Live data from Hacker News

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

theregister.com

51–60 of 73 posts

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#51
post #33

This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…

It's also very much not the case; regulators adjusted that part of eIDAS earlier this week - Browsers aren't required to trust these certificates for DNS or HTTPS connections. The law is still in proposal/feedback stage and the lawmakers listened to the complaints. TLS interception likely was never a seriously intended goal, just a side-effect due to how the law was worded.

Interesting, what is the purpose then? Do you have a link to the updated text?

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#52
post #23

We really need to go back to days of police actually going through the trouble of investigating and catching criminals - at least in principle. Now every government security agency dreams of having complete access to the communications of everyone so they don't go through the trouble of doing their job. First UK, now EU. Although I'm generally closer to the EU mentality of trusting the governments more than the corpo…

[flagged]

BUT citizen should be NOT reading THE REGISTER, becasue of these kind of misinformation / misquided campaings

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#53
post #3

How is forbidding browsers from distrusting spying CAs proposed to work? E.g. would using/distributing Firefox become a crime?

No, it would mean for Firefox developers that it's illegal to have feature that can disable the EU member state certificates.

Such crypto backdooring failed in the past, so they're trying to go after the weakest link they can think of. In this case, software publishers.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#54
post #45

The problem the EU faces - or the respective national European intelligence agencies for that matter - is that they lack access to a comprehensive, global data funnel. The US, Russia and China all have their respective systems: The US has access to the data of Facebook (WhatsApp and Instagram), Apple messenger, Google's GMail. Russia has Telegram and China has I think Weibo, WeChat, TikTok and probably some more. I w…

[flagged]

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#55
post #23

We really need to go back to days of police actually going through the trouble of investigating and catching criminals - at least in principle. Now every government security agency dreams of having complete access to the communications of everyone so they don't go through the trouble of doing their job. First UK, now EU. Although I'm generally closer to the EU mentality of trusting the governments more than the corpo…

[flagged]

All that is already a reality in many 3rd world countries and even is European ones like Turkey. By all that, I mean all that!

Turkey had a scandal with TurkTrust cert authority(a company owned by the Turkish military fund) where they issued a root cert by mistake(?) and a government body was caught by Google when pretending to be Google.

At the same time, Turkey has a robust online services. Signing documents, medical stuff - everything happens digitally and signed securely and Turkish citizens very rarely need to go to physical government locations and almost never need to deal with physical paperwork . There's even government controlled mail service that you can use to do official communications and if something goes sought the courts can check the communications from your government provided, cert signed inbox.

The problem with the new stuff that EU and UK are trying to do is, to remove the "being caught by Google" part by legally whenever they feel fit.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#56
post #51

Earlier quoted context omitted.

It's also very much not the case; regulators adjusted that part of eIDAS earlier this week - Browsers aren't required to trust these certificates for DNS or HTTPS connections. The law is still in proposal/feedback stage and the lawmakers listened to the complaints. TLS interception likely was never a seriously intended goal, just a side-effect due to how the law was worded.

Interesting, what is the purpose then? Do you have a link to the updated text?

Afaik they want a digital id card for each person and business, so europeans can legally identify themselves and enter legally valid digital contracts on the web.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#57

Earlier quoted context omitted.

[flagged]

BUT citizen should be NOT reading THE REGISTER, becasue of these kind of misinformation / misquided campaings

> BUT citizen should be NOT reading THE REGISTER, becasue of these kind of misinformation / misquided campaings

You might misunderstand the competency of some citizens here. Does DigiNotar ring a bell?

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#58

The current internet is essentially so secure, it doesn't need or have a properly walled-off of underground of people who value secure communications. In the west few people outside actual criminals practice it strictly. > EFF warns incoming rules may return web 'to the dark ages of 2011' I don't want this law to pass, but I have fond memories of some of the communities that existed back then. If it passes, I at the…

[flagged]

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#59
I remember a (now removed?) passage in Wikipedia stated that self-signed certificates where considered as default for HTTPS back in the 90ies. But the idea of signing Certificate-Authorities prevailed. Users get instantly a “lock” creating a feeling of security - and it made some people rich.

Self-Signed actually is the only trustworthy approach to use certificates. And with QR-Codes or ASCII-Art it is user friendly. Your partner (e.g. bank) would print a hash/fingerprint on the contract and the user MUST check it on first connection.

To complicated? SSH does that always. PGP is built upon the idea of users itself trusting. No end users?

Signal and WhatsApp! Actually you need to check the hash/fingerprint in the profile of your chat or you’ve only an encrypted connection but no security who receives the messages.

I think we should drop the entire approach of Certificates and issuing through “Authorities”. SecureBoot was flawed from the very first moment due its use of Certificates signed by an Authority named Microsoft. And a top-down security enforced from companies isn’t one.

PS: Lenovo turns off SecureBoot when you order a Laptop with Linux. A wise decision. I just miss a note that the password for hardware-disk-encryption and UEFI.

Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

#60
post #51

Earlier quoted context omitted.

It's also very much not the case; regulators adjusted that part of eIDAS earlier this week - Browsers aren't required to trust these certificates for DNS or HTTPS connections. The law is still in proposal/feedback stage and the lawmakers listened to the complaints. TLS interception likely was never a seriously intended goal, just a side-effect due to how the law was worded.

Interesting, what is the purpose then? Do you have a link to the updated text?

Unfortunately the new text isn't public yet; I'm basing my conclusion on this source: https://epicenter.works/en/content/eu-digital-identity-refor... (which was linked on HN earlier today) and claims that the TLS/HTTPS stuff has been adjusted.

At risk of poorly resummarizing the article:

The real purpose seems to be that the EU wants to regulate customer data collection for online transactions. It's an e-Identity law at its core; the EU wants member states to set up a centralized "Wallet" service that can be used to safely exchange a limited amount of PI for things such as digital transactions.

There's little direct reason for example for say, Hetzner, to have the address data of any of their customers on file - they don't send you any physical mail or anything like that. They have that info mostly because of anti-fraud laws that mandate they store a lot of information with each transaction. With the new Wallet setup, they only have to request what they need and the government can still keep those KYC laws working without you having to store a ton of personal data at a third party.

The QWAC stuff is a part of the law because the way this practically ends up working is that a EU citizen that wants to use the wallet (the process is strictly opt-in; if you don't want to use it, you don't have to) needs to give their approval kinda like how it works with OAuth. QWACs were a harebrained attempt at making it clear to the user that the site they're giving their approval on was actually a real government site.

The original law text forced QWACs to not only be displayed but prevented browser makers from doing the usual security processes to deem if the certificates are safe. The new text seems to address this issue according to the source; QWACs for government sites must still be displayed if approved by the browser (so for government sites you'd still get the green text after the security lock like how it was back in the day when EVs were a thing - this is what the EU really wants out of this law from what I can tell, normal certificates don't give them this assurance - they basically want to tell their citizens "yeah, if you see this text after the padlock, only then you can be sure this is the German government"), but browsers aren't required to forcibly bypass all their security processes to do so, giving them back the control they need against bad actors. Firefox can still choose to block a bad QWAC or restrict the list of QWACs they approve to only a small list of government domains, should they decide the certificate authority is behaving inappropriately.

Post reply on HN