Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

71–80 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#71
post #70
post #64

Earlier quoted context omitted.

You still wont be able to break the end to end encryption of a site. You can only intercept traffic that the server can read, you can't intercept traffic that are encrypted end to end. And if the site can see your data assume the government can see it as well, they can get it with a warrant.

Website-based end-to-end encryption isn't usually. In most cases, the "e2e-encrypting" website will deliver the Javascript that does the "e2e-encryption", which can easily be manipulated to provide a copy of all messages to some convenient third location. A warrant will maybe warn the site and the user that something is going on. A man-in-the-middle attack without a warrant delivered to either party is more likely to…

> which can easily be manipulated to provide a copy of all messages to some convenient third location.

Updating others javascript as a proxy isn't "easily".

Also if the government goes all this way to tell each internet provider to spy on people, why do you think they couldn't tell certificate authorities to spy on people? It is the same level. I wouldn't be surprised if many CA's in USA already does this.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#72
post #34
post #7

I’m assuming this another… misguided… attempt by the security services to make their jobs easier. The grip that intelligence communities apparently have on our governments is ridiculous. Why do they have such influence?

Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…

It’s intriguing to observe this phenomena on HN where any posts critical of the EU will get downvoted, even though it is natural for any country or block to try various means to show or enforce its power.

And before someone says otherwise, I’ve seen this playing out hundreds of times.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#73

From: https://data.consilium.europa.eu/doc/document/ST-14959-2022-... Article 45(2): "Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. For those purposes web-browsers shall ensure that the identity data provided using any of the methods is displayed in a user friendly manner. Web-browsers shall ensure support and interoperability with qualified certific…

Allow the eIDAS certificates, but limit them to the country code TLDs to match the jurisdiction of the certificate issuer.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#75
post #26
post #21

Earlier quoted context omitted.

"The weakness is only if someone controls your internet connection and can use a compromised certification process to trick you into thinking you are at e2e.com" That will be (or already is) done at ISP level. It will probably be fully automated, where they just put a court order number into a form, and it automatically just catches all your traffic in gear that's installed at the ISP.

It is only undetectable if the site actually uses the vulnerable certificates. Otherwise you can see that the government is spying on you since the browser tells you what certificate it got (Telling you what certificate was used is a part of eIDAS). There is no way the government will replace certificates like that on an automated basis, it is too easy for people to notice and make a big deal about.

There's probably at most one person every ten millions who uses add-ons displaying each connection's certificate authority; and even them will likely not notice anything if it's only done to them occasionally (not to mention that absolutely no one checks the connections used to download third-party stuff, to my knowledge).

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#77
post #61
post #51

Earlier quoted context omitted.

> the only difference from now is that your browser will display "secure" instead of "invalid cert". There is no other difference. Oh that's SUCH as an insignificant difference!!! > So to orchestrate an attack they would need to build an webbapp that is sufficient similar for you not to notice, take over your internet connection and break the certification process. You can simply relay the requests to the original si…

> You can simply relay the requests to the original site/"webapp", no need to build one similar Doesn't work if the app encrypts messages locally, so end to end encryption is still valid with this.

We're talking about normal browsing, not webapps performing their encryption

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#78
post #34

Earlier quoted context omitted.

Probably not really. The EU itself (at the Brussels level) doesn't have much of an intelligence apparatus. One exists but it's small and weak compared to the likes of the NSA. The most capable was GCHQ but of course that's no longer a part of the EU. The EU likes passing internet related legislation because of: 1. The politics of it. It involves the raw exercise of power over people who are easily bullied and that th…

It’s intriguing to observe this phenomena on HN where any posts critical of the EU will get downvoted, even though it is natural for any country or block to try various means to show or enforce its power. And before someone says otherwise, I’ve seen this playing out hundreds of times.

It got downvoted since it says this regulation isn't made to spy on people. People want to believe it was made for a sinister purpose and not just due to naivete.

If you look around you see plenty of people that gets upvoted and are critical of EU, so that isn't it.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#80
Very concerning. As a slight aside though, it is not a "secret law". All EU laws are published on its website in every official language, and the vast majority of laws (including this one) must be publicly ratified by the directly elected European Parliament before coming effective.

They should tone down this kind of sensationalist clickbait that I would expect to find in UK tabloids. They probably think it helps them impress the urgency of the matter on the public but frankly it just makes me doubt the veracity of the claims made in the article (though in this case I trust Mozilla and would hope that they are not misrepresenting the content of the law itself).

Post reply on HN