This claim that eIDAS is an attempt to intercept TLS and spy on citizens has been repeated over and over this week without any basis and I'm getting sick of it. I don't understand why everyone immediately assumes bad faith here when it's much more likely that this is just a botched article written by someone who has not had to deal with the intricacies of the web PKI. Do you seriously think the intent here is to allo…
Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
71–73 of 73 posts
I agree actually. Which data exactly will be transported over TLS connection secured by these certs? Who said it has to be the entire HTTP traffic, why not just the traffic required for authentication? It seems very vague at the moment...
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#72We really need to go back to days of police actually going through the trouble of investigating and catching criminals - at least in principle. Now every government security agency dreams of having complete access to the communications of everyone so they don't go through the trouble of doing their job. First UK, now EU. Although I'm generally closer to the EU mentality of trusting the governments more than the corpo…
My biggest problem with the whole mentality is that most high profile shootings are still being carried out with unsecured methods, e.g. the Paris shooting from 2015 was organized via bare SMS. If law enforcement can't catch criminals using the unsecured channels how can they argue at all that the encryption is to blame?
Re: Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections
#73Earlier quoted context omitted.
The government would be able to obtain a certificate identical to the one of the a website owner (the real one), enabling the mitm attack (for example with the help of ISPs etc).
Wouldn't Certificate Transparency make it very visible and obvious if they did that?
CT would not be allowed if ETSI does not allow it. Neither would distrusting that mis-issuing CA be allowed.