Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

61–70 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#61
post #51
post #16

Earlier quoted context omitted.

Governments still can't see your requests to servers under normal circumstances with this law. The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at "e2e.com" when you are on another site, and in those cases the only difference from now is that your browser will display "secure" instead of "invalid cert". There is no oth…

> the only difference from now is that your browser will display "secure" instead of "invalid cert". There is no other difference. Oh that's SUCH as an insignificant difference!!! > So to orchestrate an attack they would need to build an webbapp that is sufficient similar for you not to notice, take over your internet connection and break the certification process. You can simply relay the requests to the original si…

> You can simply relay the requests to the original site/"webapp", no need to build one similar

Doesn't work if the app encrypts messages locally, so end to end encryption is still valid with this.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#62

Does anyone know what the supposed benefits are for this kind of bill? Are proponents overtly advocating for increased surveillance ability?

A key idea behind all of this is to sell "qualified certificates". Which is another way of saying "expensive certificates".

In the past, CAs sold EV certificates which gave you a nice green look in the browser bar and no security advantage (arguably security downsides, because you cannot automate it). That was good business, until browsers decided that this makes no sense and scraped any special treatment for EV certificates.

The "qualified certificates" by the EU are essentially EV with a new name.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#63

How will this be enforced? If Mozilla or Google added some hard coded certificate into a new browser version, what if a distribution like Debian patched it out? Or if a user can delete it from the certificate stores themselves?

People get very hung up on what people can technically do, but the domains of the browser or OS that doesn’t follow these rules will simply be blocked at the DNS level so that you can’t download them any more. The relevant entities such as companies developing or using said non-compliant projects will be fined, and any natural persons jailed outright, à la Stallman’s The Right To Read.

You can't block a browser at the DNS level.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#64
post #57
post #8

There is nothing there that says every service must use specific certificates, just that browsers should accept certain ones. So this in no way breaks encryption for apps who care, this only reduces security on apps that wants to reduce security. For example, if you use private "e2echat.com" it can still use safe certs and be safe, the risk is only that "governmentchat.com" will use bad certs, which was already a ris…

There is no way for e2echat.com to make sure that the client will insist on a certain safe CA. Sure, in case e2echat.com controls all clients this would be possible, but this is a rare case. In the general case, any CA can sign any website certificate. So all those new government CAs can sign all the man-in-the-middle certificates they like, and browsers are obliged to accept them. Nothing the website can do about th…

You still wont be able to break the end to end encryption of a site. You can only intercept traffic that the server can read, you can't intercept traffic that are encrypted end to end.

And if the site can see your data assume the government can see it as well, they can get it with a warrant.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#65
post #41

The following quote from former Jean-Claude Juncker, president of the European Commission sums up the way the EU seems to work quite nicely: "We decide on something, leave it lying around and wait and see what happens. If no one kicks up a fuss, because most people don't understand what has been decided, we continue step by step until there is no turning back."[0] [0] - https://en.wikiquote.org/wiki/Jean-Claude_Junck…

Wow, a lot of those quotes are damning.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#67

Earlier quoted context omitted.

People get very hung up on what people can technically do, but the domains of the browser or OS that doesn’t follow these rules will simply be blocked at the DNS level so that you can’t download them any more. The relevant entities such as companies developing or using said non-compliant projects will be fined, and any natural persons jailed outright, à la Stallman’s The Right To Read.

You can't block a browser at the DNS level.

I meant domains offering downloads of the non-compliant browser/OS; updated. Thanks!

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#70
post #64
post #57

Earlier quoted context omitted.

There is no way for e2echat.com to make sure that the client will insist on a certain safe CA. Sure, in case e2echat.com controls all clients this would be possible, but this is a rare case. In the general case, any CA can sign any website certificate. So all those new government CAs can sign all the man-in-the-middle certificates they like, and browsers are obliged to accept them. Nothing the website can do about th…

You still wont be able to break the end to end encryption of a site. You can only intercept traffic that the server can read, you can't intercept traffic that are encrypted end to end. And if the site can see your data assume the government can see it as well, they can get it with a warrant.

Website-based end-to-end encryption isn't usually. In most cases, the "e2e-encrypting" website will deliver the Javascript that does the "e2e-encryption", which can easily be manipulated to provide a copy of all messages to some convenient third location.

A warrant will maybe warn the site and the user that something is going on.

A man-in-the-middle attack without a warrant delivered to either party is more likely to go undetected.

Post reply on HN