windows installer provided by the government adds the country's Central Bank's CA for any purposes, even for software signatures. If you have a company, they also force you to use their own application for making some annual declarations. That software asks for your OS user password using a home-brew dialog so that it can update itself. If you don't prov…
I’m curious what country this is, if you’re willing to share. I’m surprised any business filing is using a desktop app rather than on the web these days.
It's a complete nightmare. If you want to use some other digital services you are restricted to specific browser versions, some only allow you to use Windows, and in some cases the unsigned installer is only available via HTTP.
Re: Some observations on the final text of the European Digital Identity framework
#44I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…
One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.
Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services despite warning my bank about the potential problems months ahead of the forced transition. The only way to regain access is to travel back to Denmark and visit my bank or my local council.
Re: Some observations on the final text of the European Digital Identity framework
#45Earlier quoted context omitted.
One disadvantage: As a temporary visitor to Sweden, since you don’t have a personnummer, you’re fucked.
Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…
Re: Some observations on the final text of the European Digital Identity framework
#46Earlier quoted context omitted.
here's one example, the brazil irs https://www.receita.gov.br/ good lucky finding the cert if you didn't download your firefox in brazilian portuguese or didn't register you apple device in brazil. I mean, it is not difficult to find the cert, but it is a pain for travelers.
The problem seems to be "wrong domain", not "CA not recognized". You sure you have the right URL?
Re: Some observations on the final text of the European Digital Identity framework
#47I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…
The providers holds all the keys, you cannot verify that a signature is legit yourself, you wont get access to the keys they use to sign things, and a cryptographic signature is not really the same as a normal signature on a document.
Re: Some observations on the final text of the European Digital Identity framework
#48Earlier quoted context omitted.
Yes, this is a huge problem. In fact, when looking into Swedish jobs, you are usually advised to try to get a personnummer ASAP to make your relocation as smooth as possible. Denmark also has similar problems with their digital ID. Any unusual scenario turns into a nightmare. For instance, I moved abroad during their transition from a codecard to an app, and I lost access to my bank account and all ID-linked services…
an this is why a EU wide system is needed. I hold 3 digital identities (Spain, Italy and Sweden) and, believe me, it's not fun.
However, it is also necessary to make sure data privacy is factored in.
Re: Some observations on the final text of the European Digital Identity framework
#49Earlier quoted context omitted.
Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…
> This is a transfer of power from a voluntary industry consortium to appointed EU technocrats Or a transfer of power from US-centric companies to actual sovereign bodies. I don't want to live in a cyberpunk world. This sounds good to me. Note that browsers are still allowed to remove them if they are compromised.
Re: Some observations on the final text of the European Digital Identity framework
#50Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.
>Cookie banners happened because US devs didn't steelman EU regs. EU sites have the same amount of cookie banners as US ones. (ie, all major sites have one)