Live data from Hacker News

Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

eidas-open-letter.org

61–67 of 67 posts

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#62

I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…

Why do we need that? CA system with TLS certificates works well, even while DNS is not trusted. It's a good solution for websites.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#63
post #51

Earlier quoted context omitted.

DNSSEC is a great concept with a rather convoluted design that's based on limitations of computers in the 90s. It's obviously better to have DNSSEC than not to, but I wouldn't call it a "great solution". Case in point: the DNS client never actually validates the DNSSEC signatures, the DNS server the client uses is supposed to do that, and then simply sets a flag that says "I validated this". Perfect for recursive DNS…

> It's a shame, really, because DANE would've fixed so many problems. It would basically make services like Let's Encrypt unnecessary and would move us close to a world where email encryption and validation works by default.

It would take us to a world where the only CA you can and have to trust is the TLD operators and their nation. Where transparency is mostly an afterthought and violators can't be forced to do anything.

DNSSEC sucks ass.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#64
post #52

Earlier quoted context omitted.

We're already all used to running ad/script block on our clients so accept a certain level of breakage. It's just a part of the cost of using the web that some sites are crap (youtube being the big one nowadays) but in the end we just "route around them" (they die).

> We're already all used to running ad/script block on our clients so accept a certain level of breakage. The "we" reading this post? Yeah, probably. The internet population as a whole? Absolutely not, nowhere close. I've been using Adblock or its descendants since the original Firefox extension where downloadable filter lists were a separate addon, and every time I have to browse a mainstream web site when using a "…

Exactly. Besides, why should a grandma lose online banking access because some IT guy (or gal, I'm not judging) fat-fingered a certificate revocation in production and now the site is broken?

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#65
Isn’t there a way to do away with CA and do it on the block chain?

BUT to be clear the governments shouldn’t be compromising the security of their own people and organisations in the first place. We can’t technology our way out of this behaviour!

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#66
post #24

Earlier quoted context omitted.

HPKP was generally not recommended even when it was still around due to the danger of breaking your site. https://scotthelme.co.uk/im-giving-up-on-hpkp/

We're already all used to running ad/script block on our clients so accept a certain level of breakage. It's just a part of the cost of using the web that some sites are crap (youtube being the big one nowadays) but in the end we just "route around them" (they die).

>in the end we just "route around them" (they die)

My comment was about the perspective of the website owner, not the website user. The website owner certainly doesn't want to be routed around and have the website die. So the website owner will avoid HPKP.

Re: Joint statement of scientists and NGOs on the EU’s proposed eIDAS reform

#67

This would be really easy to detect. Just look at the certificate chain. It would be trivial to make a plugin to warn the user of this, at which point they know they're under surveillance which would be worse than just doing human surveillance IMO.

Almost nothing coming out of the EU that touches encryption makes sense these days, even when viewed from their own perspective. It's like they are desperate to get any kind of crypto regulation into the door before some deadline and consequences be damned.

I say this with the upmost request to their politicians, but their politicians have no clue what they're doing. They clearly don't understand how any of this works. None of what they propose can solve the issues they claim they want to solve. Not this, not client-side scanning, nothing. I genuinely wonder who's "advising" them on this stuff and what their true motives are.

It's sad to see the EU like this but nothing lasts forever. I feel sad for the next generations. They'll be the ones to bare the full brunt of these misguided regulations.

Post reply on HN