Live data from Hacker News

Last Chance to fix eIDAS: Secret EU law threatens Internet security

last-chance-for-eidas.org

81–90 of 314 posts

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#81
post #75
post #26

Earlier quoted context omitted.

It is only undetectable if the site actually uses the vulnerable certificates. Otherwise you can see that the government is spying on you since the browser tells you what certificate it got (Telling you what certificate was used is a part of eIDAS). There is no way the government will replace certificates like that on an automated basis, it is too easy for people to notice and make a big deal about.

There's probably at most one person every ten millions who uses add-ons displaying each connection's certificate authority; and even them will likely not notice anything if it's only done to them occasionally (not to mention that absolutely no one checks the connections used to download third-party stuff, to my knowledge).

Yes, because CA level attacks are basically nonexistent and not a very big deal since they require you to control the targets internet connection.

The moment people learn that the US government could control a CA and your internet provider to spy on you maybe that will change. But as is people think it is too much work for governments to bother with it.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#82

Oh dear, shooting on one's foot once again. Fortunately, they cannot forbid a natural person from removing any given certificate. If this passes, I am sure we have blacklists and scripts for these in no time.

New Firefox plugin: "Disable EU Certs"

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#83
post #44

Earlier quoted context omitted.

If a nonprofit like Let’s Encrypt can perform automated certificate renewal with a few API calls, so can the government. Also, MITMs are a thing and getting the EIDAS certs in the root store will show that the certs in question are trusted, which is all that really matters because there is no way for users to know what certificates were actually installed by the website owner.

That has nothing to do with this, I don't think you understand this vulnerability. You can see which certificate authority issued the cert, so you can see if the suddenly the site started using a vulnerable cert provider and thus know that it is compromised. Note that the same attack is possible right now, the only difference is how your browser displays it, you can just install a plugin to get back the original beha…

First, few people would know that they should install a plugin, second, since the laws says that browsers "shall ensure", there's a good chance that they would be forced to try to block these plugins

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#84

The proposal is so obscene that I doubt Apple, Google or even Microsoft would ever comply with it.

I guess Europe would have to fund its own browser development. The rest of the world won't participate.

Developing a browser these days mostly involves slapping on their own branding over Firefox or Chromium though, so hardly the end of the world for EU.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#85

The proposal is so obscene that I doubt Apple, Google or even Microsoft would ever comply with it.

I guess Europe would have to fund its own browser development. The rest of the world won't participate.

It's a market of nearly half a billion people, two-tier browsers seem more likely. IIRC Netscape did this in the past over US export laws on cryptography.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#86
post #71
post #70

Earlier quoted context omitted.

Website-based end-to-end encryption isn't usually. In most cases, the "e2e-encrypting" website will deliver the Javascript that does the "e2e-encryption", which can easily be manipulated to provide a copy of all messages to some convenient third location. A warrant will maybe warn the site and the user that something is going on. A man-in-the-middle attack without a warrant delivered to either party is more likely to…

> which can easily be manipulated to provide a copy of all messages to some convenient third location. Updating others javascript as a proxy isn't "easily". Also if the government goes all this way to tell each internet provider to spy on people, why do you think they couldn't tell certificate authorities to spy on people? It is the same level. I wouldn't be surprised if many CA's in USA already does this.

It is "easily", because current commercially available "firewall" appliances include that kind of capabilities. Just a few clicks, install a CA certificate, add a logging endpoint, done. Certain regulated industries like finance and medicine are required to use those. All chats are instantly intercepted and logged.

And the way to spy on people via a certificate authority is exactly as described, you get a CA that signs your man-in-the-middle certificate for a website you do not own. Then you MitM that traffic using that certificate, while still getting a green "lock" icon.

With current WebCA certificates, certificate transparency does help a little to detect such MitM certificates, and some CAs have actually been caught red-handed. There are processes to punish or remove such CAs. However, this law would also prevent such actions, thus making it impossible to prevent any future malfeasant CAs.

About an example MitM certificate case and removal, see the DigiNotar case: https://blog.mozilla.org/security/2011/08/29/fraudulent-goog...

For more about how certificate transparency works see http://nil.lcs.mit.edu/6.824/2020/papers/ct-faq.txt

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#87
For anyone who’s about to say that surveillance isn’t the point of this legislation: it definitely is; we very recently saw Germany trying to MITM jabber.ru users[1], having a CA that can be asked to issue any certificate is definitely something that’d be used for surveillance purposes.

[1] https://notes.valdikss.org.ru/jabber.ru-mitm/

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#88
post #77
post #61

Earlier quoted context omitted.

> You can simply relay the requests to the original site/"webapp", no need to build one similar Doesn't work if the app encrypts messages locally, so end to end encryption is still valid with this.

We're talking about normal browsing, not webapps performing their encryption

Webapps are also vulnerable because the Javascript can be manipulated in a MitM attack.

The only way around this would be a "real" app.

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#89
post #78

Earlier quoted context omitted.

It’s intriguing to observe this phenomena on HN where any posts critical of the EU will get downvoted, even though it is natural for any country or block to try various means to show or enforce its power. And before someone says otherwise, I’ve seen this playing out hundreds of times.

It got downvoted since it says this regulation isn't made to spy on people. People want to believe it was made for a sinister purpose and not just due to naivete. If you look around you see plenty of people that gets upvoted and are critical of EU, so that isn't it.

We had a recent MITM on jabber.ru[1] conducted by Germany, a EU state that was only detected because they failed to renew the MITM cert. I have no reason to believe making this easier isn’t one of the goals of EIDAS.

[1] https://notes.valdikss.org.ru/jabber.ru-mitm/

Re: Last Chance to fix eIDAS: Secret EU law threatens Internet security

#90
Seems like some politicians from EU commission had parents in Stasi, KGB and other organisations and became allured by the stories of watching other people, learning they secrets or perhaps even seeing their naked photographs.

So these pervs now want to do the same. For what?

Post reply on HN